Skip to content

Return an error message if the user doesn't exist inside ReviseAuth::PasswordResetsController #84

Closed Answered by excid3
ahmadabdelhalim asked this question in Q&A
Discussion options

You must be logged in to vote

No, the general best practice here is to send the same message either way. It helps prevent people checking if an account is registered with that email if someone is trying to do malicious things.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ahmadabdelhalim
Comment options

Answer selected by ahmadabdelhalim
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #83 on June 10, 2024 16:23.