Always present success message for non-existent users

Created on 24 August 2017, over 7 years ago
Updated 2 October 2023, over 1 year ago

In order to prevent enumeration attacks where the attacker tries to identify if an email address is registered on the website, add an option to present the standard "email sent" message (without actually the email being sent) instead of presenting an error when a non-existent email tries to login.

Feature request
Status

Fixed

Version

2.0

Component

Code

Created by

🇩🇪Germany fotidim Berlin

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024