sizzlelab / side

t3rc
6 stars 3 forks source link

Password changing hidden danger #62

Closed miyula closed 12 years ago

miyula commented 12 years ago

New issue from #42:

When participant -- or normal user not a researcher -- is making the changes in his/ her profile, it is asked to confirm the password, but the other field with password is also editable, so the user can just to two write new password and that is it. Somehow it is wrong.

miyula commented 12 years ago

There is no need to enter password when user want to change his/her profile. If user input password, it means to change it.

I configured the system, so the user can't change the email account (to protect achieving new password) , and add a note bellow password input box.

mataanin commented 12 years ago

Reassigning to @katuta to test it.

katuta commented 12 years ago

ok, clear. Two suggestions to make it a bit more clear:

  1. The phrase: To change the current user password, enter the new password in both fields. - place it above the passwords fields, not after like it is now.
  2. Name fields: Password to New Password and Confirm Password to Confirm New Password
miyula commented 12 years ago

This issue has been updated, please check it.

katuta commented 12 years ago

looks good. nothing to add.