Ticket #347 (closed defect: fixed)

Opened 23 months ago

Last modified 20 months ago

Verification URL in Trac is incorrect

Reported by: philknerr Owned by: Joel
Priority: minor Milestone:
Component: Website Version:
Keywords: Cc:
Processor Architecture: Blocked By:
Blocking: Operating System:

Description

I created an account on Trac in order to report the bug which is now Ticket #346. After creating an account, I got the following verification e-mail:

Subject: [Eraser] Trac email verification for user: philknerr
From: "trac [at] heidi.ie" <trac [at] heidi.ie>
Date: Wed, March 17, 2010 9:30 pm
To: philip.knerr [at] philknerr.com
Priority: Normal

Please visit the following URL to confirm your email address.

Verification URL: </trac/verify_email?token=[token]>
Username: philknerr
Verification Token: [token]

--
Eraser <http://eraser.heidi.ie/trac/>
Eraser - Secure Data Removal for Windows

This email and any files transmitted with it are confidential and intended
solely for the use of the individual or entity to whom they are addressed.
If you have received this email in error please notify the sender by return
e-mail and delete it from your system. Thank you.
Any opinions expressed are that of the individual and not necessarily that
of Heidi Computers Ltd.
Although Heidi Computers Ltd believe this email and any attachments are
free of any virus or defect that may affect a computer, it is the responsibility
of the recipient to ensure that this is so, and Heidi Computers Ltd accepts
no responsibility for any loss, contamination or damage arising in any way
from its use.
Heidi Computers Ltd, registered in the Republic of Ireland (No. 8273384),
Registered office, 9 Trafalgar Court ,Greystones,Co Wicklow, Ireland.

[The token is redacted because I don't know if it's sensitive, e.g., possibly someone could hack this account on Trac knowing the token? The at-signs in the e-mails were replaced because Trac doesn't seem to like them.]

The URL above would not work if one clicked it. I guessed that it should be preceded by " http://eraser.heidi.ie"; this in fact worked. It's likely that an unsophisticated user trying to report a bug wouldn't figure out as much, and might just not bother to report the bug.

I'm currently using a text-only e-mail client (e.g., one that doesn't render HTML). This is probably irrelevant, as the e-mail doesn't even appear to have a text/html part.

Blocking

IdSummaryMilestone
#347Verification URL in Trac is incorrect

Blocked by

IdSummaryMilestone
#347Verification URL in Trac is incorrect

Change History

comment:1 Changed 22 months ago by Joel

  • Status changed from new to assigned
  • Owner set to Garrett

comment:2 Changed 20 months ago by Joel

  • Status changed from assigned to accepted
  • Owner changed from Garrett to Joel

This looks like a Trac bug. Maybe we should upgtade the plugins:  http://trac-hacks.org/log/accountmanagerplugin/trunk

comment:3 Changed 20 months ago by Joel

  • Status changed from accepted to closed
  • Resolution set to fixed

Updated. Reopen this ticket if other users experience this problem.

Note: See TracTickets for help on using tickets.