Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Limit password reset requests and reposition feedback message #1832

Open
Headphaze opened this issue Feb 7, 2025 · 0 comments
Open

Limit password reset requests and reposition feedback message #1832

Headphaze opened this issue Feb 7, 2025 · 0 comments

Comments

@Headphaze
Copy link

Currently there is the ability to send unlimited password reset requests in a short space of time.
This is a potential point of exploit and should probably be fixed.

I think a reasonable limit would be 5 minutes between activations of this requests.

Also, I think it's worth moving the pop up message to just above the request box so it's easier to see. It can be easily missed at the bottom of the screen on a light-mode interface: "If the address you've entered is correct, you should now receive an email with instructions"

Cheers

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant