[kwlug-disc] Kanboard plugin shopping list.

Paul Nijjar paul_nijjar at yahoo.ca
Sun Jan 8 17:50:23 EST 2017


Does the software allow "forgot my password" links that send an email?
If so then here is a workflow that I have used: 

- Create the account with some password generated by random.org and a
  valid email address for the user.
- Go to the login page and click "Forgot my password". If the software
  is reasonable that will send an email to the user with a
  time-expired link so they can log in and change their password
  manually.

If there is no such "forgot my password" functionality then that is a
bad thing and I do not have a clear answer.

- Paul 

n Sun, Jan 08, 2017 at 02:45:45PM +0000, Chamunks wrote:
> 
> When it comes to user registration how do we want to handle sending
> credentials because I don't believe this app handles security as smartly as
> I'd like. Like forcing password changes.

> 
> On Fri, Jan 6, 2017, 6:38 PM Paul Nijjar via kwlug-disc <
> kwlug-disc at kwlug.org> wrote:
> 
> >
> > I recommend against allowing self-registration, unless you think
> > spammers will be polite enough to refrain from flooding your site.
> > It is probably better for you to create accounts on demand?
> >
> > Everybody likes to enable all the toys with new installations.
> > Experience has taught me to keep things minimal and add features as
> > they show themselves to become necessary.
> >
> > - Paul





More information about the kwlug-disc mailing list