Page MenuHomePhabricator

Special:PasswordReset should ask only for e-mail address
Closed, DeclinedPublic

Description

Author: jgonera

Description:
The message on Special:PasswordReset says:

"If you are certain of your e-mail, but not your username, only enter your e-mail."

Why would anyone enter their username then?


Version: 1.21.x
Severity: normal
See Also:
https://bugzilla.wikimedia.org/show_bug.cgi?id=40040

Details

Reference
bz46009

Event Timeline

bzimport raised the priority of this task from to Needs Triage.Nov 22 2014, 1:37 AM
bzimport set Reference to bz46009.
bzimport added a subscriber: Unknown Object (MLST).

In MediaWiki, user's email address is private info.
We should not make it possible for someone to check whether an email is registered.

(In reply to comment #1)

In MediaWiki, user's email address is private info.
We should not make it possible for someone to check whether an email is
registered.

and plus, some people can't remind there signup email addess :p

Note that I wrote the text only on English Wikipedia (it's not in core):

https://en.wikipedia.org/wiki/Special:AllMessages?prefix=passwordreset-text

As I said at bug 40040, it takes a little more work to get a good message in core, since there is more variability in the form fields.

JuneHyeon is correct on both counts:

  1. Not revealing whether an email is registered, though that is more relevant to bug 46010
  2. It sometimes being easier to just enter your username if you are certain of it.