node-login icon indicating copy to clipboard operation
node-login copied to clipboard

Added password confirmation on account creation & email verification via confirmation link.

Open bjwyse opened this issue 12 years ago • 5 comments

bjwyse avatar Feb 11 '13 22:02 bjwyse

This still needs a link to resend the verification e-mail. Trying to work on that now.

Et3rn1ty avatar Feb 20 '13 02:02 Et3rn1ty

Querystring hash?

I probably haven't thoroughly thought about this, but is it OK to just be sending the hashed password in a query string for the password reset?

You didn't change it but I wasn't sure where to ask this at.

ddoolin avatar Mar 01 '13 16:03 ddoolin

Not sure why you're asking on this issue. The verification hashes the username in order to verify. For password reset, why would sending the current password hash be a bad thing? as soon as it's reset the "current" hash may no longer be valid. EDIT: unless the user changes their password to the exact same password... but then why would they have requested a reset in the first place. EDIT 2: I dont know that much about encryption so i could be wrong that the same password would have the same hash given a second encryption.

Et3rn1ty avatar Mar 01 '13 16:03 Et3rn1ty

@bjwyse : I'd like to integrate your changes into my fork. Are you releasing your contributions under the same license as node-login, i.e., MIT?

brettz9 avatar Feb 05 '20 03:02 brettz9

I went ahead and released 1.0.0 of nogin incorporating these changes which includes these changes (the differences were I think substantial enough from this PR that inspired them). (My changes are breaking, however.)

Note that an update now causes a new activation to be required (user changing email). Email won't be changed until activated.

brettz9 avatar May 25 '20 10:05 brettz9