Security-Flaw or Design - Username as Password?

Good morning everyone,

yesterday I discovered a strange thing: it’s possible to use the Username as password (testet in NC17 and NC18).
Should that be so ???

Abrax

you should enable app “password policy” and do some setups there (admin account)…

you should enable app “password policy” and do some setups

Of course I did.
If your Username rules the password policy you can set the Username as password

so if you think this is a bug (or unwanted) you maybe want to report it at https://github.com/nextcloud/server after having checked if it’s not already been filed?

awww… and it would be great if you’d post a link to your filed issue here which would solve the thread - at least on the forum.

1 Like