Rocket.chat: Password reset confirmed also at non-existing e-mail address

Created on 3 Mar 2017  路  7Comments  路  Source: RocketChat/Rocket.Chat

When asking for a password reset, a notification pops up, that an e-mail has been sent with further instructions, even with non-existing e-mail addresses. We would expect saying that there is no user associated to that e-mail address.
Furthermore, if you repeat this, the "Password reset" button is duplicated (see screenshot):
bildschirmfoto_2017-03-03_11-14-06

Rocket.Chat Version: 0.52

email uux bug

Most helpful comment

@rasos this could possibly be a "security feature". Because you can get the information is someone is registred with this email adress.. if it says at all requests "positive" you dont have this problem.

All 7 comments

@rasos this could possibly be a "security feature". Because you can get the information is someone is registred with this email adress.. if it says at all requests "positive" you dont have this problem.

For the reasons stated by @TheReal1604 we will always do a false positive, but the button error needs to be fixed @karlprieb

Maybe we should make it more clear.. adding a "If this email is registered, we'll send instructions on how to reset your password"

@rasos , I am unable to reproduce the bug. I'm on 0.53-develop. When I click on reset password, it takes me to the login page. when I again click forgot password, I don't see any duplicated button.

@va6996 the duplicated button is definitely reproducable on 0.52, I have the same issue on a test server as well as on production, both repeatedly updated since 0.36 or so. Will check again after our next upgrade cycle.

Weird login button behaviour is duplicate of #6255 - see screencast https://vid.me/qUoP

The button error was fixed on 0.56 (#6741) and the behaviour reported is so by design, so I'll be closing this issue.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

royalaid picture royalaid  路  3Comments

djeber picture djeber  路  3Comments

karlprieb picture karlprieb  路  3Comments

amayer5125 picture amayer5125  路  3Comments

neha1deshmukh picture neha1deshmukh  路  3Comments