protection for openid identities

chungyc - April 2, 2009 - 11:05
Project:User Protect
Version:6.x-1.x-dev
Component:Code
Category:bug report
Priority:normal
Assigned:Unassigned
Status:closed
Description

OpenID is a core module, but User Protect does not protect the editing of OpenID identities at all, so any user with the administer user permission can add an OpenID to the administrator account and obtain a way to login as the administrator without having to edit the password.

#1

hunmonk - April 2, 2009 - 13:59

i don't know a thing about open ID, so if anybody wants this fixed, please feel free to submit a patch, and i'll review and commit if it's quality.

#2

DanielTheViking - June 2, 2009 - 10:49

Second that. OpenIDs changes should definetely be possible to protect.

(Would also be useful if certain roles could be notified by email on selected changes. I just filed a feature request about that. That would help delegate in a somewhat controlled manner. OpenID changes would be one of those special changes that would be extra useful to "secure"/"monitor".)

#3

hunmonk - October 15, 2009 - 21:09
Status:active» needs review

here you go. adds an openid protection to all aspects of the module, including a 'change own openid' permission for users.

anybody able to try this out and see if it works ok?

AttachmentSize
up_openid.patch 8.45 KB

#4

chungyc - October 24, 2009 - 01:39

I tried it on my site, and the OpenID protection patch seems to be working.

#5

hunmonk - October 24, 2009 - 03:31
Title:No protection for OpenID identities» protection for openid identities
Version:6.x-1.2» 7.x-1.x-dev
Status:needs review» fixed

committed to 6.x-1.x-dev.

#6

hunmonk - October 24, 2009 - 03:41
Version:7.x-1.x-dev» 6.x-1.x-dev

#7

System Message - November 7, 2009 - 03:50
Status:fixed» closed

Automatically closed -- issue fixed for 2 weeks with no activity.

 
 

Drupal is a registered trademark of Dries Buytaert.