Meshcentral: Feature Request - Account Creation Requires Email Validation

Created on 19 Apr 2020  路  4Comments  路  Source: Ylianst/MeshCentral

Yesterday I enabled new account creation from our login page, with domain filtering set to the corporate email. The domain filtering works great, however I've noticed I can create new accounts using nonexistant emails that have corporate domain. These get the same permissions as accounts made with valid emails, and has me wondering what the email verification actually accomplishes besides the green checkmark.

A bad actor who finds/knows the login page and email domain could flood the server with new accounts using fake emails. The risk may be low, and can be further reduced by restricting permissions on new accounts, but it could still become a massive headache

Would it be possible to implement a configuration option which prevents account creation pending email verification?

Fixed - Confirm & Close bug

Most helpful comment

Published MeshCentral v0.5.11 with a new email verification login screen. It blocks login until you provide and verify a valid email address. Testing and feedback appreciated.

MC2-EmailVerifyLogin

All 4 comments

Good catch.

Published MeshCentral v0.5.11 with a new email verification login screen. It blocks login until you provide and verify a valid email address. Testing and feedback appreciated.

MC2-EmailVerifyLogin

Closing this since it's probably fixed. Let open a new issue if needed.

@Ylianst This works if you create the user yourself, but if the user creates an account from the login screen themselves, the system automatically logs them in immediately after account creation, bypassing verification. Only if the user then logs out and tries to log back will the verification screen show.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

petervanv picture petervanv  路  3Comments

PathfinderNetworks picture PathfinderNetworks  路  3Comments

MailYouLater picture MailYouLater  路  3Comments

MailYouLater picture MailYouLater  路  4Comments

guerby picture guerby  路  3Comments