[SAC] [OSGeo] #1804: password reset resets wrong password if a user has >1 account on an email address

#1804: password reset resets wrong password if a user has >1 account on an email
address
---------------------------+---------------------
Reporter: rduivenvoorde | Owner: sac@…
     Type: task | Status: closed
Priority: normal | Milestone:
Component: SysAdmin | Resolution: fixed
Keywords: |
---------------------------+---------------------
Changes (by strk):

* status: new => closed
* resolution: => fixed

Old description:

Somebody (well I'm not aware it was myself) created a (now removed) user
'test' in ldap, and used my email address with it, which already is used
in my personal user account...

BUT trying to reset the 'test' user, my own account's password was
actually rest as shown in the email:
The temporary password for the OSGeo Userid "rduivenvoorde" is "****".

So we cannot even rest the test-user password.

I think it should not be possible to add a user with an already
available/used email address?

OR the reset form should work on account name and not with email address?

New description:

Somebody (well I'm not aware it was myself) created a (now removed) user
'test' in ldap, and used my email address with it, which already is used
in my personal user account...

BUT trying to reset the 'test' user, my own account's password was
actually rest as shown in the email:
The temporary password for the OSGeo Userid "rduivenvoorde" is "****".

So we cannot even rest the test-user password.

I think it should not be possible to add a user with an already
available/used email address?

OR the reset form should work on account name and not with email address?

--
Comment:

today it is not possible to register a user with the same email as another
existing user
--
Ticket URL: <#1804 (password reset resets wrong password if a user has >1 account on an email address) – OSGeo;
OSGeo <Gter - OSGeo;
OSGeo committee and general foundation issue tracker.