Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add current password field to prevent unauthorized users from changing password of the current user #2428

Open
Nenge1 opened this issue Aug 17, 2017 · 4 comments

Comments

@Nenge1
Copy link
Contributor

Nenge1 commented Aug 17, 2017

Link,
Mifos dropdown->profile>change password

image

Allowing user to enter only new password increase vulnerability because the username is visible.

@santoshconflux
Copy link
Collaborator

@mbj36 , this is one of the much-needed enhancement and let me know whether it requires fixing at the Fineract side as well.

@mbj36
Copy link
Member

mbj36 commented Aug 23, 2017

@gkrishnan724 Can you check API is available or not ?

@gkrishnan724
Copy link
Collaborator

@santoshmath @mbj36 I believe this issue should be created at fineract side.

@santoshconflux
Copy link
Collaborator

santoshconflux commented Aug 28, 2017

@gkrishnan724 , Created at Fineract side:

https://issues.apache.org/jira/browse/FINERACT-516

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

5 participants