Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Password prompts require the admin password, not the impersonated user's password #230

Open
strugee opened this issue Jul 27, 2023 · 1 comment

Comments

@strugee
Copy link
Member

strugee commented Jul 27, 2023

STR:

  1. Impersonate another admin (seems silly, but in this case I did this because I originally logged in to a shared admin account and was too lazy to dig through my password manager for the password to the admin account I created for myself on a different computer - so it was easier to just impersonate myself)
  2. Try to take some privileged action. In my case it was changing who gets announcements from Announcement Center at /index.php/settings/admin, but presumably you could also update some apps or something
  3. Input the impersonated user's password and get a "credentials failed" message or something like that
  4. Input the admin password and notice it succeeds

I'm on Nextcloud 26.0.4, Impersonate 1.13.1.

@kesselb
Copy link

kesselb commented Dec 27, 2024

This seems like a rather strange edge case? ;)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants