Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-57682

Password reset messages are misleading

    XMLWordPrintable

Details

    • Suggestion
    • Resolution: Unresolved
    • None
    • Content - Page
    • None
    • 1
    • 1
    • We collect Confluence feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

    Description

      Background

      CWD-3484 underlined a misleading wording that was displayed as password reset message. While it apparently has been fixed for Crowd, it is still an issue in Confluence:

      The message that is displayed can be very misleading as it always informs users that an email was sent even though this is not always true. If there are no plans to make the message conditional, it would certainly make sense to at least change the wording of the generic message. Perhaps something like the following would be more appropriate:
      "Thank you. If we find an account matching the username you have entered you will receive an email with further instructions and a reset password link. The link will lead to a page where you can choose your new password."

      Steps to reproduce

      1. Go to the login page and click on Forgot your password?
      2. Type in any string as username which is either existing or not
      3. The following misleading message is displayed:


      As pointed out in CWD-2457, not revealing whether or not the user exists in the DB is a cautious design decision, which is fine.

      Suggestion

      However, in line with CWD-3484, a more generic wording should be used in Confluence as well:

      Thanks! If we recognize that email address, you should receive a link to reset your password via email soon. If you don't receive an email in the next five minutes, check your spam folder or try again with a different email address.

      Our additional suggestion:

      Please also make sure to not include a leading or trailing whitespace (e.g. by copying and pasting your username.

      Attachments

        1. screenshot-3.png
          screenshot-3.png
          13 kB
        2. screenshot-2.png
          screenshot-2.png
          8 kB
        3. screenshot-1.png
          screenshot-1.png
          15 kB

        Issue Links

          Activity

            People

              Unassigned Unassigned
              afernandezanusuyia AmandaFernandez (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated: