Hi there,
So right now you can change your email without any verification. So if someone were to compromise my forum account somehow, they could login and change the email without a hassle. This also means the real user can't recover account access as the forget password function will send the password reset email to the new email.
I think it should be different. I know a large amount of websites that force users to verify their old email first when they change to a different one.
So:
Thanks.
So right now you can change your email without any verification. So if someone were to compromise my forum account somehow, they could login and change the email without a hassle. This also means the real user can't recover account access as the forget password function will send the password reset email to the new email.
I think it should be different. I know a large amount of websites that force users to verify their old email first when they change to a different one.
So:
- User changes the email of their XF account
- An email with a verification link gets sent out to the old email
- An email with a verification link gets sent out to the new email
- When user clicks the link on both accounts, the account email gets changed
Thanks.
Upvote
1