- Notifications
You must be signed in to change notification settings - Fork 305
Closed
Labels
Description
In Reset Password /account/password/reset, if you enter a valid username you get
An invalid username results in
This can be used to confirm whether or not a username exists. It would be better if both cases resulted in the same message. That could be the original message or perhaps "A Reset Password link has been sent to the email associated with this username"
This is a simple fix but as it is a security issue, please could you do an immediate release.
See also: #1758