-
-
Notifications
You must be signed in to change notification settings - Fork 213
Non-activated members shouldn't block one from registering once again #7992
Comments
|
This would be a huge usability improvement +1 |
|
@Defcon0 consider the following case: |
|
Then maybe a new field like "banned" could be useful? Of course this field would have to be widely used in Contao. |
|
It should be as simple as resending the activation mail if the account already exists and still has an activation token assigned. @contao/developers /cc |
|
I think this should also do it, thanks! |
|
@leofeyer I agree. If the user already exists, resend the activation mail. |
|
I'd say, the db should be updated, since this new data is the one to be the latest in the users mind :) |
|
Resending the activation e-mail should be enough. If they cannot remember their username they cannot get the activation e-mail and if they forgot the password there is the possibility for a password forgotten functionality. |
Of course not. If the submitted data does not exactly match the existing data, we must assume that it is not the same person trying to register. |
|
Mhm, but where's the danger with that taking into account that a possible attacker needs to have access to the email address of the victim? |
|
Imagine two employees of an agency, both trying to register with the same username e-mail address (info@agency.com). But one time it is "Dona Evans" and the next time "John Smith". At least the username, the e-mail address and the name have to match IMHO. |
|
Resending the activation e-mail makes sense to me. Besides that, an aditional toggle-icon in the BE-member-listing should be added for the "Allow login" field since Deactivate: no and Allow login: yes is not the same in the current concept. |
|
Implemented in contao/core-bundle@01d315f. |
Hello,
in our daily work it's often the case that some of the page visitors register, don't activate and after some time try to register again with the same mail address. Of course, the activation email had been thrown away already... Now the email field throws an error that the mail address has already been taken.
In my opinion, this shouldn't be. Wouldn't it be better if one could register again, get a new activation code and mail?
Bye Defcon0
The text was updated successfully, but these errors were encountered: