#36954 closed defect (bug) (fixed)
Cancelling an admin email address change on Multisite lacks a nonce
Reported by: |
|
Owned by: |
|
---|---|---|---|
Milestone: | 4.6 | Priority: | lowest |
Severity: | minor | Version: | |
Component: | Administration | Keywords: | good-first-bug has-patch |
Focuses: | multisite | Cc: |
Description
The change of admin email address on a site in Multisite requires the link in a confirmation email to be clicked before it's activated. The "Cancel" link shown next to the "Email Address" field on the General Settings screen during that process lacks a nonce.
Attachments (2)
Change History (10)
#2
@
9 years ago
- Keywords has-patch added; needs-patch removed
- Milestone changed from Awaiting Review to 4.6
This ticket was mentioned in Slack in #core-multisite by flixos90. View the logs.
9 years ago
#6
@
9 years ago
@scottbasgaard Looks good! I made a small change in 36954.2.diff so that the nonce is unique based on the site ID. Otherwise the same "cancel" URL would work on multiple sites.
Note: See
TracTickets for help on using
tickets.
Nice find @johnbillion, gave it a quick go.