Page MenuHomePhabricator

Email notification to old address when verified email address is changed or removed
Closed, ResolvedPublic

Description

If a verified email address is changed or removed, an email notification should be sent to the old address. The email is for informational purposes only, it should not contain any verification codes. The main purpose of this is a reasonable defense against account cracking.

Discussion on en.wp: [[Wikipedia:Village pump (proposals)/Account security#Notify of removal of verified email address]]


Version: unspecified
Severity: enhancement

Related Objects

StatusSubtypeAssignedTask
ResolvedGalorefitz
Resolvedkostajh
OpenNone
ResolvedNone
OpenNone
ResolvedShivanshbindal9
ResolvedShivanshbindal9
OpenNone
ResolvedShivanshbindal9
ResolvedShivanshbindal9
ResolvedShivanshbindal9
OpenNone
ResolvedNone
DuplicateNone
Resolved JMinor
OpenBUG REPORTNone
Resolvedmatmarex

Event Timeline

bzimport raised the priority of this task from to Low.Nov 21 2014, 11:27 PM
bzimport added a project: MediaWiki-Email.
bzimport set Reference to bz29856.
bzimport added a subscriber: Unknown Object (MLST).
Devirk set Security to None.
Devirk subscribed.

Change 276563 had a related patch set uploaded (by Galorefitz):
User.php: Update 'setEmailWithConfirmation' for notification email

https://gerrit.wikimedia.org/r/276563

Change 276563 merged by jenkins-bot:
User.php: Update 'setEmailWithConfirmation' for notification email

https://gerrit.wikimedia.org/r/276563

Change #1165073 had a related patch set uploaded (by Reedy; author: Michael Große):

[mediawiki/core@REL1_43] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165073

Change #1165086 had a related patch set uploaded (by Reedy; author: Michael Große):

[mediawiki/core@REL1_39] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165086

Change #1165099 had a related patch set uploaded (by Reedy; author: Michael Große):

[mediawiki/core@REL1_44] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165099

Change #1165086 merged by jenkins-bot:

[mediawiki/core@REL1_39] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165086

Change #1165114 had a related patch set uploaded (by Reedy; author: Michael Große):

[mediawiki/core@master] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165114

Change #1165133 had a related patch set uploaded (by Reedy; author: Michael Große):

[mediawiki/core@REL1_42] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165133

Change #1165099 merged by jenkins-bot:

[mediawiki/core@REL1_44] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165099

Change #1165073 merged by jenkins-bot:

[mediawiki/core@REL1_43] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165073

Change #1165114 merged by jenkins-bot:

[mediawiki/core@master] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165114

Change #1165133 merged by jenkins-bot:

[mediawiki/core@REL1_42] SECURITY: fix IP leak to unverified email

https://gerrit.wikimedia.org/r/1165133