[wp-trac] [WordPress Trac] #43037: Login error message "Invalid username. Lost your password?" is confusing

WordPress Trac noreply at wordpress.org
Wed Sep 11 17:00:28 UTC 2019


#43037: Login error message "Invalid username. Lost your password?" is confusing
-------------------------------------------------+-------------------------
 Reporter:  afercia                              |       Owner:
                                                 |  SergeyBiryukov
     Type:  defect (bug)                         |      Status:  reviewing
 Priority:  normal                               |   Milestone:  5.3
Component:  Login and Registration               |     Version:  2.8
 Severity:  normal                               |  Resolution:
 Keywords:  has-screenshots has-patch has-copy-  |     Focuses:  ui,
  review 2nd-opinion                             |  accessibility
-------------------------------------------------+-------------------------
Changes (by afercia):

 * keywords:  has-screenshots has-patch has-copy-review => has-screenshots
     has-patch has-copy-review 2nd-opinion


Comment:

 To clarify (before it gets asked) why WordPress doesn't hide error
 messages related to the username and why that's not considered
 "information disclosure", see
 https://core.trac.wordpress.org/ticket/3708#comment:3 and all the
 following tickets closed as "wontfix", for example #4290.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/43037#comment:27>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list