Skip to content

Conversation

sgiehl
Copy link
Member

@sgiehl sgiehl commented Aug 9, 2022

Description:

This also adds the requirement to provide a password confirmation to the method UsersManager.addUser, but as the method in not longer used in the UI, this will only prevent it being "misused" with a session auth.

Review

@sgiehl sgiehl added c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github. Needs Review PRs that need a code review labels Aug 9, 2022
@sgiehl sgiehl added this to the 4.12.0 milestone Aug 9, 2022
Copy link
Contributor

@bx80 bx80 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested that the password confirmation is shown when inviting a user, works well.

@bx80
Copy link
Contributor

bx80 commented Aug 17, 2022

Not sure why one of the UI screenshots is out by one pixel, I'll update it again just to be sure.

@bx80 bx80 merged commit 3b78161 into 4.x-dev Aug 17, 2022
@bx80 bx80 deleted the adduserconfirm branch August 17, 2022 02:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github. Needs Review PRs that need a code review
Development

Successfully merging this pull request may close these issues.

2 participants