Page MenuHomePhabricator

Should not show if username exists on failed login on private wikis.
Closed, ResolvedPublic

Description

Currently on failed log in, users are shown different messages if the username does or does not exist. If anons don't have read rights to special:listusers, the same message for auth failure should be used regardless of if the tried username exists or not.

Otherwise a user could discover who has an account at the secret cabal wikis by trying different account names in the log in form and observing the error message.

This was discussed the other day on irc, and I thought i'd file a bug so it isn't forgotten about.


Version: 1.18.x
Severity: enhancement

Details

Reference
bz27751

Event Timeline

bzimport raised the priority of this task from to Medium.Nov 21 2014, 11:26 PM
bzimport set Reference to bz27751.
bzimport added a subscriber: Unknown Object (MLST).
  • This bug has been marked as a duplicate of bug 11757 ***