Description
So basically, we requested a merge. It contained a sign in with scratch username and password form. That makes users feel like it is insecure even though it does not store it. Also that means ANYONE can hack into ANYONE’S account. We need to add scratch Auth or commenting Auth
Impact
Everyone who goes to the Account Page and signs in gets impacted
Patches
Not yet
Workarounds
Currently it’s secure if you don’t sign in
References
These issues:
Description
So basically, we requested a merge. It contained a sign in with scratch username and password form. That makes users feel like it is insecure even though it does not store it. Also that means ANYONE can hack into ANYONE’S account. We need to add scratch Auth or commenting Auth
Impact
Everyone who goes to the Account Page and signs in gets impacted
Patches
Not yet
Workarounds
Currently it’s secure if you don’t sign in
References
These issues: