Re: ***UNCHECKED*** Does anybody have a use case for users with empty passwords?

Ralf Schlatterbeck <[email protected]>
Newsgroups gmane.comp.bug-tracking.roundup.user
Message-ID <[email protected]>
On Fri, Jul 19, 2019 at 04:19:37PM -0400, John P. Rouillard wrote:
> Hi all:
> 
> In running my demo tracker, I realized that users without any password
> are allowed to log in.
> 
> Does anybody have a use case where a user without a password should be
> able to login to the web interface?

Hmm, I don't think allowing users with no passwords to log in is a good
idea. If you want everyone to allow access you could assign the
necessary permissions to the anonymous user.

But that doesn't mean that the password field is used in all scenarios.
I'm using Kerberos Auth behind Apache in some installations and AFAIK
the passwords will be empty in those trackers (Apache authenticates the
user via Kerberos in that case, there is no password).

Ralf
-- 
Dr. Ralf Schlatterbeck                  Tel:   +43/2243/26465-16
Open Source Consulting                  www:   http://www.runtux.com
Reichergasse 131, A-3411 Weidling       email: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.