Last modified: 2011-04-14 19:56:46 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T29751, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 27751 - Should not show if username exists on failed login on private wikis.
Should not show if username exists on failed login on private wikis.
Status: RESOLVED DUPLICATE of bug 11757
Product: MediaWiki
Classification: Unclassified
User login and signup (Other open bugs)
1.18.x
All All
: Normal enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2011-02-26 20:49 UTC by Bawolff (Brian Wolff)
Modified: 2011-04-14 19:56 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Bawolff (Brian Wolff) 2011-02-26 20:49:12 UTC
Currently on failed log in, users are shown different messages if the username does or does not exist. If anons don't have read rights to special:listusers, the same message for auth failure should be used regardless of if the tried username exists or not.

Otherwise a user could discover who has an account at the secret cabal wikis by trying different account names in the log in form and observing the error message.

This was discussed the other day on irc, and I thought i'd file a bug so it isn't forgotten about.
Comment 1 Alexandre Emsenhuber [IAlex] 2011-04-14 19:56:46 UTC

*** This bug has been marked as a duplicate of bug 11757 ***

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links