Re: Reauthorization for changes

John Rouillard via Roundup-users <[email protected]> Thu, 14 Aug 2025 10:37:45 -0400
Newsgroups gmane.comp.bug-tracking.roundup.user
Message-ID <CANfx4mv0s7nVy-vaiUP_mDKAmquwa9mswc_fbWu9PzSW2ECqzQ@mail.gmail.com>
Hi all:

The Reauth code has been pushed to the mercurial sourceforge repo on the
reauth-confirm_id branch.  I am keeping the Reauth naming scheme since
that's closer to how OWASP refers to it.

Please take a look at the docs. I have updated the upgrade documents,
the customization document and the reference document along with adding
the appropriate modules/classes to the pydoc generated from docstrings.
Also check out the code and test for the workflow. The test code could use
some refactoring.

The last question I have is should I add the reauth workflow when changing a
user's password or address to the packaged templates?

I'm planning on merging it this weekend.

Thoughts, comments?

Thanks.

-- rouilj