go2null / redmine_account_policy

Password Expiry and other enhancements
GNU General Public License v3.0
3 stars 13 forks source link

Lost password view exposes real user emails #13

Closed farkwun closed 8 years ago

farkwun commented 8 years ago

In current Redmine implementation, lost password behaves differently depending on user status and on user existence.

This allows 'real' accounts to be identifiable through this view.