Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Confirm additional email address" should not show password #35

Open
GoogleCodeExporter opened this issue Mar 30, 2015 · 0 comments
Open

Comments

@GoogleCodeExporter
Copy link

The "confirm additional email address" message sent to the new address shows 
the password of the requesting user in plain text, when it should not, since 
the receiver of such a message may have gotten it due to user error (typo, 
anyone?) but will nonetheless be granted full access to to the requesting 
user's account, simply by virtue of _actively_being_told_ his login data, and 
all his list memberships.

Jeff:  This needs some discussion.

Original issue reported on code.google.com by [email protected] on 4 Jun 2009 at 11:22

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant