Skip to content

Add 'forgot password' feature #16

@manuelkiessling

Description

@manuelkiessling

The application needs a "forgot password" feature which allows users to enter their email address on a dedicated form, and if an account for this email address exists, an email is sent to the address, with a link that is valid for 24 hours and which, if clicked, provides a web UI form where the user can set a new password for the account mapped to the email address.

The implementation needs to ensures that this feature cannot be used to determine if an email address is registered or not; the web UI reaction is always the same, whether the email entered on the "forgot password" form is known in the system or not.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions