-
Notifications
You must be signed in to change notification settings - Fork 101
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CANTINA-954: Security: Use ambiguous error message in forgot password #4973
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
rebeccahum
force-pushed
the
change-login-message
branch
from
October 24, 2023 18:03
f14bd78
to
e6cdf02
Compare
Codecov Report
@@ Coverage Diff @@
## develop #4973 +/- ##
=============================================
+ Coverage 28.76% 28.79% +0.03%
Complexity 4742 4742
=============================================
Files 278 278
Lines 20896 20904 +8
=============================================
+ Hits 6010 6019 +9
+ Misses 14886 14885 -1
|
mebbe fix test with type checking
rebeccahum
force-pushed
the
change-login-message
branch
from
October 24, 2023 21:28
a64c315
to
9988539
Compare
sjinks
approved these changes
Oct 24, 2023
WPprodigy
reviewed
Oct 25, 2023
@@ -1,13 +1,17 @@ | |||
<?php | |||
namespace Automattic\VIP\Security; | |||
|
|||
use WP_Error; | |||
|
|||
const FORGET_PWD_MESSAGE = 'If there is an account associated with the username/email address, you will receive an email with a link to reset your password.'; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This needs to be a translatable string :)
github-actions
bot
added
[Status] Deployed to staging
[Status] Deployed to production
and removed
[Status] Deployed to staging
labels
Oct 31, 2023
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
We should use an ambiguous error message in the Forgot Password, since the messages confirm if a user has entered a correct username or email in the "Forgot Password" form.
Changelog Description
Updated: Forgot Password
When users hit the Forgot Password in wp-login, it will no longer confirm if their email or username exists.
Pre-review checklist
Please make sure the items below have been covered before requesting a review:
Pre-deploy checklist
Steps to Test
[email protected]
vipgo