Topic: Avatars and Password Changing

Admins and mods can upload avatars for users that don't yet exist by changing the id in the upload_avatar URL. Not really a big bug, just something worth noting.

Another thing like that is that on the profile screen, the Change Password link always appears if you're a mod. However, you get Permission Denied if you click the link on the profile of a mod or admin. The link should probably be hidden in that case wink

Re: Avatars and Password Changing

Smartys wrote:

Admins and mods can upload avatars for users that don't yet exist by changing the id in the upload_avatar URL. Not really a big bug, just something worth noting.

The question is if it's worth fixing due to the added overlay. A query will have to be executed to determine if the user actually exists.

Smartys wrote:

Another thing like that is that on the profile screen, the Change Password link always appears if you're a mod. However, you get Permission Denied if you click the link on the profile of a mod or admin. The link should probably be hidden in that case ;)

I'm on it.

Once again, nice finds :)

"Programming is like sex: one mistake and you have to support it for the rest of your life."

Re: Avatars and Password Changing

Smartys wrote:

Admins and mods can upload avatars for users that don't yet exist by changing the id in the upload_avatar URL. Not really a big bug, just something worth noting.

if they do this for then next id to be registered does the avatar appear on this users profile?

Re: Avatars and Password Changing

Yes, it would.

"Programming is like sex: one mistake and you have to support it for the rest of your life."

Re: Avatars and Password Changing

lol, that would be odd :S

Re: Avatars and Password Changing

Yes, it would :)

We'll see. It's not the end of the world. First of all, why would a moderator or admin want to do that and secondly, how big is the change the he/she has the knowledge? :)

"Programming is like sex: one mistake and you have to support it for the rest of your life."

Re: Avatars and Password Changing

yeh i mean if they are a moderator surely you can trust them

Re: Avatars and Password Changing

Connorhd wrote:

if they do this for then next id to be registered does the avatar appear on this users profile?

I see it as a feature, not a bug - it is very useful for adding a free bonus avatar to say the 1000th registered user :-)