Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GitHub][web-base] Remove the reset password feature via the primary email address #9

Open
huabin opened this issue May 6, 2022 · 0 comments
Labels
feature Feature request no triage

Comments

@huabin
Copy link
Owner

huabin commented May 6, 2022

Detailed description according to the following.

The service or application that you want to submit an issue to
GitHub.com

What feature and where in the system

  • Go to https://github.com/settings/emails

Current Status
Password can be reset via primary email address.

The way you want it to be
Remove the reset password feature via the primary email address

Reason
Primary email address is the default used for GitHub notifications, i.e., replies to issues, pull requests, etc. And it may be used as the 'author' or 'committer' address for web-based Git operations, e.g., edits and merges.

It is public and will be known by others, it should not be used for password reset and security related operations.

Additional context
There are two issues 1, 2, they can leak the primary email address.

@huabin huabin added feature Feature request no triage labels May 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature Feature request no triage
Projects
None yet
Development

No branches or pull requests

1 participant