It is currently 16 Sep 2019, 21:34




 Page 1 of 1 [ 2 posts ] 
Author Message
 Post subject: Password update/reset  Topic is solved
PostPosted: 20 Jan 2016, 08:54 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 2440
Location: France
Has thanked: 83 times
Been thanked: 162 times
Hello!

Finally, I was challenged to write decent code to handle a password update/reset and had a free evening yesterday to do just that!

Before:

Manually update the password in the SQL dabatase and store it un-encrypted.
This will make the Forum account out of sync.
Ask the user to log in with the temporary password and update it again to re-synchronize Account + Forum.

Problem: almost nobody sets a new password to resync the account, leaving the password in clear in the database and generating logon errors on the Forum.

After:

One click, popup for a new value from the Admin interface.
Password encrypted directly.
Password + Forum account is re-sync'ed.
No need to ask the user to update the password again.
Notification Email automatically sent.

Planned:

Re-use this code to let users request a password reset with email confirmation.

Julien
_________________
LDDb on Facebook!
HLD-X9 | LG-1 | RFD-1 | MSC-4000 | Lumagen 2144
DHS-8.8 | Oppo 205 | SL-1200G
Offline
 Profile  
 
 Post subject: Re: Password update/reset
PostPosted: 20 Jan 2016, 12:31 
Advanced fan
Advanced fan
User avatar

Joined: 13 Sep 2012, 23:14
Posts: 653
Location: United Kingdom
Has thanked: 33 times
Been thanked: 26 times
admin wrote:
Hello!

Finally, I was challenged to write decent code to handle a password update/reset and had a free evening yesterday to do just that!

Before:

Manually update the password in the SQL dabatase and store it un-encrypted.
This will make the Forum account out of sync.
Ask the user to log in with the temporary password and update it again to re-synchronize Account + Forum.

Problem: almost nobody sets a new password to resync the account, leaving the password in clear in the database and generating logon errors on the Forum.

After:

One click, popup for a new value from the Admin interface.
Password encrypted directly.
Password + Forum account is re-sync'ed.
No need to ask the user to update the password again.
Notification Email automatically sent.

Planned:

Re-use this code to let users request a password reset with email confirmation.

Julien


Julien,

most of the time I have no idea what the tech updates mean (pretty hopeless PC/computer wise) but can I just say thanks for the site & thanks for all your time & work to keep it going the way it does.

I for one genuinely appreciate what you do for us all here.

Again..... THANK-YOU
Offline
 Profile  
 
Display posts from previous:  Sort by  
 Page 1 of 1 [ 2 posts ] 


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to: