Two questions regarding passwords in OSSN

Dominik L Posted in General Discussion 11 months ago

When a user wants to change his password on the profile page, he can just enter the new one and save it, and it is changed

Wouldn't it make more sense to make the user enter the old password and then enter the new one? Maybe also for security reasons?

Also for registration:

Wouldn't it make more sense to double check the password? so "password" and "confirm password"?

Replies
vn Badeva badeva Replied 3 months ago

It's definitely a good point to consider adding an extra layer of security by requiring the user to enter their old password before setting a new one. This is a common practice in many platforms to prevent unauthorized password changes.

https://www.opensource-socialnetwork.org/component/view/5195/password-change-security iq test

vn Ethnic joystick Replied 10 months ago

@Arsalan Shah I cannot access your link. What's the problem with it? https://www.opensource-socialnetwork.org/component/view/5195/password-change-securityeggy car

German Dominik L Replied 11 months ago

Thanks!

And for login page?