Page MenuHomePhabricator

Logging in with a temporary password doesn't really log me in while logged in as another user
Open, LowPublic

Description

Repro:

  1. Request a password reset for User:A
  2. Log in to the wiki as User:B
  3. Go to [[Special:UserLogin]]
  4. Try to log in as User:A using the password in the mail
  5. Follow the instruction to set a new password for User:A

Result:

I'm still logged in as User:B.

Expected:

I'm now logged in as User:A.


Version: 1.22.0
Severity: normal

Details

Reference
bz48499

Event Timeline

bzimport raised the priority of this task from to Low.Nov 22 2014, 1:37 AM
bzimport set Reference to bz48499.
bzimport added a subscriber: Unknown Object (MLST).

btw the instruction in step 5 is:

You logged in with a temporary emailed code. *To finish logging in*, you must set a new password here:

Shamless plug: one way to fix this is to get rid of temporary passwords entirely (https://gerrit.wikimedia.org/r/27472)