[OpenStreetMap] #5130: Reset password facility leaks email addresses

OpenStreetMap trac at noreply.openstreetmap.org
Tue Feb 25 09:01:02 UTC 2014


#5130: Reset password facility leaks email addresses
-----------------------+-------------------------
  Reporter:  oxplot    |      Owner:  rails-dev@…
      Type:  defect    |     Status:  closed
  Priority:  critical  |  Milestone:
 Component:  website   |    Version:
Resolution:  wontfix   |   Keywords:
-----------------------+-------------------------
Changes (by TomH):

 * status:  new => closed
 * resolution:   => wontfix


Comment:

 I'm perfectly well aware of that advice, but we have chosen not to follow
 it in this case because, frankly, it makes for utterly terrible usability.

 If the only feedback to let you know if you typed the address right, or if
 your memory of which address you registered with is correct, is an email
 that might not arrive until some hours later then the whole experience
 becomes a nightmare for a (possibly not very technical) user.

 As the person who gets the emails when people can't help themselves there
 is no way I am going to do this I'm afraid.

-- 
Ticket URL: <https://trac.openstreetmap.org/ticket/5130#comment:1>
OpenStreetMap <http://www.openstreetmap.org/>
OpenStreetMap is a free editable map of the whole world



More information about the rails-dev mailing list