It is currently 29 Mar 2024, 09:19




 Page 1 of 1 [ 2 posts ] 
Author Message
 Post subject: Password update/reset  Topic is solved
PostPosted: 20 Jan 2016, 08:54 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 4540
Location: Tokyo
Has thanked: 292 times
Been thanked: 1136 times
Hello!

Finally, I was challenged to write decent code to handle a password update/reset and had a free evening yesterday to do just that!

Before:

Manually update the password in the SQL dabatase and store it un-encrypted.
This will make the Forum account out of sync.
Ask the user to log in with the temporary password and update it again to re-synchronize Account + Forum.

Problem: almost nobody sets a new password to resync the account, leaving the password in clear in the database and generating logon errors on the Forum.

After:

One click, popup for a new value from the Admin interface.
Password encrypted directly.
Password + Forum account is re-sync'ed.
No need to ask the user to update the password again.
Notification Email automatically sent.

Planned:

Re-use this code to let users request a password reset with email confirmation.

Julien
_________________
HARDWARE DATABASE
HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G
LDD-1 MSC-4000 R2144 PONTUS II C45 MC257
Offline
 Profile  
 
 Post subject: Re: Password update/reset
PostPosted: 20 Jan 2016, 12:31 
Hardcore fan
Hardcore fan
User avatar

Joined: 13 Sep 2012, 23:14
Posts: 1199
Location: United Kingdom
Has thanked: 265 times
Been thanked: 259 times
admin wrote:
Hello!

Finally, I was challenged to write decent code to handle a password update/reset and had a free evening yesterday to do just that!

Before:

Manually update the password in the SQL dabatase and store it un-encrypted.
This will make the Forum account out of sync.
Ask the user to log in with the temporary password and update it again to re-synchronize Account + Forum.

Problem: almost nobody sets a new password to resync the account, leaving the password in clear in the database and generating logon errors on the Forum.

After:

One click, popup for a new value from the Admin interface.
Password encrypted directly.
Password + Forum account is re-sync'ed.
No need to ask the user to update the password again.
Notification Email automatically sent.

Planned:

Re-use this code to let users request a password reset with email confirmation.

Julien


Julien,

most of the time I have no idea what the tech updates mean (pretty hopeless PC/computer wise) but can I just say thanks for the site & thanks for all your time & work to keep it going the way it does.

I for one genuinely appreciate what you do for us all here.

Again..... THANK-YOU
Offline
 Profile  
 
Display posts from previous:  Sort by  
 Page 1 of 1 [ 2 posts ] 


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to: