3 ms·
>if it has and they don't have it allow them to change their email to their real email address Couldn't an unscrupulous individual use that feature to take ove
by coderdude 13y ago
>if it has and they don't have it allow them to change their email to their real email address
Couldn't an unscrupulous individual use that feature to take over non-activated accounts? An immediate use for that exploit doesn't spring to mind but this makes my spidey sense tingle. What sites allow this?
- citricsquid 13y agoFrom my experience a user will almost always remember the password they've just entered, even if they got the email wrong. They should be able to login to a not-yet activated account and be presented with the option to correct the email for the activation email to be sent to. There's no potential for abuse there.