[Koha-bugs] [Bug 21325] Prevent authentication when sending userid and password via querystring parameters

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Mon Apr 19 02:15:56 CEST 2021


https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=21325

--- Comment #14 from David Cook <dcook at prosentient.com.au> ---
(In reply to Katrin Fischer from comment #13)
> I assume we should add something to the release notes about this as it might
> be a breaking change for some customizations?

Not only customization but also creative authentication by end users. See Bug
27305. Nico was very creative using the querystring to authenticate Google
Calendar with Koha. 

I originally worked on this to stop him from being able to do that, although I
feel bad that we don't have a ready feature to replace it for him.

-- 
You are receiving this mail because:
You are watching all bug changes.


More information about the Koha-bugs mailing list