This issue has become a feature request for a new setting to be added that allows enabling better privacy on login/password reset forms. This will mean those who prefer usernames/email addresses not be revealed can enable that setting, and those who prefer the better UX of knowing what incorrect information was submitted to these forms can leave it disabled.
If I enter my username in the Reset Password form (/user/password) and submit, I see this message:
Further instructions have been sent to your e-mail address.
If I enter a made-up username in the same form and submit, I get this:
Sorry, [made-up username] is not recognized as a user name or an e-mail address.
This basically tells people whether or not a given username or email address is in-use on the site. I see this as a (low) security issue and possible privacy issue.
I recommend instead giving something like the following message (like I've seen on other sites) whether a valid or invalid username/email address was entered:
If a matching account was found, further instructions have been sent to that account's e-mail address.
Recent comments
Funnily we launched a new Dutch website this very week, milieucafe.nl It is not a 'news' website but operates in the context of local government. The layout focuses on content instead of...
Looking for examples of (local) news websites running on BackdropCMS
The answer is off topic, but I'll add a little. 1. Backend. Why you don't need links to other websites: Since you know the structure of your site and content, you can decide for...
Looking for examples of (local) news websites running on BackdropCMS
Hi Chrys, AI isn't always your best friend. A form alter hook is correct, but hiding by CSS isn't ideal. You could look at how the TinyMCE integration does it, which provides hiding...
CKEditor5: Here's how to prevent "Select Image from Library" from appearing