Disable password reset as temporary fix to vulnerability (#396)

Disabled password reset and left message notifying user of problem. In response to CVE-2019-19844
This commit is contained in:
Matthew Smith
2020-01-17 13:13:16 +00:00
committed by David Taylor
parent 4ad12ab40a
commit e0c6a56263
3 changed files with 14 additions and 1 deletions

View File

@@ -0,0 +1,9 @@
{% extends 'base_rigs.html' %}
{% block title %}Password Reset Disabled{% endblock %}
{% block content %}
<h1>Password reset is disabled</h1>
<p> We are very sorry for the inconvenience, but due to a security vulnerability, password reset is currently disabled until the vulnerability can be patched.</p>
<p> If you are locked out of your account, please contact an administrator and we can manually perform a reset</p>
{% endblock %}