Skip to content

Different userURL still shows the form #31

@sebsel

Description

@sebsel

In my testing, when I used a different userURL, the form seems to accept it. Of course, the password will not match etc, so there will be no signed code, but maybe we can display the username, or, since we only support one, check for a valid one before showing the form?

After thinking about it: maybe we should not give away that information? The genuine user will not be in this situation, only when people will fiddle with the params.

On the other hand: what happens with https vs http / if the user changes his URL?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions