ovh / manager

OVHcloud Control Panel
https://ovh.github.io/manager/
BSD 3-Clause "New" or "Revised" License
216 stars 98 forks source link

Login security emails are send to wrong email with sub-accounts #3012

Open FlorianLudwig opened 4 years ago

FlorianLudwig commented 4 years ago

Describe the bug On login a notification is sent to the accounts email address. In case of a sub-account this is sent to the main account (without an indication that the login is through a sub account).

To Reproduce Steps to reproduce the behavior:

  1. Create a sub account
  2. Login with sub account
  3. check emails

Expected behavior Notification email should go to subaccounts email.

antleblanc commented 4 years ago

Hi @FlorianLudwig! Thanks for reporting this issue.

In order to be able to reproduce the issue, could you please confirm URL used to log in?

Thank you

FlorianLudwig commented 4 years ago

Hi @antleblanc,

do you mean like

https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.de/&ovhSubsidiary=de

?

FlorianLudwig commented 4 years ago

Hi @antleblanc have been able to reproduce this issue?

antleblanc commented 4 years ago

Hi @antleblanc,

do you mean like

https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.de/&ovhSubsidiary=de

?

Yes! That's perfect! Thank you!

Hi @antleblanc have been able to reproduce this issue?

Yes we are to reproduce this issue.

The Manager application itself doesn't send any emails so I have contact the right team internally to notify them and I will keep you posted.

Maurozio commented 3 years ago

hello, Login Notification sent to email are important security measure frequently used. An example how the text inside the login notification email should be: "There was a successful login to Manager, using (nic-handle) from (IP address). If this was not you please contact us immediately, change password and ....)" Does OVH Manager support login notification sent to the account email address? It seems not.