I think the new email address must be confirmed before the old email address is removed. What if a user puts in someone else's email address? The way XF currently works, the new email will start receiving messages without authorizing it. Could be a potential problem. Many websites work this way now.Confirm new email from the old email would be a nice feature. If a users account has been breached they couldn't change the email and the owner would still be able to recover the account.
That doesn't help if the account has been breached, they could just update and confirm the email to their own.I think the new email address must be confirmed before the old email address is removed. What if a user puts in someone else's email address? The way XF currently works, the new email will start receiving messages without authorizing it. Could be a potential problem. Many websites work this way now.
@Mike any thoughts?
Correct, I never suggested it for anything breach related. It's definitely an outlet that could be leveraged for misuse, and as also noted, for some bizzare reason some users will put in a bogus address rather than simply unsubscribe.That doesn't help if the account has been breached, they could just update and confirm the email to their own.
Correct, I never suggested it for anything breach related. It's definitely an outlet that could be leveraged for misuse, and as also noted, for some bizzare reason some users will put in a bogus address rather than simply unsubscribe.
What you suggested is not practical, because many times users no longer have access to the old email account to approve the change.

We use essential cookies to make this site work, and optional cookies to enhance your experience.