-
Improvement
-
Resolution: Fixed
-
Trivial
-
1.8.3
-
None
-
N/A
-
MOODLE_18_STABLE
-
MOODLE_19_STABLE
When e-mail auth method is disabled www.domain.com/login/forgot_password.php should also be disabled to prevent mischievous users abusing it and flooding other users with password change e-mails.
There should also be something in the code that limits the number of e-mails sent to a specific e-mail address in a given time frame (if this is even possible?!).
I've removed the page from our site to stop this happening, but this isn't the most elegant fix.
Any ideas?
Thanks,
Marty
- has a non-specific relationship to
-
MDL-7407 Add turing number into email signup form
-
- Closed
-