Anyhow, I never found the worklogs to be setup server-side very well, I mean, from a user point of view it's easy to use and operate, but the underlying coding is messy, the fact you can take any topic and put another users name in it looks bad. (since it takes in two values from the url, one for the user, one for post)
Sorry to re-open this thread about 'site-security' but I just noticed a thing that BRL's admin site should take in consideration. If I check my 'Account' page I can see my registered products AND the registration code. I think it should a better solution if the registration code can be sent (if lost) only by e-mail to the address given at the moment of the registration. Of course in case of changing e-mail address a contact with BRL will be necessary. Maybe this is a suggestion already given, in this case I'm late! Byez
PS: I'm quite sure (well...) that I wrote some other posts in the forum, but now they are gone.