<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>Forgot Password dialog presents empty security question if none is set</title> 
  <pubDate>Fri, 10 Apr 2026 18:27:14 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/10430</link> 
  <atom:link rel="self" type="application/rss+xml" title="Forgot Password dialog presents empty security question if none is set" href="https://bugs.horde.org/ticket/10430/rss" /> 
  <description>Forgot Password dialog presents empty security question if none is set</description> 
 
   
   
  <item> 
   <title>HOW TO REPRODUCE:
A user enters an alternate_email but no s</title> 
   <description>HOW TO REPRODUCE:
A user enters an alternate_email but no security question/answer.
He logs out and clicks &quot;Forgot password&quot;.
He provides username and alternate email.

EFFECT:
He is presented an empty security question and an answer field which does not accept any input (empty line complains about &quot;required&quot;, any input would not match backend content.

EXPECTED BEHAVIOUR:

Either do not present security question if none is set or forbid reset self service if none is set. I would go for the former though there is a slight potential of DoS in setups where alternate_email is auto-set/required.

ACTION:

I would patch that according to &quot;do not present security question if none is set &quot;. 
Please post any disagreements.</description> 
   <pubDate>Tue, 16 Aug 2011 10:52:36 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10430#t66990</link> 
  </item> 
   
  <item> 
   <title>Changes have been made in Git for this ticket:

[rla] Don&#039;t </title> 
   <description>Changes have been made in Git for this ticket:

[rla] Don&#039;t present security question dialog if none is set #10430

 1 files changed, 8 insertions(+), 5 deletions(-)
http://git.horde.org/horde-git/-/commit/98e7ed658b56dbbdaafcf321b459652a8cd75ef2</description> 
   <pubDate>Tue, 16 Aug 2011 14:19:03 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10430#t66992</link> 
  </item> 
   
  <item> 
   <title>Changes have been made in Git for this ticket:

[rla] Don&#039;t </title> 
   <description>Changes have been made in Git for this ticket:

[rla] Don&#039;t present security question dialog if none is set #10430

 2 files changed, 3 insertions(+), 2 deletions(-)
http://git.horde.org/horde-git/-/commit/84e8bd5b011c31ba6b071864f65c989b3acae1f3</description> 
   <pubDate>Tue, 16 Aug 2011 14:19:11 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10430#t66993</link> 
  </item> 
   
  <item> 
   <title>Changes have been made in Git for this ticket:

Revert &quot;[rla</title> 
   <description>Changes have been made in Git for this ticket:

Revert &quot;[rla] Don&#039;t present security question dialog if none is set #10430&quot; This is contested on &lt;dev@&gt; and wrong branch anyway This reverts commit 84e8bd5b011c31ba6b071864f65c989b3acae1f3. This reverts commit 98e7ed658b56dbbdaafcf321b459652a8cd75ef2.

 3 files changed, 7 insertions(+), 11 deletions(-)
http://git.horde.org/horde-git/-/commit/14b5e0749000e0d5740a93e816c1e212e99390dc</description> 
   <pubDate>Tue, 16 Aug 2011 15:02:10 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10430#t66994</link> 
  </item> 
   
  <item> 
   <title>Changes have been made in Git for this ticket:

[rla] Reset </title> 
   <description>Changes have been made in Git for this ticket:

[rla] Reset password dialog shows a warning when no security question is set #10430

 3 files changed, 7 insertions(+), 2 deletions(-)
http://git.horde.org/horde-git/-/commit/c05dbf0330f21de8d6ffad6098ba7af3db85ba11</description> 
   <pubDate>Wed, 17 Aug 2011 14:41:50 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10430#t67018</link> 
  </item> 
   
  <item> 
   <title>It was decided that skipping security question is unsafe. 
</title> 
   <description>It was decided that skipping security question is unsafe. 
Users now get a warning if no security question is set when they try to reset their password.</description> 
   <pubDate>Wed, 17 Aug 2011 14:43:38 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/10430#t67019</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
