Hi,
I just noticed that passwords for accounts on tracker.projeqtor.org and demo.projeqtor.org can be changed easily from the login screen. This looks like a security issue to me (hopefully, the admin can still revert this back but you don't want to reset the password every morning).
To me, a shared account should not be able to change password and access the user parameters (the latter can be changed) but the admin should be able to change the user parameters if needed.
Thank you,
I just noticed that passwords for accounts on tracker.projeqtor.org and demo.projeqtor.org can be changed easily from the login screen. This looks like a security issue to me (hopefully, the admin can still revert this back but you don't want to reset the password every morning).
To me, a shared account should not be able to change password and access the user parameters (the latter can be changed) but the admin should be able to change the user parameters if needed.
Thank you,