Gossamer Forum
Home : Products : Gossamer Links : Version 1.x :

User log on (signup)

Quote Reply
User log on (signup)
I just noticed if a user tries to sign up for the site, and gives a valid UserID and PW, they are logged on while being informed the Username/Password/Email have already been taken.

While this might seem like a good idea, it's also a security hole... sure they could enter that PW/ID ... but they really should be told that the PW/ID/Email is already in use.

Quote Reply
Re: User log on (signup) In reply to
it's one of many bugs to user.cgi

i already gave alex the fix for it like 3 days ago..

it doesn't actually log them in.. it says they are registered.. but they are not..

http://www.gossamer-threads.com/...um9/HTML/000459.html

jerry