api-management-developer-portal icon indicating copy to clipboard operation
api-management-developer-portal copied to clipboard

Request password reset returns internal server error when email address is not valid

Open rachel-langford opened this issue 5 years ago • 8 comments

Every bug report should have precise description and reproduction steps; console traces or source code references are appreciated.

For assistance requests, contact Azure support or submit a post on Stack Overflow. We don't provide support through GitHub Issues. Feature requests can be raised on the Azure Feedback Forum.

Bug description

If a password reset is requested for an email address not registered on with API management, get "Server error. Unable to send request. Please try again later"

Reproduction steps

  1. Go to forgot password
  2. enter a email address that is not valid for any user
  3. enter the characters
  4. click request reset
  5. Server error is returned

Expected behavior

Same as if it was a valid email address. The site shouldn't error - could be used to compromise system if can identify valid vs non valid email addresses registered.

Is your portal managed or self-hosted?

Managed

Release tag or commit SHA (if using self-hosted version)

NA

API Management service name

emi

Environment

Chrome / Windows 10

Additional context

image

rachel-langford avatar Jan 29 '20 19:01 rachel-langford

Hi Rachel, thanks for reporting the issue. We would need your APIM service name to investigate it. Please send it to [email protected].

azaslonov avatar Jan 29 '20 20:01 azaslonov

Have emailed (it's emi, as mentioned above)

rachel-langford avatar Jan 29 '20 20:01 rachel-langford

@rachel-langford thank you, we will enhance this behavior in the next managed version release

ygrik avatar Jan 29 '20 21:01 ygrik

Please reopen this issue, as it has not been solved.

antonsalimAU avatar Nov 11 '21 04:11 antonsalimAU

By adding this issue to the Backlog project, we have prioritized it for development. You can monitor its status in the project's board.

msftbot[bot] avatar Nov 11 '21 20:11 msftbot[bot]

@antonsalimAU, we will soon start working on a fix and it will likely be deployed in the first quarter of 2022.

mikebudzynski avatar Nov 11 '21 20:11 mikebudzynski

Is there an update on this?

ChrisZevenbergenNavara avatar Apr 22 '22 09:04 ChrisZevenbergenNavara

@harunrst Has this improvement been implemented?

mikebudzynski avatar May 07 '22 04:05 mikebudzynski