Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 293733

Provide a standard mechanism to determine whether a user's password can be reset.

$
0
0

Motivation

It is desired by various issues (see below) to add a central mechanism for determining whether a user's password can be reset.

This would provide the facility to (allow contrib to):

This patch does not propose implementing the above ideas.

Proposed resolution

Standardize on a password reset access operation.

When a request for a user's password reset cannot be satisfied, the error should be vague and not leak the existence of the user, aka user enumeration.

User interface changes

None

API changes

None

Data model changes

None


Viewing all articles
Browse latest Browse all 293733

Trending Articles