Skip to content

Reset authinfo pw on registrant change #2892

@vohmar

Description

@vohmar

Transfer/auth code is generally used for authorizing registrar transfer (https://datatracker.ietf.org/doc/html/rfc5731#section-3.2.4). But it could also be used to signal registrant consent for registrant change (https://datatracker.ietf.org/doc/html/rfc5731#section-3.2.5).

Currently the code is reset only on registrar transfer, creating a security risk if used for any other purpose.

Todo: Reset authInfo pw on registrant transfer in addition to registrar transfer

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions