Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

allow to reset password with username or email #1149

Closed
lianglee opened this issue Sep 6, 2017 · 1 comment
Closed

allow to reset password with username or email #1149

lianglee opened this issue Sep 6, 2017 · 1 comment

Comments

@lianglee
Copy link
Member

lianglee commented Sep 6, 2017

allow to reset password with username or email

@githubertus
Copy link
Contributor

I just became aware of this change
and honestly I'm not really happy with it.
Now, any evil community member can use any other member's username and run the reset action.
He can do it as often as he wants, so this may result in a real spamming pain. And besides all that: you don't even know who the idiot was.
If we want to stay with this option it should be combined at least with a second parm (e.g. date of birth) to be checked.

githubertus pushed a commit to githubertus/opensource-socialnetwork that referenced this issue Nov 13, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants