Please Log in or Create an account to join the conversation.
We're aware, but it requires a rewrite of forgot login so it has not been done yet. The password sent is randomly generated however so there's no issues regarding plaintext storage at the very least. The user is expected to change their password.The password reset email sends both the username and password, which is a huge no-no from security perspective.
No, not until we've redesigned the forgot login behavior.Is there a way to send a password reset token/link (similar to Joomla's native password reset) instead?
Please Log in or Create an account to join the conversation.
Please Log in or Create an account to join the conversation.
Please Log in or Create an account to join the conversation.
Please Log in or Create an account to join the conversation.
Please Log in or Create an account to join the conversation.