Duplicated and obsolete email change on user profile page #6223

Closed
opened 2025-11-02 06:48:57 -06:00 by GiteaMirror · 4 comments
Owner

Originally created by @WildCryptoFox on GitHub (Oct 28, 2020).

REDACTED. See email to security@gitea.io.

Originally created by @WildCryptoFox on GitHub (Oct 28, 2020). REDACTED. See email to security@gitea.io.
GiteaMirror added the topic/securitytype/bug labels 2025-11-02 06:48:57 -06:00
Author
Owner

@ashimokawa commented on GitHub (Oct 28, 2020):

What we did on codeberg.org is to just forbid to change the email there, it must be done in the account settings and then the primary email can be switched after confirming. So we just patched out the feature to do it in the settings directly.

We did not open an issue here but contacted you in January via the official way of reporting security problems.

@ashimokawa commented on GitHub (Oct 28, 2020): What we did on codeberg.org is to just forbid to change the email there, it must be done in the account settings and then the primary email can be switched after confirming. So we just patched out the feature to do it in the settings directly. We did not open an issue here but contacted you in January via the official way of reporting security problems.
Author
Owner

@WildCryptoFox commented on GitHub (Oct 28, 2020):

(Whoops.) Thank you @ashimokawa for the information (and hint there is an official channel for this which I admit I should have checked for...)

@WildCryptoFox commented on GitHub (Oct 28, 2020): (Whoops.) Thank you @ashimokawa for the information (and hint there is an official channel for this which I admit I should have checked for...)
Author
Owner

@WildCryptoFox commented on GitHub (Oct 28, 2020):

(Redacted and history deleted. Too late... but hopefully this will be fixed soon. At least the issue is relatively minor.)

@WildCryptoFox commented on GitHub (Oct 28, 2020): (Redacted and history deleted. Too late... but hopefully this will be fixed soon. At least the issue is relatively minor.)
Author
Owner

@zeripath commented on GitHub (Oct 28, 2020):

Do you know if the API is similarly affected?

@zeripath commented on GitHub (Oct 28, 2020): Do you know if the API is similarly affected?
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/gitea#6223