Xonotic Forums

Full Version: Forum password reset security
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
I notice the mechanism for resetting a password for the Xonotic Forums has quite an insecure step: your new, temporary password is sent in plaintext to your email account. Secondly, once you login using this password you are not automatically taken to the change password screen, instead being dropped off at the main page.

Would it be possible to have the first password reset link take you to a page where you can enter your new password straight away, rather than leaving the account somewhat more vulnerable until the user changes their password manually?
I don't see how your alternative would make it any harder from an adversarial point of view. It would make it less foolproof by forcing users to change their passwords, but that's all.

Anyway, I couldn't find a way. Sorry :x