Users can change their email from profile settings. They will be logged out immediately. Users can log in again with the updated email without verifying the same. This is a security problem. So this change enforce the user to reconfirm the email after changing it. Users can log in with the updated email only after the confirmation. Fixes: https://huntr.dev/bounties/7afd04b4-232e-4907-8a3c-acf8bd4b5b22/ |
||
|---|---|---|
| .. | ||
| administrator_notifications | ||
| agent_notifications | ||
| .keep | ||
| confirmation_instructions_spec.rb | ||
| conversation_reply_mailer_spec.rb | ||