#14918: Password reset with e-mail OR username
-------------------------------------+--------------------------------------
          Reporter:  jonash          |         Owner:  nobody
            Status:  new             |     Milestone:        
         Component:  Authentication  |       Version:  SVN   
        Resolution:                  |      Keywords:  auth  
             Stage:  Unreviewed      |     Has_patch:  1     
        Needs_docs:  0               |   Needs_tests:  0     
Needs_better_patch:  0               |  
-------------------------------------+--------------------------------------
Changes (by Keryn Knight <[email protected]>):

  * needs_better_patch:  => 0
  * component:  Uncategorized => Authentication
  * needs_tests:  => 0
  * needs_docs:  => 0

Comment:

 Does this not further expose the ability to grief another user with reset-
 password emails? Usernames are more prevalent as (often persistent) online
 personas, and emails are, comparatively speaking, closely guarded
 (largely, I suspect, because of the deluge of spam).

 In a scenario such as say, a forum, where people may not always get on,
 providing the ability to easily send a reset-password email to anyone
 who's username you can see seems like an open invitation to annoy.

-- 
Ticket URL: <http://code.djangoproject.com/ticket/14918#comment:1>
Django <http://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/django-updates?hl=en.

Reply via email to