•  
      request #31095 Send confirmation email after password reset
    Infos
    #31095
    Nicolas Terray (nterray)
    2023-02-23 17:47
    2023-02-23 17:47
    32699
    Details
    Send confirmation email after password reset

    When the user reset its password, it is recommended to:

    Send the user an email informing them that their password has been reset (do not send the password in the email!).

    https://cheatsheetseries.owasp.org/cheatsheets/Forgot_Password_Cheat_Sheet.html#user-resets-password

    Note: I suggest to do the same when the user change its password in user preferences » security.

    UX/UI
    Empty
    Empty
    • [ ] enhancement
    • [x] internal improvement
    Empty
    Stage
    Empty
    Verified
    Empty
    Attachments
    Empty
    References
    References list is empty