• Resolved yuluma

    (@yuluma)


    Current situation with clean install and twenty 17 theme.

    Reset password with an email address that exists in the user section
    get a text message after reload that a password reset link was send to the given address

    Reset password with an email address that

      doesn’t exist

    in the user section
    get a redirect to the password reset page… nothing else

    According to general standards like this, or this I would expect the same response like:

    If you have an account with us we’ve send you an email with a link to reset your password.

    OR

    If WP cares less about security/privacy at least I would expect a text to display with a failed password request. Especially now we know there IS a difference between an exisiting and non existing email address.

    UX Bug
    At least we could state that we now have a situation where we do inform the customer and where we leave them in great doubt if anything happened at all. This can’t be good for the users of the sites that work with WP.

Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘Display text after lost password request’ is closed to new replies.