Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enhancement: Option to disable password reset functionality entirely #2326

Open
1 task done
kzar opened this issue Apr 5, 2024 · 1 comment · May be fixed by #2327
Open
1 task done

Enhancement: Option to disable password reset functionality entirely #2326

kzar opened this issue Apr 5, 2024 · 1 comment · May be fixed by #2327
Assignees
Labels
enhancement New feature or request

Comments

@kzar
Copy link

kzar commented Apr 5, 2024

What features would you like to see added?

I'd rather disable the password reset functionality entirely, since I don't need it and it's a potential vector for attack. It would be great if there was an option to disable it.

More details

My concerns:

  1. The default is the insecure password reset link, which I fear will lead to folks getting compromised.
  2. The email flow leaks account emails by complaining when an incorrect email address is entered.

Which components are impacted by your request?

No response

Pictures

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct
@kzar kzar added the enhancement New feature or request label Apr 5, 2024
@danny-avila
Copy link
Owner

Will address both your concerns today if I can

@berry-13 berry-13 self-assigned this Apr 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants