Skip to content

When creating an account don't email the password #11

@mawiseman

Description

@mawiseman

I think it would be better practice (and probably more secure) to send a link with userid and expiration date via jwt and force the user to choose their own password

https://jwt.io/

This would mean

  • admin passwords are floating around in emails
  • the user only had a limited time to action the email

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions