Skip to content

Conversation

@manuelkiessling
Copy link
Member

Adds a "forgot password" feature which allows users to enter their email address on a dedicated form, and if an account for this email address exists, an email is sent to the address, with a link that is valid for 24 hours and which, if clicked, provides a web UI form where the user can set a new password for the account mapped to the email address.

The implementation ensures that this feature cannot be used to determine if an email address is registered or not; the web UI reaction is always the same, whether the email entered on the "forgot password" form is known in the system or not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant