Red Hat Bugzilla – Bug 845188
No error message when sign up with a registered email address on INT.
Last modified: 2015-05-14 21:13:10 EDT
Description of problem:
After I registered my account with email address firstname.lastname@example.org.I clicked the confirm url ,and have used it to create my apps.
Then I tried to sign up a new account with the same address(email@example.com), but get no a successful register page with no error message.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1.Sign up an account on INT, confirm it, and use it do some operations.
2.Go to sign up page, input the same email address.
It returns a page said registered successful.
User should get some error message said that the email have been registered.
Sorry to make a mistake when discribe the problem. The last sentence of the description should be :"Then I tried to sign up a new account with the same address(firstname.lastname@example.org), but get a successful register page with no error message."
This is a security issue. We do not expose whether a user already has an email account by design so that malicious parties can't detect whether the user has an account already. So this is fixing a problem that was occurring.