Comment 'My hosting asked me ...' to 'Dolphin Connect Bug'
  • My hosting asked me to post this:

    Checking IDs would seem to be problematic.  I am number 2 on Dolphin and there already exists a number 2 on UNA; but the number 2 on UNA does not have a Dolphin account.  Could you please explain the algorithm?  I am going to delete the entry from the bx_dol_accounts and see if it recreates it; sees if it recreates hijacking an existing UNA account or not.

    I know you think this is minor but it isn't.  The Dolphin user was connected to an admin account on UNA and gained full access to the site; so this is a serious bug.