michaellaunay / alirpunkto

0 stars 0 forks source link

The "define new password" form should contain the necessary fields only #97

Open SergioArbarviro opened 5 months ago

SergioArbarviro commented 5 months ago

When resetting his/her password ("forgot password" function), the user should focus on the information that is needed for him/her to update his/her passoword, and should waste no time. S/he should not either be provided with information that s/he has no access to and cannot modify at that moment.

As a consequence, only the following fields should be present in the "reset password" form:

All the other fields currently on the "reset password" form should be removed, namely:

These fields will be edited by the Cooperator / the Ordinary Member of the Community once s/he is connected, but only then.

SergioArbarviro commented 2 months ago

After reflection, the information that is displayed on the "reset password" form should be even less numerous, and be limited to:

only.

Indeed, it is needless to display to a person who may have stolen the access of the user to his/her e-mail address some elements of access to the AlirPunkto platform (namely: the Pseudonym) or that support the identification of the legitimate user to the platform (the UID).