Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Username recovery #89

Open
auriamg opened this issue Mar 9, 2018 · 11 comments
Open

Username recovery #89

auriamg opened this issue Mar 9, 2018 · 11 comments
Assignees

Comments

@auriamg
Copy link
Member

auriamg commented Mar 9, 2018

Some users may forget their username, so username recovery based on their email would be a welcome feature

@vampy vampy self-assigned this Mar 25, 2018
@qwertychouskie
Copy link
Contributor

Maybe just change the password recovery to only require their username or email, not both. Some users also may forget which of their emails they used when making the account, but still know their username, so this would benefit them too.

@auriamg
Copy link
Member Author

auriamg commented Feb 24, 2019

@leyyin I would like to remove the "Minor" label you added as this is generating quite a fair amount of support requests that we need to handle manually

@auriamg auriamg removed the P4: Minor label Feb 24, 2019
@vampy
Copy link
Member

vampy commented Feb 25, 2019

Ok, I'll see what I can do about this.

@snowfall-sc
Copy link

My User name totally forget please help.

@ringo32
Copy link

ringo32 commented May 12, 2019

cannot make a new login or finding my old login :)

@grantcarthew
Copy link

Same here. Kids username has been forgotten. Can't register a new name because the email already exists. Seems a little silly requiring both a username and a password.

@deveee
Copy link
Member

deveee commented Aug 20, 2019

@grantcarthew If user name doesn't matter, then you can just use something like https://10minutemail.net/

@grantcarthew
Copy link

Hi @deveee and thanks for the comment. This is not what this issue is about. If I wanted to create an account I could.

No website anywhere asks for your username AND email address to reset. If the usernames have to be unique, then you only need one of the identity items. If the usernames do not need to be unique, then you only need the email address to reset.

Whilst on this topic, it is a security breach to inform the person who is resetting the account that the username/email combination failed. A "reset submitted successfully" message is all that should be displayed. By letting the user know that they got something wrong you enable brute force attacks.

I'm running Debian unstable and update often. This issue is going to get bigger quickly. You are seeing the early adopters right now.

@deveee
Copy link
Member

deveee commented Aug 20, 2019

I understand the problem, it was just a quick workaround.

@dmccollough1
Copy link

Sad that here at the tail end of 2023 that this is still open and unresolved. :(
(and yes, if I knew how to fix this issue, I'd gladly contribute code to do so)

@JusPLP
Copy link

JusPLP commented Aug 2, 2024

are there any plans?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

9 participants