Open SergioArbarviro opened 8 months ago
After reflection, the information that is displayed on the "reset password" form should be even less numerous, and be limited to:
only.
Indeed, it is needless to display to a person who may have stolen the access of the user to his/her e-mail address some elements of access to the AlirPunkto platform (namely: the Pseudonym) or that support the identification of the legitimate user to the platform (the UID).
When resetting his/her password ("forgot password" function), the user should focus on the information that is needed for him/her to update his/her passoword, and should waste no time. S/he should not either be provided with information that s/he has no access to and cannot modify at that moment.
As a consequence, only the following fields should be present in the "reset password" form:
All the other fields currently on the "reset password" form should be removed, namely:
These fields will be edited by the Cooperator / the Ordinary Member of the Community once s/he is connected, but only then.