Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

User can reset password without current password #12676

Closed
3 tasks
liamnv opened this issue Jan 22, 2021 · 5 comments
Closed
3 tasks

User can reset password without current password #12676

liamnv opened this issue Jan 22, 2021 · 5 comments
Assignees
Labels
authentication:access-control Rlated to access control !deprecated-label:bug Deprecated label - Use #bug instead inactive Inactive for >= 30 days

Comments

@liamnv
Copy link
Contributor

liamnv commented Jan 22, 2021

A clear and concise description of what the bug is.

Expected results

User must provide current password to reset password

Actual results

User can reset password without of current password

Screenshots

If applicable, add screenshots to help explain your problem.

How to reproduce the bug

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. See error

Environment

(please complete the following information):

  • superset version: superset version
  • python version: python --version
  • node.js version: node -v

Checklist

Make sure to follow these steps before submitting your issue - thank you!

  • I have checked the superset logs for python stacktraces and included it here as text if there are any.
  • I have reproduced the issue with at least the latest released version of superset.
  • I have checked the issue tracker for the same issue and I haven't found one similar.

Additional context

Add any other context about the problem here.

@liamnv liamnv added the #bug Bug report label Jan 22, 2021
@lamielle
Copy link
Contributor

@liamnv can you provide a few more details on the bug you're reporting here? This could be a serious security issue. I'm relatively new to Superset but I think providing more information per the issue template would help the Superset team triage this bug.

@liamnv
Copy link
Contributor Author

liamnv commented Jan 26, 2021

@lamielle I found this is an issue of Flask App Builder, I'm contributing for its here dpgaspar/Flask-AppBuilder#1553

@mistercrunch
Copy link
Member

@dpgaspar ^^^

@zuzana-vej zuzana-vej added !deprecated-label:bug Deprecated label - Use #bug instead authentication:access-control Rlated to access control and removed #bug Bug report labels Apr 20, 2021
@stale
Copy link

stale bot commented May 2, 2022

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. For admin, please label this issue .pinned to prevent stale bot from closing the issue.

@stale stale bot added the inactive Inactive for >= 30 days label May 2, 2022
@rusackas
Copy link
Member

rusackas commented Feb 5, 2024

This is likely fixed by now, and is pretty out of date if not. If people are still encountering this in current versions (3.x) please open a new Issue or a PR to address the problem.

@rusackas rusackas closed this as completed Feb 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
authentication:access-control Rlated to access control !deprecated-label:bug Deprecated label - Use #bug instead inactive Inactive for >= 30 days
Projects
None yet
Development

No branches or pull requests

6 participants