Re: ***UNCHECKED*** Does anybody have a use case for users with empty passwords?
Ralf Schlatterbeck <[email protected]>
| Newsgroups | gmane.comp.bug-tracking.roundup.user |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Jul 19, 2019 at 04:19:37PM -0400, John P. Rouillard wrote: > Hi all: > > In running my demo tracker, I realized that users without any password > are allowed to log in. > > Does anybody have a use case where a user without a password should be > able to login to the web interface? Hmm, I don't think allowing users with no passwords to log in is a good idea. If you want everyone to allow access you could assign the necessary permissions to the anonymous user. But that doesn't mean that the password field is used in all scenarios. I'm using Kerberos Auth behind Apache in some installations and AFAIK the passwords will be empty in those trackers (Apache authenticates the user via Kerberos in that case, there is no password). Ralf -- Dr. Ralf Schlatterbeck Tel: +43/2243/26465-16 Open Source Consulting www: http://www.runtux.com Reichergasse 131, A-3411 Weidling email: [email protected]