View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
20121 | Bug reports | Authentication | public | 2025-05-23 13:31 | 2025-05-26 15:31 |
Reporter | alainl88 | Assigned To | tibor.pacalat | ||
Priority | none | Severity | text | ||
Status | closed | Resolution | won't fix | ||
Summary | 20121: Wrong alert on failed authentication with access code | ||||
Description | When the user uses a wrong access token, he gets the alert "The access code you have provided is either not valid, or has already been used." | ||||
Steps To Reproduce | Steps to reproduceStart a new survey with closed participants list. Enter a wrong access code. Expected resultThe user should see an alert that inform him that the code is not correct Actual resultThe alert "The access code you have provided is either not valid, or has already been used" is shown. It could lead to misunderstanding since the error is provided only when a wrong access code is used. | ||||
Tags | No tags attached. | ||||
Bug heat | 6 | ||||
Complete LimeSurvey version number (& build) | 6.14.0+250520 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | |||||
Database type & version | MariaDB | ||||
Server OS (if known) | |||||
Webserver software & version (if known) | |||||
PHP Version | 8.2 | ||||
If i don't make error : we update this string for security issue : don't give more information than needed The access code you have provided is either not valid is a correct sentence |
|
Issued a PR https://github.com/LimeSurvey/LimeSurvey/pull/4293. |
|
No : the whole sentence is OK ! Can be both : bad token or already used or invalid token. |
|
I agree with Denis, nothing to do here. This is vague because of security. |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2025-05-23 13:31 | alainl88 | New Issue | |
2025-05-23 14:14 | DenisChenu | Note Added: 82746 | |
2025-05-23 14:14 | DenisChenu | Bug heat | 0 => 2 |
2025-05-23 15:36 | alainl88 | Note Added: 82749 | |
2025-05-23 15:36 | alainl88 | Bug heat | 2 => 4 |
2025-05-23 16:29 | DenisChenu | Note Added: 82750 | |
2025-05-26 15:30 | tibor.pacalat | Note Added: 82764 | |
2025-05-26 15:30 | tibor.pacalat | Bug heat | 4 => 6 |
2025-05-26 15:31 | tibor.pacalat | Assigned To | => tibor.pacalat |
2025-05-26 15:31 | tibor.pacalat | Status | new => closed |
2025-05-26 15:31 | tibor.pacalat | Resolution | open => won't fix |