Re: ***UNCHECKED*** Does anybody have a use case for users with empty passwords?
Tom Ekberg <[email protected]>
| Newsgroups | gmane.comp.bug-tracking.roundup.user |
|---|---|
| Message-ID | <DM6PR08MB4778DA0DC9CA8629F7E8008ECAC40@DM6PR08MB4778.namprd08.prod.outlook.com> |
I agree. We use shibboleth for authentication so Apache takes care of it. The tracker password is empty for all of our users. Tom Ekberg Senior Computer Specialist, Lab Medicine 4th Floor, Pat Steel Building Department of Laboratory Medicine Work: (206) 520-4856 Email: [email protected] ________________________________ From: Ralf Schlatterbeck <[email protected]> Sent: Monday, July 22, 2019 2:35 AM To: [email protected] <[email protected]> Subject: Re: [Roundup-users] ***UNCHECKED*** Does anybody have a use case for users with empty passwords? On Fri, Jul 19, 2019 at 04:19:37PM -0400, John P. Rouillard wrote: > Hi all: > > In running my demo tracker, I realized that users without any password > are allowed to log in. > > Does anybody have a use case where a user without a password should be > able to login to the web interface? Hmm, I don't think allowing users with no passwords to log in is a good idea. If you want everyone to allow access you could assign the necessary permissions to the anonymous user. But that doesn't mean that the password field is used in all scenarios. I'm using Kerberos Auth behind Apache in some installations and AFAIK the passwords will be empty in those trackers (Apache authenticates the user via Kerberos in that case, there is no password). Ralf -- Dr. Ralf Schlatterbeck Tel: +43/2243/26465-16 Open Source Consulting www: http://www.runtux.com Reichergasse 131, A-3411 Weidling email: [email protected] _______________________________________________ Roundup-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/roundup-users _______________________________________________ Roundup-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/roundup-users