[wp-trac] [WordPress Trac] #24617: Spammed users should not be able to reset their password

WordPress Trac noreply at wordpress.org
Sat Apr 16 18:31:19 UTC 2016


#24617: Spammed users should not be able to reset their password
-------------------------------------------------+-------------------------
 Reporter:  r-a-y                                |       Owner:
     Type:  defect (bug)                         |  websupporter
 Priority:  normal                               |      Status:  assigned
Component:  Users                                |   Milestone:  4.6
 Severity:  normal                               |     Version:  3.0
 Keywords:  good-first-bug has-patch has-unit-   |  Resolution:
  tests                                          |     Focuses:  multisite
-------------------------------------------------+-------------------------
Changes (by jeremyfelt):

 * owner:   => websupporter
 * status:  new => assigned


Comment:

 Thanks @websupporter, [attachment:24617.03.patch] is looking good. Let's
 change the error text to something more generic so that we're not
 necessarily passing that info on to the user. The suggested "Your account
 has been disabled" from above seems right. Thoughts?

--
Ticket URL: <https://core.trac.wordpress.org/ticket/24617#comment:10>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list