Password reset request - Return consistent message for both existent and non-existent accounts. #2352
Closed
netcatgirl
started this conversation in
Ideas / Feature Requests
Replies: 1 comment
-
|
Thanks for the hint. Will be fixed in the next release. :) See #4438 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Currently, when requesting a new password, it lets the user know if the account exists or not.
and
maybe the message could be changed to something like
I read about it on the owasp.org auth cheat sheet and thought it might apply here.
Beta Was this translation helpful? Give feedback.
All reactions