AuthMeReloaded icon indicating copy to clipboard operation
AuthMeReloaded copied to clipboard

Release accounts registered by mail and have not logged in

Open hsombini opened this issue 9 years ago • 2 comments

Hello guys, have you ever considered a register system that player must confirm his account by doing something or the account would be deleted so other player can register it?

Maybe just send the password through mail like the plugin already do, but if the player doesn't login in X amount of hours, the account will be deleted.

I feel that registering by email, many accounts would be will be registered but the owner will never login, maybe a typo on email or something else, with that feature we can make sure that the accounts will get released fast.

hsombini avatar Aug 13 '16 00:08 hsombini

Let's try not to shove everything in 5.2 please

ljacqu avatar Aug 13 '16 13:08 ljacqu

I would be happy for that too.

Right now it looks like this to me:

I have the following options after entering an incorrect Email or a fake Email: 1.: Or you will never restore your account to. 2.: Or you just can’t play because you sent the password to an email you don’t have.

There are a lot of problems with users, and since identities can only be verified with an email address, I’m amazed that this improvement hasn’t happened yet.

The problem is that there is no way the player can be identified. And so anyone could come in for forgetting their password.

Someone has spent real money, and someone just wants to break into your account.

So I would ask for at least one feature that if you enter an email, it will need to be verified and only then can registration continue. (It’s almost everywhere and so it’s logical I don’t understand why they don’t think about it here. This is a huge security issue. Especially on a server where hundreds play. 🙄)

It would be enough to put it in the e-mail registration with the "/verification" command to expand it.

Player: /register 12345 [email protected] System: Please check your email and enter the code. Player: /verification 12345 System: Registration successful.

If no confirmation is made within X minutes, registration will be free again and you will not need an account that would be fake.

So I can boldly instruct malicious players who just want to crack accounts. And for normal players, I will be able to recommend the "/email recorvery" command.

ColorsASD avatar May 09 '22 16:05 ColorsASD