Properly validate current user password during password change.#43447
Merged
azasypkin merged 3 commits intoelastic:masterfrom Aug 16, 2019
Merged
Properly validate current user password during password change.#43447azasypkin merged 3 commits intoelastic:masterfrom
azasypkin merged 3 commits intoelastic:masterfrom
Conversation
Contributor
|
Pinging @elastic/kibana-security |
Contributor
💚 Build Succeeded |
azasypkin
commented
Aug 16, 2019
| .send({ password: wrongPassword, newPassword }) | ||
| .expect(401); | ||
|
|
||
| // Let's check that we can't login with wrong password (bug happen :shrug:). |
Contributor
Author
There was a problem hiding this comment.
note: typo in a silly comment, hilarious 🙈 (will remove when we'll be addressing review comments).
kobelb
approved these changes
Aug 16, 2019
Contributor
kobelb
left a comment
There was a problem hiding this comment.
This is great! Only one optional comment
| /** | ||
| * Utility class that knows how to decorate request with proper Basic authentication headers. | ||
| */ | ||
| export class BasicCredentials { |
| let sessionCookie: Cookie; | ||
| beforeEach(async () => { | ||
| // Create mock user to change password for. | ||
| await getService('supertest') |
Contributor
There was a problem hiding this comment.
optional: we added a security service which potentially makes this a bit easier
kibana/x-pack/test/api_integration/apis/apm/feature_controls.ts
Lines 190 to 194 in d66b3c7
Contributor
Author
There was a problem hiding this comment.
wow, didn't know about that, thanks!
| .send({ password: wrongPassword, newPassword }) | ||
| .expect(401); | ||
|
|
||
| // Let's check that we can't login with wrong password (bug happen :shrug:). |
Contributor
💚 Build Succeeded |
Contributor
Author
|
7.x/7.4.0: ce716ae |
jloleysens
added a commit
to jloleysens/kibana
that referenced
this pull request
Aug 19, 2019
…_update_json_spec * 'master' of github.com:elastic/kibana: (35 commits) fix: 🐛 pass whole action context to isCompatible() method (elastic#43457) Deleted old kbn-top-nav directive (elastic#43168) [ML] Fixing cloning of single metric distinct count job (elastic#43435) Update @elastic/charts version 8.1.6 > 9.1.1 (elastic#43516) [Inspector Views] [Request View] - Migrate inspector_views to new platform (elastic#43191) [ML] Adding loading indicators to all wizard charts (elastic#43382) disable flaky test (elastic#43492) feature(code/frontend): cancel file blob and directory commits request if outdated (elastic#43348) fix(code/frontend): button group url should have previous query string (elastic#43428) [SIEM] Fixes index substring incorrectly matching configured indices and failing to install ML job (elastic#43409) [SIEM] Adds performance enhancements such by removing wasted renderers and adding incremental DOM rendering (elastic#43157) disable flaky test (elastic#37859) Added sass lint to Canvas (elastic#43410) [Maps] add indicator when layer is filtered by search bar (elastic#43283) Properly validate current user password during password change. (elastic#43447) Spaces - allow for hex color codes that include uppercase characters (elastic#43470) [Reporting] Add a bit more logging and a few more logging level promotions (elastic#43415) Partially convert index pattern server to typescript (elastic#43291) [Infra UI] Use sum for aggregating AWS metrics. (elastic#43293) [SIEM] Format bytes columns in timeline (elastic#43147) ...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
In this PR we properly validate current user password before we try to change it and finally get rid of
BasicCredentialsclass. The issue was introduced in #39446.Fixes: #42807