[wp-trac] [WordPress Trac] #34281: Allow admins to send users a 'Reset Password' link
WordPress Trac
noreply at wordpress.org
Mon Feb 22 16:51:06 UTC 2021
#34281: Allow admins to send users a 'Reset Password' link
-------------------------------------------------+-------------------------
Reporter: Ipstenu | Owner:
| adamsilverstein
Type: task (blessed) | Status: reopened
Priority: normal | Milestone: 5.7
Component: Users | Version: 4.4
Severity: normal | Resolution:
Keywords: has-screenshots has-ux-feedback | Focuses:
has-patch has-dev-note | javascript, privacy
-------------------------------------------------+-------------------------
Comment (by audrasjb):
Replying to [comment:108 SergeyBiryukov]:
> That was my point, only add the IP address if the login is not the same
as the current user's login (which would be the case when requesting the
password reset link from the admin). But it's possible that I'm missing
something too :)
Ah! I believe we want the opposite :)
- Lost password link on wp-login: send the IP address so the user can be
prevented from request from other IPs
- New reset password methods on WP-Admin: don't send the IP address as the
password reset is asked by a known user on the website (and it fixes some
potential privacy issues)
--
Ticket URL: <https://core.trac.wordpress.org/ticket/34281#comment:109>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform
More information about the wp-trac
mailing list