Announcement

#1 2009-08-16 20:46:15

MJ80
Member
2009-04-19
56

I Found A Bug

Users can sign up without passwords.

Although no big deal, thought i would tell you about it.

Offline

 

#2 2009-08-17 14:10:10

nicolas
Former Piwigo Team
2004-12-30
1232

Re: I Found A Bug

Thanks. I confirm. Can you post a bug to our bugtracker ?
http://piwigo.org/bugs/bug_report_advanced_page.php

Offline

 

#3 2009-08-17 14:57:08

MJ80
Member
2009-04-19
56

Re: I Found A Bug

Wont let me in there. Says I dont have permission?

Offline

 

#4 2009-08-17 15:40:18

nicolas
Former Piwigo Team
2004-12-30
1232

Re: I Found A Bug

MJ80 wrote:

Wont let me in there. Says I dont have permission?

Sorry, I forgot it : you must create an account.

Offline

 

#5 2009-08-17 16:27:50

MJ80
Member
2009-04-19
56

Re: I Found A Bug

Mm, how do I post a bug?

Offline

 

#6 2009-08-17 22:51:32

plg
Piwigo Team
Nantes, France, Europe
2002-04-05
13789

Re: I Found A Bug

(before answering to the question "how to create a bug?", let's discuss about the issue)

Is it really a bug? OK, this is not a best practice, but I don't think it should be forbidden. Maybe something like a javascript (client side) check on form submission saying "Hey, are you sure you want an empty password?" would be better, don't you think?

Offline

 

#7 2009-08-17 23:09:39

MJ80
Member
2009-04-19
56

Re: I Found A Bug

Im not really worried because my users shouldnt be so stupid as to not put in a password. But there should be a safeguard yes. As in, YOU MUST ENTER A PASSWORD. Dont give them an option of "are you sure you dont want a password.....What if someone signs up with the same name as someone else, and uploads into a folder designated for another person.

For my gallery its possible, because each member has their own album which I create via FTP..

But for anyone else that uses piwigo, I guess it wont matter either way. Leaving comments etc could be a problem if users accidently dont put in a password..

My gallery is different in that I get many thousands of users who upload into their own albums, which I have to create manually :/

But as I said, its no big deal, Ill just delete the user or send them an email to enter a password if it does ever happen....

Offline

 

#8 2009-08-17 23:27:16

nicolas
Former Piwigo Team
2004-12-30
1232

Re: I Found A Bug

And the other "problem" is that the star suggest that the password field is required. If we keep that star, it's a bug.

Offline

 

Board footer

Powered by FluxBB

github twitter newsletter Donate Piwigo.org © 2002-2024 · Contact