Skip to content

Email verification link of a deleted account enables automatic login #2031

@bajiat

Description

@bajiat

From @saralavanip on January 25, 2017 16:53

Steps

  1. Visit https://staging.apinf.io (version 0.39.0)
  2. Create account 1 (eg. with email address: test1@test.com)
  3. Open email and click on account 1 verification link
  4. Visit https://staging.apinf.io
  5. Login as admin and delete the above added account
  6. Logout
  7. Create another account 2 (eg. with email address: test2@test.com)
  8. Open email and click on account 2 verification link
  9. Repeat step 3

Findings

  • Click on email verification link of a deleted account, enables automatic login to the latest active account.
  • Displays error message 'Verify email link Expired'

Screenshot

screenshot 90

Copied from original issue: Digipalvelutehdas/APIKA#297

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions