[buddypress-trac] [BuddyPress Trac] #9137: REST API related issues for signups and pending accounts

buddypress-trac noreply at wordpress.org
Thu Apr 25 12:31:10 UTC 2024


#9137: REST API related issues for signups and pending accounts
---------------------------------------+--------------------------
 Reporter:  niftythree                 |       Owner:  espellcaste
     Type:  defect (bug)               |      Status:  new
 Priority:  normal                     |   Milestone:  Up Next
Component:  REST API                   |     Version:
 Severity:  normal                     |  Resolution:
 Keywords:  needs-patch needs-testing  |
---------------------------------------+--------------------------

Comment (by espellcaste):

 **Scenario 1**: Multiple pending accounts can be registered through the
 REST API with the same email address, but different usernames.

 I can confirm this using BP 12.4. But as I've noted, and tested, above,
 this will be fixed in the next milestone (14).


 > Please try testing this through the website with BuddyPress version
 12.4.0. i.e. register an account through the REST API, and then you will
 be able to constantly request the resending of activation emails by
 entering the username and anything into the password field on the website.

 Oh, you mean the web version, not the REST API. I can confirm this too.
 But here I'm not sure what could be done. We don't want to avoid people
 from requesting to resend the email, if necessary. I'll need to talk it
 over with the team about this one. Maybe we can add some sort of time
 limit or attempts. Or a hook so that devs can decide how to best approach
 it from their community.

 ---

 Thanks! You found a bug. I have a fix incoming.

-- 
Ticket URL: <https://buddypress.trac.wordpress.org/ticket/9137#comment:5>
BuddyPress Trac <http://buddypress.org/>
BuddyPress Trac


More information about the buddypress-trac mailing list