Comment to Dolphin Connect Bug
-
My hosting asked me to post this:
Checking IDs would seem to be problematic. I am number 2 on Dolphin and there already exists a number 2 on UNA; but the number 2 on UNA does not have a Dolphin account. Could you please explain the algorithm? I am going to delete the entry from the bx_dol_accounts and see if it recreates it; sees if it recreates hijacking an existing UNA account or not.
I know you think this is minor but it isn't. The Dolphin user was connected to an admin account on UNA and gained full access to the site; so this is a serious bug.