[SPT/CWIS] Problems with New Accounts/Reset of passwords

Edward Almasy ealmasy at scout.wisc.edu
Thu Jul 10 16:05:07 CDT 2008


On Jul 10, 2008, at 3:21 PM, Dan Smith-IT wrote:
> For Reset password, the adminstration panel is currently set to send  
> the following email out:
>
> You can reset your password by visiting the following link.
> https://cwis.waldenu.edu/X-RESETURL-X
>
> X-RESETCODE-X
> X-USERNAME-X
> X-RESETURL-X
>
> When it sends an email, it sends out the following:
>
> You can reset your password by visiting the following link.
> https://cwis.waldenu.edu/?UN=twinky&RC=40CD82D67C
>
> 40CD82D67C
> twinky
> ?UN=twinky&RC=40CD82D67C

The value for the password reset URL is derived from the Apache  
REQUEST_URI environment variable.  Do you have mod_rewrite rules in  
your Apache configuration that may be preventing this value from being  
set accurately?

You can probably get around the problem by using X-RESETPARAMETERS-X  
instead of X-RESETURL-X like this:

    You can reset your password by visiting the following link.
    https://cwis.waldenu.edu/SPT--ResetPassword.phpX-RESETPARAMETERS-X

The X-RESETPARAMETERS-X value will supply the URL parameters needed  
for the password reset page.


What's very odd is that if the e-mail template in your message is  
correct, the "https://cwis.waldenu.edu/" portion in the resulting  
password reset e-mail should be followed by another "http://cwis.waldenu.edu/ 
" something like this:

    You can reset your password by visiting the following link.
    https://cwis.waldenu.edu/http://cwis.waldenu.edu/?UN=twinky&RC=40CD82D67C

Because the "http://" piece is hard-coded into the value that replaces  
X-RESETURL-X.

Ed


---
    Edward Almasy                             ealmasy at scout.wisc.edu
    Co-Director                                 1210 W Dayton Street
    Internet Scout                                  Madison WI 53706
    Computer Sciences Department                608-262-6606 (voice)
    University of Wisconsin - Madison             608-265-9296 (fax)





More information about the SPT-CWIS-Users mailing list