When an external user wants to reset his password on the login page of Filr, he can send the password reset notification as may times as he wants, he just needs to enter his email address again and hit the OK-Button. Also it is possible to enter as many email addresses as you want and Filr will tell if the account exists or not.

In my opinion, the password reset function should be protected by a captcha.
This would increase security and would prevent a possible brute force attack or spam flood.

Comments

  • good idea, noted Adrian!