xeerex wrote:
Why can't someone just click the "forgotten password" link?
|
hi xeerex, i never said nobody can click on, i was thinking about recovering the password, not reseting and getting a new one, by clicking one the "forgotten password" link, sorry if i didn't explain clearly. 
Of course user can change the new password by the former (but in this case, why not allowing it from start, by sending back the real password ?).
But it's a waste of time (a little one i admit, but still one
) and it will leads to complications : topics of users who aren't aware they can change the new one, problems with stoic user who tries to remember the new password (and not a really esay one, as C2D33FE1 ... and don't forget this user already forget its own password ... i'm not so sure he will remember this one better
), etc.
And finally as said ljamal, it could be a way to harass someone by reseting its password frequently.
So i ask again my question more clearly now : is it a way to send back the user password if he clicks on the forgotten password link, instead of reseting and sending a new one ?
i hope i'm not boring with this question 
Edgard