Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-44685

Password reset messages are misleading

    XMLWordPrintable

Details

    • 3
    • 3
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

    Description

      Background

      CWD-3484 underlined a misleading wording that was displayed as password reset message. While it apparently has been fixed for Crowd, it is still an issue in JIRA:

      The message that is displayed can be very misleading as it always informs users that an email was sent even though this is not always true. If there are no plans to make the message conditional, it would certainly make sense to at least change the wording of the generic message. Perhaps something like the following would be more appropriate:
      "Thank you. If we find an account matching the username you have entered you will receive an email with further instructions and a reset password link. The link will lead to a page where you can choose your new password."

      Steps to reproduce

      1. Go to the log in page and click on Can't access your account?
      2. Type in any string as user name which is either existing or not
      3. The following misleading message is displayed:

      A reset password link has been sent to you via email.
      You can follow that link and select a new password.
      If the email does not arrive, please contact your JIRA administrators.

      As pointed out in CWD-2457, not revealing whether or not the user exists in the db is a cautious design decision, which is fine.

      Suggestion

      However, in line with CWD-3484, a more generic wording should be used in JIRA as well:

      Thanks! If we recognise that email address, you should receive a link to reset your password via email soon. If you don't receive an email in the next five minutes, check your spam folder or try again with a different email address.

      Our additional suggestion:

      Please also make sure to not include a leading or trailing whitespace (e.g. by copying and pasting your user name.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              5754b9a6c8ea Andreas van Rienen (Scandio)
              Votes:
              14 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated: