Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update password reset email text #1139

Closed
amplifi opened this issue Feb 17, 2017 · 5 comments · Fixed by #1210
Closed

Update password reset email text #1139

amplifi opened this issue Feb 17, 2017 · 5 comments · Fixed by #1210

Comments

@amplifi
Copy link
Contributor

amplifi commented Feb 17, 2017

Our password reset email template reads:

You're receiving this email because you or someone else has requested a password for your user account at Cadasta Platform.

It can be safely ignored if you did not request a password reset. Click the link below to reset your password.

<link>

In case you forgot, your username is <username>.

Thank you for using Cadasta Platform!

For security purposes, we should advise users to immediately report password reset emails they didn't request; these are not safe to ignore. We should also avoid sending the username in the same email as the password reset, as this gives anyone with the email the ability to access the user account with no additional information required. Ideally, our password reset process wouldn't confirm or deny the existence of a user account for a given email address. Please see this link for password reset (and other transactional) email best practices.

@aklife97
Copy link
Contributor

aklife97 commented Mar 2, 2017

Hi,
Can you please clarify how do you intend to

advice users to immediately report password reset emails

Should this be as another link provided in the mail?
If yes, what should happen if the user reports the reset email?

@oliverroick
Copy link
Member

@aklife97 Users should send an email to security (at) cadasta to let us know what happened

@jack17529
Copy link

@oliverroick assign this to me and send me the link to code.

@oliverroick
Copy link
Member

@jack17529 during the application process for GSoC we don't assign issues to anyone. It is okay to have more than one pull request for the same issue, we will still consider it as part of your application.

amplifi pushed a commit that referenced this issue Mar 7, 2017
* Bugfix#1139: password reset email fix

* Bugfix#1139 fixed the bug and tested
@jack17529
Copy link

jack17529 commented Mar 7, 2017

@oliverroick sorry sir ,I read it then forgot.
But sir can we ask in comments section that anybody is working on this issue?

laura-barluzzi pushed a commit to laura-barluzzi/cadasta-platform that referenced this issue Mar 14, 2017
* Bugfix#1139: password reset email fix

* Bugfix#1139 fixed the bug and tested
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
5 participants