Page 1 of 1

Duplicate E-mail Addresses

Posted: Mon Jan 30, 2012 8:02 pm
by cuervo5150
Greetings,

I just stumbled across a little loophole that I want to bring to your attention.

I do not allow duplicate email addresses on my site and have that system setting set to "no" on my server. However, I just noticed that players could use Account/Change Info, to successfully enter an email address already in use. Of course I could set the Allow Account Changes option to "no", but then players would not be able to change anything inside of PM.

Also, players can enter a duplicate email if the Allow Password Recovery option is turned on. They can select the new email pip, and successfully enter an email address already in the system.

I just updated my test server to 2.92 and found these apply to that version as well.

BTW: your new rake utility is pretty cool!

Re: Duplicate E-mail Addresses

Posted: Mon Jan 30, 2012 8:37 pm
by Kent Briggs
Thanks, I'll take a look.

Re: Duplicate E-mail Addresses

Posted: Mon Jan 30, 2012 9:18 pm
by Kent Briggs
cuervo5150 wrote: Also, players can enter a duplicate email if the Allow Password Recovery option is turned on.
I assume you meant the "Validate email addresses" option, correct?

Re: Duplicate E-mail Addresses

Posted: Mon Jan 30, 2012 9:25 pm
by cuervo5150
Ooops, yes....That's what I ment.

Re: Duplicate E-mail Addresses

Posted: Wed Feb 01, 2012 4:56 pm
by Kent Briggs
This should now be fixed in 2.93