6.0.0-beta1
8/14/25

[#555] Login tricks
Summary Login tricks
Queue IMP
Queue Version RELENG_3
Type Bug
State Not A Bug
Priority 2. Medium
Owners
Requester aromanov (at) eerc (dot) kiev (dot) ua
Created 09/09/2004 (7644 days ago)
Due
Updated 09/09/2004 (7644 days ago)
Assigned
Resolved 09/09/2004 (7644 days ago)
Github Issue Link
Github Pull Request
Milestone
Patch No

History
09/09/2004 05:41:32 PM Chuck Hagenbuch Comment #2
State ⇒ Not A Bug
Reply to this comment
This is bogus in several ways. First, you're probably using the same 
browser, which shares cookies, and not logging out - either that, or 
you have the session id embedded in your "saved source" - so of course 
you see the accounts without auth.



Second, this is just way unsupported (and unsecure) behavior on your part.
09/09/2004 05:34:15 PM aromanov (at) eerc (dot) kiev (dot) ua Comment #1
State ⇒ Unconfirmed
Priority ⇒ 2. Medium
Type ⇒ Bug
Summary ⇒ Login tricks
Queue ⇒ IMP
Reply to this comment
Dear developers,



To simplify login procedure I saved the login page, inserted my login 
and password data into html source. Now I need just to click the 
button without typing it every time. When I tried to use the same 
modified login page for another account simply copying the file and 
changing the login and password data the strange thing occurred. Both 
accounts, then activated from the copied login pages, can have access 
to each other's mail. Probably this is due to the same identifier 
assigned to 'Horde2' input value that is used in both files. Although 
this is not a critical error, it potentially might be used for 
unauthorized access.



Thank you for consideration.

Alexander Romanov

Saved Queries