Uploaded image for project: 'JCommune'
  1. JCommune
  2. JC-1711

User can steal session to use the same captcha for registration

VotersWatchers
    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 2.4 Larks
    • Fix Version/s: 2.4 Larks
    • Labels:
      None
    • Environment:

      Firefox, Opera, IE, Chrome (latest versions)

    • Sprint:
      2.4 Larks

      Description

      Precondition:

      • User should be logged out

      Test scenario:

      1. Right click on "Sign Up" -> select "открыть в новой вкладке"
        Registration form opened in a new page
      2. Repeat first step: right click on "Sign Up" -> select "открыть в новой вкладке" to open a new page with registration form
      3. Fill out the registration form at the first opened page, with correct Username, Mail, Password and captcha text.
      4. Press Sign Up button and receive a message about successful registration
      5. Open second registration page and fill it with other(different) correct Username, Mail, Password
      6. Use the captcha text from previous registration
      7. Press Sign Up button

      AR: Message about successful registration received, user is registered
      ER: User should received a warning message under captcha text field about wrong text. User couldn't use the same captcha text for different registrations in one session

        Attachments

          Issue Links

            Structure

              Activity

                People

                • Assignee:
                  Pavel Gradobik Pavel Gradobik
                  Reporter:
                  Pavel Gradobik Pavel Gradobik
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  4 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:

                    Time Tracking

                    Estimated:
                    Original Estimate - Not Specified
                    Not Specified
                    Remaining:
                    Remaining Estimate - 0h
                    0h
                    Logged:
                    Time Spent - 4h
                    4h

                      Structure Helper Panel