Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-73135

Forgot password works while site is in maintenance mode

    XMLWordPrintable

Details

    • Bug
    • Status: Open
    • Minor
    • Resolution: Unresolved
    • 3.8 regressions
    • None
    • Administration
    • None

    Description

      When a site is put into a maintenance mode, it is possible for non-admin users to access the forgot password page (login/forgot_password.php) and reset their passwords.

      However users are subsequently unable to login on account of the site being in maintenance mode.

      In addition to this behaviour being confusing to users, it seems unwise to allow any action that changes data in the database while the site is in maintenance mode.

      To reproduce:

      1. Login as site admin and place site into maintenance mode.
      2. Select a non-admin user account to use for testing
      3. Visit the forgot password page and reset the password for the non-admin user account you selected above
      4. Go to the site login page and attempt to login as the non-admin user
      5. See a message saying that the site is in maintenance mode and can be accessed only by site administrators

       

      Attachments

        Activity

          People

            Unassigned Unassigned
            muyiwataiwo Olumuyiwa Taiwo
            Andrew Lyons, Huong Nguyen, Jun Pataleta, Michael Hawkins, Shamim Rezaie, Simey Lameze
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: