Page MenuHomePhabricator

Require login for "Must Verify Email" controller
ClosedPublic

Authored by epriestley on Jun 7 2016, 11:35 PM.
Tags
None
Referenced Files
F15548180: D16077.id.diff
Sat, Apr 26, 10:19 PM
F15526353: D16077.id.diff
Mon, Apr 21, 8:39 PM
F15507661: D16077.id.diff
Tue, Apr 15, 9:55 PM
F15483879: D16077.id38684.diff
Wed, Apr 9, 3:05 PM
F15473432: D16077.id38683.diff
Sat, Apr 5, 10:06 PM
F15471989: D16077.diff
Sat, Apr 5, 10:31 AM
F15403046: D16077.id.diff
Mar 18 2025, 1:44 AM
F15390687: D16077.id.diff
Mar 15 2025, 6:26 AM
Subscribers
None

Details

Summary

Via HackerOne. This page fatals if accessed directly while logged out.

The "shouldRequireLogin()" check is wrong; this is a logged-in page.

Test Plan

Viewed the page while logged out, no more fatal.

Faked my way through the actual verification flow.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley retitled this revision from to Require login for "Must Verify Email" controller.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: chad.
chad edited edge metadata.
This revision is now accepted and ready to land.Jun 7 2016, 11:35 PM
This revision was automatically updated to reflect the committed changes.