You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Password Recovery currently indicates whether or not a username/email exists as a user in the system. It shouldn't do that. A better solution would be to just tell the user that an email will be sent to the address if it's in the system. Maybe have it throw a random security question out as well so would-be miners/hackers can't tell if the address exists in the system or not.
The text was updated successfully, but these errors were encountered:
Password Recovery currently indicates whether or not a username/email exists as a user in the system. It shouldn't do that. A better solution would be to just tell the user that an email will be sent to the address if it's in the system. Maybe have it throw a random security question out as well so would-be miners/hackers can't tell if the address exists in the system or not.
The text was updated successfully, but these errors were encountered: