This repository was archived by the owner on Sep 10, 2024. It is now read-only.
Password recovery #13
Labels
A-Account-Management
Related to self-service account management
A-Local-Password
Related to the local password database
S-Major
Major functionality / product severely impaired, no satisfactory workaround.
T-Enhancement
New feature of request
Z-Product-Input
Requires input from the product team
Uh oh!
There was an error while loading. Please reload this page.
Users should be able to recover their account via email.
Potential flows:
The first flow feels better at not disrupting the current action. If you're in the middle of a client login, it's easier to resume that login after that.
The second flow feels better at preventing social engineering attacks, as we would require the person to click a link and change the password on the same device they are checking their emails, whereas in the option 1., the attacker could just ask "can you give me the code you just got by email" and the user could overlook that it's for a password change?
Open questions:
Relevant design screens:
The text was updated successfully, but these errors were encountered: