Details
-
Bug
-
Resolution: Done
-
P1: Critical
-
2011q4
-
V2.2.1-NQT-003
Description
When registering a new email address with gerrit, it sends an email with a verification link.
This link is a http://codreview.qt.nokia.com/...
When opening the link in the browser, it requests http basic authentication credentials (i.e. plain text on an insecure channel)
This triggers a security warning in the browser
Note to reproduce:
I was already logged in to gerrit using firefox, but the default web browser is IE8
Attachments
For Gerrit Dashboard: QTQAINFRA-167 | ||||||
---|---|---|---|---|---|---|
# | Subject | Branch | Project | Status | CR | V |
75260,2 | Fixed gerrit email verification link requires insecure login | v2.7.0-based | qtqa/gerrit | Status: MERGED | +2 | 0 |