Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-18787

The "Forgot your password?" form offers too much information concerning user accounts

    XMLWordPrintable

Details

    • Integration
    • Unknown
    • N/A
    • N/A

    Description

      Steps to reproduce:

      Result: the platform confirms if the user exists or not (on 12.10.8 and 13.4).

      Expected result: a generic message concerning the password without confirming if the user  exists or not (e.g. "If the account is registered on the application, you will receive a dedicated message").

      Attachments

        Issue Links

          Activity

            People

              surli Simon Urli
              oana.tabaranu Elena-Oana Florea
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: