mirror of
https://github.com/projectsend/projectsend.git
synced 2026-10-05 21:01:33 +00:00
717852ff6a
An account that signs in through a provider has no password to prove, so the password screen let the signed-in session choose one with no proof at all. A stolen session could then make itself permanent: set a password, confirm it, enrol its own second factor and remove the owner's last provider, since the account now read as local. The screen now refuses to set a provider account's password and offers to email a link instead: the ordinary reset link, to the account's own address, so whoever sets the password must read that inbox. The reset pages accept a signed-in visitor, since the owner opens the link in the browser they are signed in with; the token, not the session, is the authority. Using the link signs out every session holding the old password, the one that asked for it included. Compulsory two-factor lets the link through, so a provider account still has a way to enrol. Ordinary accounts are unchanged: they prove their current password. GHSA-4r8h-mwfm-f5f4