<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #82: Security: separate sending of username and password</title>
    <link>http://localhost:8080/trac/ticket/82</link>
    <description>&lt;p&gt;
separate the username and password emails so we don't send them together in one unencrypted email (Paul Field)
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/82</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Thu, 19 Aug 2010 13:28:28 GMT</pubDate>
      <title>owner, status changed; estimatedhours, billable set</title>
      <link>http://localhost:8080/trac/ticket/82#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/82#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;owner&lt;/strong&gt;
              changed from &lt;em&gt;jim&lt;/em&gt; to &lt;em&gt;ed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;estimatedhours&lt;/strong&gt;
                set to &lt;em&gt;0.0&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;assigned&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;billable&lt;/strong&gt;
              unset
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
There's no built-in way to send two emails.
&lt;/p&gt;
&lt;p&gt;
However, since the user typed their own password - twice - they don't really need it in the email at all. They can always use the 'forgotten password' option after all.
&lt;/p&gt;
&lt;p&gt;
So, please go to here &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/user/settings"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/user/settings&lt;/a&gt; and edit the "Welcome, no approval required" message as you see fit. I'd remove the password line and change the text to say 'you chose your password during registration.
&lt;/p&gt;
&lt;p&gt;
Reassigning to Ed since he's the one with the user text thing, though can do if needed.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Wed, 25 Aug 2010 15:26:41 GMT</pubDate>
      <title>owner changed</title>
      <link>http://localhost:8080/trac/ticket/82#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/82#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;owner&lt;/strong&gt;
              changed from &lt;em&gt;ed&lt;/em&gt; to &lt;em&gt;jim&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
a bit confused -
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;why is there a one time login here when they have already set their password?
&lt;/li&gt;&lt;li&gt;why are they being asked to re-set their password?
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
here is the text as it stands:
&lt;/p&gt;
&lt;p&gt;
Hi !username,
Thank you for registering at !site. You may log in by clicking on this link or copying and pasting it in your browser:
!login_url
This is a one-time login, so it can be used only once. After logging in, you will be redirected to !edit_uri so you can change your password.
You may also log in to !login_uri using the following username and password:
username: !username
password: !password
&lt;/p&gt;
&lt;p&gt;
all the best and welcome,
&lt;/p&gt;
&lt;p&gt;
--  !site team
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Wed, 25 Aug 2010 15:56:00 GMT</pubDate>
      <title>owner changed</title>
      <link>http://localhost:8080/trac/ticket/82#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/82#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;owner&lt;/strong&gt;
              changed from &lt;em&gt;jim&lt;/em&gt; to &lt;em&gt;ed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Yes, it's a mess and shouldn't say half of those things - just a reminder of the username and link to the login page at /user/login and a welcome note should suffice.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing wiki"&gt;LoginToboggan?&lt;/a&gt; removes the need for the one-time login, though they still need to validate their email.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Wed, 25 Aug 2010 15:58:25 GMT</pubDate>
      <title>priority changed</title>
      <link>http://localhost:8080/trac/ticket/82#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/82#comment:4</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;priority&lt;/strong&gt;
                changed from &lt;em&gt;minor&lt;/em&gt; to &lt;em&gt;major&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
OK then I'll remove all the stuff about one time logins - that might nail the validation problem and other user confusion at that point.
&lt;/p&gt;
&lt;p&gt;
bunging up to major so i remember to tweak this in due course...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Fri, 17 Jun 2011 11:23:33 GMT</pubDate>
      <title>status changed; resolution, milestone set</title>
      <link>http://localhost:8080/trac/ticket/82#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/82#comment:5</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;assigned&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;milestone&lt;/strong&gt;
                set to &lt;em&gt;Phase 4&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
finally got round to sorting this out. closing.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>