Skip to content
This repository has been archived by the owner on Aug 26, 2023. It is now read-only.

Let users know that accounts don't exist from password reset #881

Open
melinath opened this issue Nov 5, 2017 · 0 comments
Open

Let users know that accounts don't exist from password reset #881

melinath opened this issue Nov 5, 2017 · 0 comments

Comments

@melinath
Copy link
Contributor

melinath commented Nov 5, 2017

Currently, if a user doesn't have an account and tries to reset their password, they will not get an email. We also don't let the user know whether the account exists or not. This can be a confusing experience.

Originally, I think we were trying to offer some measure of security by obscuring whether the address had an account. However, I'm not sure I believe this is actually a security win since you could still check existence of an address from the account creation form.

Perhaps we should just let the users know.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant