Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reset Password event should have Email Template option #139

Closed
michael-e opened this issue May 19, 2011 · 2 comments
Closed

Reset Password event should have Email Template option #139

michael-e opened this issue May 19, 2011 · 2 comments
Assignees
Milestone

Comments

@michael-e
Copy link
Member

Reading about the latest security issues on Sony's Playstation network, I noticed that it would be a very good idea to implement an email template(s) setting for the Reset Password event. Like in Sony's case, sending an email upon successful password reset is an important security "fallback".

Typically the two step process sould be like this:

  1. Generate Recovery Code: Email saying "If you did not ask for a password reset, you may disregard this email."
  2. Reset Password: Email saying "If you did not do this, your account has been hacked. Please contact support immediately."
@ghost ghost assigned brendo May 19, 2011
@brendo
Copy link
Member

brendo commented May 19, 2011

Sounds reasonable to me and it's easy enough to implement

@brendo brendo closed this as completed in 7264942 May 19, 2011
@michael-e
Copy link
Member Author

Big Picture updated!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants