You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
postfixadmin/model
Sylvain Tissot ffb84283c2
Harden password reset process
The improvements are:

- Die with an explicit message when a user is trying to reset his lost password and the option is disabled in config
- Redirect user to main page after password change using relative URL
- Don't leak info whether user exists or has recovery info defined
- Throttle password reset requests to prevent brute force attacks
- Show phone/alt email fields in mailbox/admin edit form only when the password reset option is enabled
- Make database upgrade code compatible with other databases types
- Use the existing password generator to generate OTP. It is now stored in database, unique to each user, valid only for 1 hour and can only by used once.
7 years ago
..
AdminHandler.php Harden password reset process 7 years ago
AdminpasswordHandler.php *Handler: 10 years ago
AliasHandler.php Fix wrong way of check for can_delete 8 years ago
AliasdomainHandler.php AliasdomainHandler: 10 years ago
CliDelete.php Cli*.php: 10 years ago
CliEdit.php Cli*.php: 10 years ago
CliHelp.php Cli*.php: 10 years ago
CliScheme.php Add CliScheme.php: 10 years ago
CliView.php Cli*.php: 10 years ago
Config.php Config.php: 11 years ago
DomainHandler.php Better use Config::Lang instead of global $PALANG 8 years ago
FetchmailHandler.php FetchmailHandler: use a valid date as default for 'date' 8 years ago
MailboxHandler.php Harden password reset process 7 years ago
PFAHandler.php Harden password reset process 7 years ago
VacationHandler.php Make VacationHandler compatible with MySQL strict mode again 8 years ago