nextcloud/impersonate

Password prompts require the admin password, not the impersonated user's password

Opened this issue · 0 comments

STR:

  1. Impersonate another admin (seems silly, but in this case I did this because I originally logged in to a shared admin account and was too lazy to dig through my password manager for the password to the admin account I created for myself on a different computer - so it was easier to just impersonate myself)
  2. Try to take some privileged action. In my case it was changing who gets announcements from Announcement Center at /index.php/settings/admin, but presumably you could also update some apps or something
  3. Input the impersonated user's password and get a "credentials failed" message or something like that
  4. Input the admin password and notice it succeeds

I'm on Nextcloud 26.0.4, Impersonate 1.13.1.