Closed Quantum-Codes closed 10 months ago
I can reset that password if you message me on Discord. I am an admin.
I can reset that password if you message me on Discord. I am an admin.
Thanks, now only change password feature needsd
Definitely a priority, but I need suggestions, how are we going to reset forgotten passwords? We could do a reset multiple ways:
- Some other way that doesn't require an email, if that's even possible and secure?
We can store old passwords hashed and have it verify that is your old password. Kinda the way Chromebooks verify sign-in when you change your password.
But wouldn't that only work if you remembered your password? In that case you wouldn't have to reset your password because you wouldn't have forgotten it lol
On Wed, Oct 12, 2022, 3:35 PM cruncher12 @.***> wrote:
- Some other way that doesn't require an email, if that's even possible and secure? We can store old passwords hashed and have it verify that is your old password. Kinda the way Chromebooks verify sign-in when you change your password.
— Reply to this email directly, view it on GitHub https://github.com/TurtleCode84/tracktask/issues/74#issuecomment-1276647925, or unsubscribe https://github.com/notifications/unsubscribe-auth/AZMRUPTVM6E6FUL4YVOVXSDWC4HJBANCNFSM6AAAAAARDIP4XY . You are receiving this because you commented.Message ID: @.***>
No, the password before the one you forgot.
Hmm, it could work, maybe something like a security phrase? But if you forget the security phrase then you have to get that reset 🤣
(Edit: Nevermind, super insecure)
Still a good idea though 👍
On Wed, Oct 12, 2022, 7:06 PM cruncher12 @.***> wrote:
No, the password before the one you forgot.
— Reply to this email directly, view it on GitHub https://github.com/TurtleCode84/tracktask/issues/74#issuecomment-1276820794, or unsubscribe https://github.com/notifications/unsubscribe-auth/AZMRUPURZ2KLB5WVNNBBIALWC5AABANCNFSM6AAAAAARDIP4XY . You are receiving this because you commented.Message ID: @.***>
Maybe a reset file?
The security phrase could be encrypted/hashed maybe?
A security phrase is even more insecure than a password since people will probably make easily guess able phrases.
Right, at that point you might as well make it a second password, and then what if you forget that?
Making a second password is useless... May work but uh not ideal
Guess we have to get an SMTP 🙄
Guess we have to get an SMTP 🙄
In this case I'm going to have to push this feature back, even though it's "priority", I'm not sure if we'll have a spare endpoint once everything is in place so I want to wait.
We don't need to have an SMTP server… We could just have an MX record pointing to whatever we use. Or, we could just use ProtonMail or GMail. Anything really work fine if it has an SMTP or mail server to send it through. It is pretty easy to implement sending emails in Python, at least.
We don't need to have an SMTP server… We could just have an MX record pointing to whatever we use. Or, we could just use ProtonMail or GMail. Anything really work fine if it has an SMTP or mail server to send it through. It is pretty easy to implement sending emails in Python, at least.
Yeah, the only demotivator I have with going through the process is that a lot of mail services have either a really long verification time or they just block you and force you to email support & wait about a week for a response... We're using MX records right now for Cloudflare email routing, but that's about all it can do.
I'll try not to be lazy this weekend :P
What are we using right now? (for emails)
What are we using right now? (for emails)
MX records
We're using MX records right now for Cloudflare email routing, but that's about all it can do.
What I was saying is what email service are using (GMail, ect. what?)
This next week, I'll try and make a PoC password reset thing in python. It should be too hard, but we'll see I guess.
Shouldn't*
[ What I was saying is what email service are using (GMail, ect. what?) ]
We aren't at the moment, the only email stuff we have is MX records that redirect mail sent to our domain addresses to my personal email, through Cloudflare.
On Sat, Oct 15, 2022, 7:54 AM cruncher12 @.***> wrote:
What I was saying is what email service are using (GMail, ect. what?)
— Reply to this email directly, view it on GitHub https://github.com/TurtleCode84/tracktask/issues/74#issuecomment-1279729845, or unsubscribe https://github.com/notifications/unsubscribe-auth/AZMRUPVPYM4VWE56CYVVOWLWDKLQ5ANCNFSM6AAAAAARDIP4XY . You are receiving this because you commented.Message ID: @.***>
Oh, that make a bit more sense. :'D
Oh, that make a bit more sense. :'D
Sorry if I was confusing lol
Oh, its okay, no problem. It was like 6 in the morning so my brain ws not working. :cold_face:
Just migrated from Cloudflare's email routing to Zoho mail, so now I can both send and receive mail from the .tracktask.eu.org
domain. I also should be able to make a mail sending API if I figure out how to use Oauth2.
Update on this, I'm getting SendGrid SMTP set up, we have exactly one API endpoint to spare so this may get pushed forward on the timeline.
Will focus on this after #227
There are very important to implement and I think Change password should be given priority