qijianbo / tradie-choice

Automatically exported from code.google.com/p/tradie-choice
0 stars 0 forks source link

add old password option #219

Closed GoogleCodeExporter closed 8 years ago

GoogleCodeExporter commented 8 years ago
What steps will reproduce the problem?
1.
Go to Manage account > change password.

System does not ask for old passowrd, as a security measure.
    Just input new password twice and password is changed.
    Also, received email says: "You didn't update any of your profile data", altough I have updated the password and it works.

What is the expected output? What do you see instead?

if user changes pw there should be security to enter old pw first

Original issue reported on code.google.com by cih...@gmail.com on 6 Nov 2013 at 2:31

GoogleCodeExporter commented 8 years ago
Its done. Please check. 

Original comment by nilacser...@gmail.com on 12 Nov 2013 at 6:59

Attachments:

GoogleCodeExporter commented 8 years ago
I entered wrong password in old password field and got the message:
Your Profile updated Successfully

Dont show "New Password" on email.
Only show that password has been changed.

I.e if a user email account is hacked, then potentially they could transfer 
$$$$ causing a huge problem....

Original comment by cih...@gmail.com on 13 Nov 2013 at 1:59

GoogleCodeExporter commented 8 years ago
I tested it with giving wrong password in old password field. Its give me 
error. Please check it again. I attached the image what I see.

Original comment by nilacser...@gmail.com on 14 Nov 2013 at 5:00

Attachments:

GoogleCodeExporter commented 8 years ago
tested again not resolved

Original comment by cih...@gmail.com on 19 Nov 2013 at 12:16

GoogleCodeExporter commented 8 years ago
Please check it again and let me know with screenshot what you exactly faced.

Original comment by nilacser...@gmail.com on 20 Nov 2013 at 6:01

GoogleCodeExporter commented 8 years ago

Original comment by cih...@gmail.com on 3 Dec 2013 at 4:26