[SAC] [OSGeo] #1683: Refuse to create an OSGeo UserID associated with the email address of an already existing user

#1683: Refuse to create an OSGeo UserID associated with the email address of an
already existing user
---------------------------+--------------------------
Reporter: strk | Owner: sac@…
     Type: task | Status: new
Priority: normal | Milestone:
Component: Systems Admin | Keywords: ldap, userid
---------------------------+--------------------------
In order to reduce possible email abuse we should forbid the creation of
multiple users associated with the same email. This is to allow for email-
based recognition of fake/malicious users, for example.

Also, users that create a new account with the same email might be just
missing a "password reset" procedure instead, so it would be better to
propose an alternative.

--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/1683&gt;
OSGeo <http://www.osgeo.org/&gt;
OSGeo committee and general foundation issue tracker.

#1683: Refuse to create an OSGeo UserID associated with the email address of an
already existing user
---------------------------+--------------------
Reporter: strk | Owner: sac@…
     Type: task | Status: new
Priority: normal | Milestone:
Component: Systems Admin | Resolution:
Keywords: ldap, userid |
---------------------------+--------------------

Comment (by strk):

When refusing to create such an account, a message should clearly state
how to contact an administrator, as with the mantra-based registration in
its current incarnation.

--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/1683#comment:1&gt;
OSGeo <http://www.osgeo.org/&gt;
OSGeo committee and general foundation issue tracker.

On 05/15/2016 04:28 AM, OSGeo wrote:

#1683: Refuse to create an OSGeo UserID associated with the email address of an
already existing user
---------------------------+--------------------
Reporter: strk | Owner: sac@…
     Type: task | Status: new
Priority: normal | Milestone:
Component: Systems Admin | Resolution:
Keywords: ldap, userid |
---------------------------+--------------------

Comment (by strk):

When refusing to create such an account, a message should clearly state
how to contact an administrator, as with the mantra-based registration in
its current incarnation.

--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/1683#comment:1&gt;
OSGeo <http://www.osgeo.org/&gt;
OSGeo committee and general foundation issue tracker.
_______________________________________________
Sac mailing list
Sac@lists.osgeo.org
http://lists.osgeo.org/mailman/listinfo/sac

+1 we should not allow multiple accounts for the same email address.
Rather we should implement an email based password reset.

-Alex

On Mon, May 16, 2016 at 08:27:16AM -0700, Alex Mandel wrote:

On 05/15/2016 04:28 AM, OSGeo wrote:
> #1683: Refuse to create an OSGeo UserID associated with the email address of an

> Ticket URL: <#1683 (Refuse to create an OSGeo UserID associated with the email address of an already existing user) – OSGeo;

+1 we should not allow multiple accounts for the same email address.
Rather we should implement an email based password reset.

As recently reported (I think) I did write a script for password
reset. It's not exposed on the web, but is available as a script
to those having root access to the "web" machine. Feel free to
ticket that one if not already ticketed (web based reset).

How to prevent gathering of mass email addresses would be another
thing to keep in mind for _this_ specific ticket. But why are
we talking on the list rather than in the ticket ? Simpler to reply ?
We may want to add setup email2trac
(#897 (Install email2trac) – OSGeo)
Or if you're a mutt user you might like:
strk's projects - cartman-mutt

--strk;

#1683: Refuse to create an OSGeo UserID associated with the email address of an
already existing user
---------------------------+---------------------
Reporter: strk | Owner: sac@…
     Type: task | Status: closed
Priority: normal | Milestone:
Component: Systems Admin | Resolution: fixed
Keywords: ldap, userid |
---------------------------+---------------------
Changes (by strk):

* status: new => closed
* resolution: => fixed

Comment:

Fixed: https://git.osgeo.org/gogs/sac/web-cgi-
bin/commit/43ca5918decf4b0faba471647fe14de84951c52d

--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/1683#comment:2&gt;
OSGeo <http://www.osgeo.org/&gt;
OSGeo committee and general foundation issue tracker.