RocketChat / Rocket.Chat

The communications platform that puts data protection first.
https://rocket.chat/
Other
40.63k stars 10.63k forks source link

[BUG] Disabled password change bypass via forgot password #9434

Open cardoso opened 6 years ago

cardoso commented 6 years ago

Version: 0.60.4

Can change password by reseting password via "forgot password" even with Allow Password Change = false

hugocostadev commented 1 year ago

Still happening, we do not prevent the end user to request and set a new password through forgot password link...

image

I'll check the appropriated behavior, thanks for reporting and sorry for the late reply


Questions? Help needed? Feature Requests?