nasa-gcn / gcn.nasa.gov

General Coordinates Network (GCN) web site
https://gcn.nasa.gov
Other
184 stars 44 forks source link

Missed confirmation emails can lock up accounts #2246

Open HaoxuanGuo opened 7 months ago

HaoxuanGuo commented 7 months ago

Current behavior

Accounts that miss the confirmation email are locked due to the bug and can neither re-register nor choose to forget their password.

Expected behavior

This email address should either remain unregistered and can be re-registered, or a password can be set by retrieving the password.

Steps to reproduce

  1. Register for an account
  2. Not receiving or ignoring confirmation emails
  3. the email is locked
  4. Complete the reproduction

Environment

Safari 17.4.1 (19618.1.15.11.14) macOS 14.4.1 (23E224)

lpsinger commented 7 months ago

Yes, this is a major pain point with our identity and access management system, AWS Cognito.