Admin forced to change users password when masquerading as another user
Bug #1222200 reported by
Nitish Bezzala
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Mahara |
Fix Released
|
Low
|
Robert Lyon |
Bug Description
Admin logs into the site and creates a new user, specifying a username and password.
He visits the new users profile page, and clicks the 'Log in as' button.
Admin gets the 'Change password screen' with the message 'You are required to change your password before you can proceed.'
Only the actual user should see the change password screen, and not the mahara site admin.
Changed in mahara: | |
importance: | Undecided → Critical |
importance: | Critical → Low |
assignee: | nobody → Robert Lyon (robertl-9) |
status: | New → In Progress |
Changed in mahara: | |
status: | In Progress → Fix Committed |
milestone: | none → 1.8.0rc1 |
Changed in mahara: | |
milestone: | 1.8rc1 → 1.8.0 |
Changed in mahara: | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
the admin can circumvent having to put it a new password by clicking the link "log in anyway". I think it is good to have this screen as it is (maybe make the option to log in without having to change password more prominent) because then the admin could test the password change functionality and is also reminded that they log in as another user.