Users can change their email from profile settings. They will be logged out immediately. Users can log in again with the updated email without verifying the same. This is a security problem. So this change enforce the user to reconfirm the email after changing it. Users can log in with the updated email only after the confirmation. Fixes: https://huntr.dev/bounties/7afd04b4-232e-4907-8a3c-acf8bd4b5b22/ |
||
|---|---|---|
| .. | ||
| android_app | ||
| api | ||
| apple_app | ||
| dashboard | ||
| devise | ||
| fields | ||
| installation/onboarding | ||
| layouts | ||
| mailers | ||
| platform/api/v1 | ||
| public/api/v1 | ||
| super_admin | ||
| survey/responses | ||
| widget_tests | ||
| widgets | ||