?
avatar PhilETaylor
PhilETaylor
19 Nov 2017

Steps to reproduce the issue

Create a user, its username can be exactly the same as the password

like

username: admin
password: admin

Expected result

That Joomla holds itself to better security/validation than this and doesn't allow this in the future. Why on earth would we allow this, I cannot see any justification.

Actual result

admin/admin is valid.
user/user is valid.

avatar PhilETaylor PhilETaylor - open - 19 Nov 2017
avatar joomla-cms-bot joomla-cms-bot - change - 19 Nov 2017
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 19 Nov 2017
avatar brianteeman
brianteeman - comment - 19 Nov 2017

as always - pull requests welcome

avatar franz-wohlkoenig franz-wohlkoenig - change - 20 Nov 2017
Category Authentication
avatar franz-wohlkoenig franz-wohlkoenig - change - 20 Nov 2017
Status New Discussion
avatar franz-wohlkoenig franz-wohlkoenig - change - 21 Nov 2017
Status Discussion Closed
Closed_Date 0000-00-00 00:00:00 2017-11-21 06:25:40
Closed_By franz-wohlkoenig
avatar joomla-cms-bot joomla-cms-bot - change - 21 Nov 2017
Closed_By franz-wohlkoenig joomla-cms-bot
avatar joomla-cms-bot joomla-cms-bot - close - 21 Nov 2017
avatar joomla-cms-bot
joomla-cms-bot - comment - 21 Nov 2017
avatar franz-wohlkoenig
franz-wohlkoenig - comment - 21 Nov 2017

closed as having Pull Request #18766

Add a Comment

Login with GitHub to post a comment