Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 431106 - Forum Comfirmation Email Includes Plaintext Password
Summary: Forum Comfirmation Email Includes Plaintext Password
Status: UNCONFIRMED
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Forums (show other bugs)
Hardware: All Linux
: Normal major with 3 votes (vote)
Assignee: Forum Moderators
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-08-12 17:14 UTC by Jeffrey Walton
Modified: 2020-08-02 11:02 UTC (History)
8 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Forums: Email with plain text password (gentoo-forum-email-with-plaintext-password.png,198.75 KB, text/plain)
2012-08-12 17:14 UTC, Jeffrey Walton
Details
Changes email templates in all languages (htdocs+translations) (Remove {PASSWORD} token from email templates,90.88 KB, patch)
2015-10-09 02:05 UTC, zamabe
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Jeffrey Walton 2012-08-12 17:14:30 UTC
Created attachment 321138 [details]
Forums: Email with plain text password

After registering for a Gentoo forum account, the system emailed me my password in plain text.

(1) There was no need to email me the password since I choose it. (2) Its not appropriate to transmit secrets this way - and there was no need due to (1).

If Gentoo forums wants to email plain text passwords and other secrets, perhaps it should generate a random, throw-away password to share with the world.
Comment 1 zamabe 2015-10-09 02:05:40 UTC
Created attachment 414168 [details, diff]
Changes email templates in all languages (htdocs+translations)

Remove {PASSWORD} token from email templates.

This prevents user passwords being emailed in plain text.
Following the phpBB v3 email templates, the only template which
does send a password is the user_activate_passwd template because
it is the only one which sends a password the user did not provide.

I suspect the diff paths may not be what you want to apply this.
Let me know if/what to change them to if this is the case :)