[Mediawiki-l] made an administrator who hasn't yet established an account

2010-08-02 Thread jidanni
Say, I noticed on Wikia one can make a user an administrator, even if he has never logged in yet. This exposes a security risk. A bureaucrat pre-makes some accounts for future administrators, but before they establish accounts, somebody else establishes an account with that name, and becomes an

Re: [Mediawiki-l] made an administrator who hasn't yet established an account

2010-08-02 Thread Q
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 8/2/2010 7:18 PM, jida...@jidanni.org wrote: Say, I noticed on Wikia one can make a user an administrator, even if he has never logged in yet. This exposes a security risk. A bureaucrat pre-makes some accounts for future administrators, but

Re: [Mediawiki-l] made an administrator who hasn't yet established an account

2010-08-02 Thread Lewis Cawte
On 03/08/10 01:18, jida...@jidanni.org wrote: Say, I noticed on Wikia one can make a user an administrator, even if he has never logged in yet. This exposes a security risk. A bureaucrat pre-makes some accounts for future administrators, but before they establish accounts, somebody else

Re: [Mediawiki-l] made an administrator who hasn't yet established an account

2010-08-02 Thread Lewis Cawte
I think they mean where an account has been made and given rights before the user account is logged into, thus making it not a bug. On 03/08/10 01:22, Q wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 8/2/2010 7:18 PM, jida...@jidanni.org wrote: Say, I noticed on Wikia one can