Details
-
Bug
-
Status: Closed (View Workflow)
-
P2
-
Resolution: Done
-
None
-
CP: sprint 90
-
Core: Platform
-
Q2 2020
Description
A POST request to authn/credentials allows for passwords consisting of an empty string. This should not be permissible.
POST https://folio-snapshot-okapi.aws.indexdata.com/authn/credentials { "password":"", "username":"testy", "userId":"011bb48f-6ed3-4e62-b5b1-cf909dc7f8ce", "id":"6d924f95-671a-48b8-b0bd-9c0b6c4d448a" }
N.B. This also applies to POST authn/update and should be addressed in both places.
TestRail: Results
Attachments
Issue Links
- is blocked by
-
MODLOGIN-131 reset password fails if credentials record does not already exist
-
- Closed
-
-
UIU-1671 do not create credentials record when adding username
-
- Closed
-
- relates to
-
MODLOGIN-128 It is possible to fetch password hashes for all users
-
- Closed
-
-
MODLOGIN-132 Do not return credential hash/salt when posting credentials
-
- Closed
-
-
MODLOGIN-133 Remove PUT /authn/credentials/<id>
-
- Closed
-
-
MODLOGIN-134 Refactor DELETE /authn/credentials/<id>
-
- Closed
-
-
UIU-1672 if username is present, display "send reset password" link
-
- Closed
-