Skip to content

Confusing "almost logged in" state #385

Open
@revolter

Description

I tried logging in, and something weird happened. Here are some screenshots for context:

Before After

It told me that the credentials are wrong, but at the same time, somehow, a profile picture and username of mine were displayed.

This means that anyone who knows my email address can type something random for the password and access this information, and I feel like this shouldn't be possible.

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions