Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Technique] [Sécurité] La demande de récup du mot de passe doit retourner une réponse unique #2644

Closed
numew opened this issue Jun 4, 2024 · 0 comments

Comments

@numew
Copy link
Collaborator

numew commented Jun 4, 2024

Elle ne doit pas permettre de détecter is un compte existe avec cet email.
Idem pour la demande d'activation du compte

Screenshot 2024-06-03 at 16-59-13 2023_Apilos_Tests_Intrusion pdf

@numew numew created this issue from a note in Backlog 🪵 (🟢 Dans le sprint - To do) Jun 4, 2024
@numew numew changed the title [Technique] [Sécurité] La demande de récup du mot de passe ne doit pas permettre d'itenfier si un compte existe [Technique] [Sécurité] La demande de récup du mot de passe doit retourner une réponse unique Jun 4, 2024
@numew numew self-assigned this Jun 5, 2024
@emilschn emilschn added this to the Securité milestone Jun 6, 2024
numew added a commit that referenced this issue Jun 6, 2024
@mathildepoulpux mathildepoulpux modified the milestones: Securité, v2.2.1 Jun 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: En prod
Backlog 🪵
🟢 Dans le sprint - To do
Development

No branches or pull requests

4 participants