lunatech-labs / lunatech-notime

Time tracking tool, written as a Lunatech internship project
https://confluence.lunatech.com/display/INTRANET/NoTime
8 stars 2 forks source link

Change password does not ask for old password #10

Open martinkok opened 12 years ago

martinkok commented 12 years ago

http://floating-sky-3062.herokuapp.com/user/change-password does not require the user to enter his or her old password.

ghost commented 12 years ago

Also, if a user has the admin role, and he wants to edit his password in the admin section by editing his user account, he should be asked for his own password too.