Cms: Password reset GDPR

Created on 27 Mar 2018  Ā·  2Comments  Ā·  Source: craftcms/cms

I was reading an article this morning about how to prepare for GDPR and it mentions how to handle password reset requests. The suggestion is that we shouldn't be confirming whether or not an account exists based on the details provided.

Could a malicious user compromise data by triggering an error? For example, if a user enters email addresses in a ā€œForgot Emailā€ form, will the form confirm that the password reminder has been sent (and by inference confirm that the user has an account)?

If an account doesn't exist Craft informs the user:

image

Should this be changed so that the submission always succeeds, with the request only being processed if an account exists and failing silently if one doesn't?

question

Most helpful comment

There’s a config setting for that :) https://craftcms.com/docs/config-settings#preventUserEnumeration

All 2 comments

There’s a config setting for that :) https://craftcms.com/docs/config-settings#preventUserEnumeration

@brandonkelly Impressive! Thanks!

Was this page helpful?
0 / 5 - 0 ratings

Related issues

angrybrad picture angrybrad  Ā·  3Comments

bitboxfw picture bitboxfw  Ā·  3Comments

leigeber picture leigeber  Ā·  3Comments

brandonkelly picture brandonkelly  Ā·  3Comments

michaelhue picture michaelhue  Ā·  3Comments