Welcome Guest, Not a member yet? Register   Sign In
Community Auth Add User Registration Error
#2

(This post was last modified: 01-16-2017, 08:33 PM by skunkbad.)

If an unregistered user is attempting to login, Community Auth will never tell them that there is no email or username matching their attempt. This is by design, and in most authentication libraries considered normal, as it is pretty standard practice to reveal as little information as possible during a failed login attempt. Somebody can obviously use Community Auth's user recovery feature, but even that limits the amount of recovery requests before locking the recovery page, the theory being that you don't want somebody just hammering away at that so they can figure out the email addresses of your users.

Community Auth is years in the making, and every feature considered and reconsidered. Unless I'm wrong about what you're attempting to do, you're making a uninformed observation as to what is desirable.

Other things to know is that if the login is locked, the recovery is locked. If recovery is locked, the login is locked.
Reply


Messages In This Thread
RE: Community Auth Add User Registration Error - by skunkbad - 01-16-2017, 08:31 PM



Theme © iAndrew 2016 - Forum software by © MyBB