Greetings,
I just noticed that when users use the password recovery option, and enter an incorrect username, no error is displayed.
It just displays that a password reset mail has been sent.
But as the user entered an incorrect username, no recovery mail has been send, but the user is not aware of this.
When checking in the log on the dashboard, we see clearly that a password reset has been asked by an unknown user.
Is the absence of an error message when requesting a PW reset with an unknown username intended or can this be added?
With kind regards,
Posts: 27300
It is a security measure to not divulge if that user does in fact exist. The code to change the behavior is:
in user/controllers/password.php
Dave
_____________________________________________
Blog & G2 || floridave - Gallery Team