Skip to content
This repository has been archived by the owner on May 6, 2024. It is now read-only.

Password reset shows success regardless of whether or not email address is known #38

Open
tlrh314 opened this issue Jul 30, 2017 · 0 comments

Comments

@tlrh314
Copy link
Owner

tlrh314 commented Jul 30, 2017

Attempting to get a password reset with https://fairblogs.nl/accounts/password_reset using sjenkie@sjenk.sjenk leads to a success message.

https://fairblogs.nl/accounts/password_reset/done/

Perhaps the password reset should do a lookup to check that the user exists, if so show success message, and if not show an 'unknown email address' message

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant