-
Notifications
You must be signed in to change notification settings - Fork 81
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update password reset email text #1139
Comments
Hi,
Should this be as another link provided in the mail? |
@aklife97 Users should send an email to security (at) cadasta to let us know what happened |
@oliverroick assign this to me and send me the link to code. |
@jack17529 during the application process for GSoC we don't assign issues to anyone. It is okay to have more than one pull request for the same issue, we will still consider it as part of your application. |
@oliverroick sorry sir ,I read it then forgot. |
* Bugfix#1139: password reset email fix * Bugfix#1139 fixed the bug and tested
Our password reset email template reads:
For security purposes, we should advise users to immediately report password reset emails they didn't request; these are not safe to ignore. We should also avoid sending the username in the same email as the password reset, as this gives anyone with the email the ability to access the user account with no additional information required. Ideally, our password reset process wouldn't confirm or deny the existence of a user account for a given email address. Please see this link for password reset (and other transactional) email best practices.
The text was updated successfully, but these errors were encountered: