"Lost Username" even when login via email is allowed?

7 years 3 months ago - 7 years 3 months ago #290634 by carin
Why is in view=lostpassword at "Reminder needed for" the "Lost Username" displayed when the site allows login via username AND email? Does not make sense to me. What am I missing? It should automatically be disabled via the CB setting. Where can I disable that?

And what if I forgot my password and my username (which is the most common use case)? Why cant the user just get an email with the reset link? Why does the user have to know the username to get a reset link? It should be OR not AND. Please dont say the user has to first recover the username to get the reset link in a second round of emails ... what a UX that would be ...

CB 2.0

Please Log in to join the conversation.

7 years 3 months ago - 7 years 3 months ago #290649 by krileon
If you select both Lost Username and Lost Password you only need to supply your email address. If you select Lost Username you need to supply only your email address. If you select Lost Password you need to supply your Username and Email Address. If you don't know both then select both; why would you do them one at a time? If you don't want Lost Username functionality or needing to supply Username for Lost Password then you need to turn off login via username entirely.

Additionally we already have a feature ticket to rewrite forgot login usage. You can find it below.

forge.joomlapolis.com/issues/5680


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

7 years 3 months ago #290681 by carin
hmm, then I have a different 2.1.2 then you. My CB says "If you forgot both your username and your password, please recover the username first, then the password..." to me that is two steps, with one being unnecessary since I know the email, hence unpleasent UX.

" If you don't want Lost Username functionality or needing to supply Username for Lost Password then you need to turn off login via username entirely."
==> Why is that a causality?

The ticket gets delayed and pushed to the next version for over a year now. I think for a reasonable UX it needs to be addressed soon. Please consider solving it in a 2.1 version, thanks.

CB 2.0

Please Log in to join the conversation.

7 years 3 months ago #290696 by krileon

hmm, then I have a different 2.1.2 then you. My CB says "If you forgot both your username and your password, please recover the username first, then the password..." to me that is two steps, with one being unnecessary since I know the email, hence unpleasent UX.

The language string needs to be updated to reflect the current behavior. Have added a bug ticket for this.

forge.joomlapolis.com/issues/6471

In the meantime you can change the language string as needed by using the override functionality below.

www.joomlapolis.com/blog/kyle/18712-language-key-and-text-finder

" If you don't want Lost Username functionality or needing to supply Username for Lost Password then you need to turn off login via username entirely."
==> Why is that a causality?

Because if you require username for login they need a way to recover it. If you don't want them to recover it then don't require it for login.

The ticket gets delayed and pushed to the next version for over a year now. I think for a reasonable UX it needs to be addressed soon. Please consider solving it in a 2.1 version, thanks.

It's not just a UX change. We're not making some minor HTML adjustments. We'll be rewriting the entire forgot login process to meet modern standards of never sending passwords in emails. They'll be sent a recovery URL, which they'll navigate to and supply a new password at which point that recovery URL has to expire. This is an entirely new recovery process we have to implement. It will not be in a bug fix release so no it won't be in 2.1, but in 2.2 at the earliest and that is probably unlikely depending on current active projects.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.
The following user(s) said Thank You: carin

Please Log in to join the conversation.

7 years 3 months ago #290721 by carin
Ok thanks, that was the lang string but the user still has to do two email loops to recover the password since in most cases username AND password are forgotten and only the email is known. Anyway, to restrict login to email only is the way to go for now to have a straight forward UX.

"to meet modern standards of never sending passwords in emails"
==> that is really needed, I hope it makes its way into 2.2

CB 2.0

Please Log in to join the conversation.

7 years 3 months ago #290733 by krileon

Ok thanks, that was the lang string but the user still has to do two email loops to recover the password since in most cases username AND password are forgotten and only the email is known. Anyway, to restrict login to email only is the way to go for now to have a straight forward UX.

They do not have to recover them individually. All they have to do is select the forgot username and forgot password checkmarks. Select both of them. It then only asks for email address.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 1.503 seconds

Facebook Twitter LinkedIn