Shocked to see password

  • Mark
  • Topic Author
  • Offline
  • Premium Member
  • Premium Member
More
9 years 1 month ago #60994 by Mark
Shocked to see password was created by Mark
Great to see 1.7.1 . Must remember to install it! :P Does it fix the "state id not name" bug in email to subscriber and admin?

However, having just received an email about a new membership, I was shocked o see it contains the user's website password! It's great that I've now got the registration page up on the membership signup page, but...

Hmm, I suppose now you'll tell me that it's just one email, sent to the user and cc'ed to admin... ?
That's really bad, admin getting the password.

Please Log in or Create an account to join the conversation.

  • Tuan Pham Ngoc
  • Away
  • Administrator
  • Administrator
More
9 years 1 month ago #61007 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Shocked to see password
Hi Mark

I don't think there is any problem if admin knows user password. Admin can easily reset user password if he wants and I don't see any other Membership Pro customers complain about it

If you don't want password to be available in admin email, please submit a support ticket so that I can edit code to remove it for you !

Tuan

Please Log in or Create an account to join the conversation.

More
9 years 1 week ago #62200 by Shane French
Replied by Shane French on topic Shocked to see password
Agree. Admins should not be sent password (they shouldn't be visible as plain text anywhere), even to admins. Allow admin to reset to something new of course, but they shouldn't see a user's pw. Many people use the same password for lots of sites - I don't want a repository of their passwords clogging up my email box.

Please Log in or Create an account to join the conversation.