After changing to a new email address for use with an account, verifying it, and using it on the account for six months, it becomes un-removable, but allows for all earlier email addresses to be removed on the Manage Email page.
"This page lets you remove past e-mail addresses that were used with your account. If you remove an address, it will no longer be possible to have your password mailed to that address. This is useful if somebody discovered your password and hijacked your journal. Simply have the new password mailed to your old address, change the password, and remove the attacker's e-mail address.
This page only lets you remove e-mail addresses that were used after the first time you used the e-mail address your account is currently validated with. In particular, this means an attacker isn't able to remove your original e-mail address." This needs the following updates: you can't email yourself a password, just a password reset; you can now remove *any* previously-validated addresses after the new address has been validated for 6 months. Shall I just comment here, or stick that in Jira
( ... )
I think the new email management system is a very nifty system that handily prevents abuse from a hacker changing the email while letting people kill off old emails being attached to their accounts.
Removed the timestamp from "last updated" on the profile page Fixed reply link in email notifications when CAPTCHA is enabled so that the reply will be properly threaded upon successful CAPTCHA test
Comments 81
Thank you so much!!!
ETA The element doesn't yet appear to be working correctly in Magazine.
This is after a cash clearing.
Reply
Reply
Reply
Reply
"This page lets you remove past e-mail addresses that were used with your account. If you remove an address, it will no longer be possible to have your password mailed to that address. This is useful if somebody discovered your password and hijacked your journal. Simply have the new password mailed to your old address, change the password, and remove the attacker's e-mail address.
This page only lets you remove e-mail addresses that were used after the first time you used the e-mail address your account is currently validated with. In particular, this means an attacker isn't able to remove your original e-mail address."
This needs the following updates: you can't email yourself a password, just a password reset; you can now remove *any* previously-validated addresses after the new address has been validated for 6 months. Shall I just comment here, or stick that in Jira ( ... )
Reply
Reply
Reply
Reply
Reply
Fixed reply link in email notifications when CAPTCHA is enabled so that the reply will be properly threaded upon successful CAPTCHA test
YES YES YES THANK YOU
Reply
Leave a comment