[wp-trac] [WordPress Trac] #34281: Allow admins to send users a 'Reset Password' link

WordPress Trac noreply at wordpress.org
Mon Feb 22 16:51:06 UTC 2021


#34281: Allow admins to send users a 'Reset Password' link
-------------------------------------------------+-------------------------
 Reporter:  Ipstenu                              |       Owner:
                                                 |  adamsilverstein
     Type:  task (blessed)                       |      Status:  reopened
 Priority:  normal                               |   Milestone:  5.7
Component:  Users                                |     Version:  4.4
 Severity:  normal                               |  Resolution:
 Keywords:  has-screenshots has-ux-feedback      |     Focuses:
  has-patch has-dev-note                         |  javascript, privacy
-------------------------------------------------+-------------------------

Comment (by audrasjb):

 Replying to [comment:108 SergeyBiryukov]:
 > That was my point, only add the IP address if the login is not the same
 as the current user's login (which would be the case when requesting the
 password reset link from the admin). But it's possible that I'm missing
 something too :)

 Ah! I believe we want the opposite :)

 - Lost password link on wp-login: send the IP address so the user can be
 prevented from request from other IPs
 - New reset password methods on WP-Admin: don't send the IP address as the
 password reset is asked by a known user on the website (and it fixes some
 potential privacy issues)

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/34281#comment:109>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list