gcivil-nyu-org / nycCivilServiceJobs

4 stars 3 forks source link

BUG: Able to receive email for password reset even when account not activated(but user is created) #142

Closed gururaj3 closed 3 years ago

gururaj3 commented 3 years ago

Issue tracker is ONLY used for reporting bugs. New features should be discussed in its own thread on the #general channel of slack.

I created an account with email gss399@nyu.edu and I did not activate my account. Now, when I click on Password reset, I am still getting the reset link email to change my password.

Expected Behavior

According to me, we should first verify if the user is activated and then only send him/ her an password reset email.

Current Behavior

User can still reset his/ her password even when the account is not activated.

Ideas for Improvement

Steps to Reproduce

1. 2. 3. 4.

Context (Environment)

gauravag2207 commented 3 years ago

Hi @gururaj3 We don't have the feature to verify the account. As soon as a user creates an account, it's active and we send a confirmation email. The same is mentioned in the testing guide as well. So, this would not qualify as a bug. But we are looking into an enhancement to include email verification if time permits. If we do that, this would also be implemented.

Thanks

shivangpandya commented 3 years ago

This is working as intended, the account is activated as soon as you register and hence you are able to reset your password