hi guys, i just discovered that when you click on password retrival link it only ask for username and sends a new password to the email, what if anyone fill “admin” or any known user and hit send! the password is being changed and sent to email, can’t login with old password, meanwhile anyone can reset the password to anyone! even if it is sent to the user email address! i think this need be addressed or solved even by workaround, at least user must confirm he wants to reset the password and another email send a new one!? what you think? doesn’t make sense to me
also the “columns” feature, i have changed some columns places in a grid, then logged out, logged in with another user and still showing the same colomns what was modified by the first user!? is this making any sense to you? how the user will setup columns for other users? I tried from another computer and it is ok, showing default columns but also for the same PC it does show the same colums of the previous user, it is critical I think!? what the logout is for? doesn’t suppose to remove all user stuff from the machine???