Uploaded image for project: 'Jackrabbit Oak'
  1. Jackrabbit Oak
  2. OAK-9245

UserValidator.propertyChanged may miss plaintext password

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 1.36.0
    • core, security
    • None

    Description

      UserValidator.propertyChanged only verifies if the password property has not been changed to plain-text if the nodestate before the modification was a user node. inserting a user by modifying the primary type of an non-user node, would result in the pw constraint not being properly validated.

      Attachments

        Activity

          People

            angela Angela Schreiber
            angela Angela Schreiber
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: