Last modified: 2012-04-16 09:15:46 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T29310, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 27310 - Password reset form does not include domain information
Password reset form does not include domain information
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
User preferences (Other open bugs)
unspecified
All All
: Normal enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2011-02-11 01:03 UTC by Ryan Lane
Modified: 2012-04-16 09:15 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Ryan Lane 2011-02-11 01:03:45 UTC
The password reset form does not include domain information, or set the domain when resetting the password. This causes problems with the LDAP authentication plugin when passwords are reset.

After the user's password is reset they are logged in, but their session does not have wsDomain set, leading to strange behavior.
Comment 1 Ryan Lane 2011-02-11 01:33:42 UTC
Actually, this is worse in trunk than I thought. Password changing no longer works with LDAP at all. Since the domain isn't set when the form is loaded, wgAuth->allowPasswordChange() returns false.
Comment 2 Ryan Lane 2011-02-11 17:40:18 UTC
I've gotten to a point where password canges work by including the domain information in SpecialResetpass (r81978), but the session issue persists.

After the user changes the password, and is logged in, wsDomain disappears from the session. Somehow the user must be getting a new session without the domain properly added.
Comment 3 Ryan Lane 2011-02-11 18:50:21 UTC
Actually, on further testing r81978 fixes this (thanks to Reedy for his midas touch).

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links