MyBB Community Forums

Full Version: Password Resets?
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3 4 5 6 7 8
We have a large MyBB forum (thousand users)and i often receive such complains from users. the reset code doesn't work.. There is a bug somewhere to be found.

Cheers
I was hoping the latest update would fix this. Apparently it didn't. Sad
The next update won't fix it either, so long as no one provides steps to reproduce the issue.
(2013-01-06, 01:58 PM)frostschutz Wrote: [ -> ]The next update won't fix it either, so long as no one provides steps to reproduce the issue.

This exactly.

Nobody has yet managed to pin down an exact cause for the issue. We focus our attention on bugs that we know the cause of.
FWIW, I got a similar report from a member. I asked what exactly he did.

Quote:Forgot password, attempted several logins, passed the limit I guess and got "You have failed to login within the required number of attempts. You must now wait 0h 15m 0s before you can login again." Password reset not received but doesn't make a difference*

That was a few days ago but the 15 minutes has never expired.

*I went to admin panel and changed his password there, the new password still gives the same message.

I am not sure I want to attempt to reproduce it (ok, may be I can using a test account) because I will get myself or someone else locked out.
I've also had this issue for a long time- haven't been able to figure out what the issue is. I thought it might have something to do with having friendly redirection disabled but I'm still investigating. Hopefully someone will find the bug and the issue can be corrected. For the last 14 months, I've had to manually fix passwords for users who have forgotten them.
Dozens of users complaining about one of the most important features of any website. A bug exists and I think we need to see progress toward a fix.

I started a file to save all the complaints I get. Here is an excerpt.

Quote:I recently changed my password of my FORUM account, but then I forgot it. So, I pressed reset my password and then I got a mail from FORUM that said that I would get a new password in another mail. I opened the second mail and logged in to my account, but then when I logged in, I got a message, which said that I didn't login with the right information ( which is impossible ) and that I have to wait for 15 minutes to try again. I've tried a couple of times, but this problem doesn't get solved..


Quote:Message:i cant log in to my account my user name is {deleted} and i made a new password with the i forgot my password and i got the email and i can log in im not able to!

Ya know at first I thought users were idiots. Took me a while to really see a clear pattern that the feature has a bug somewhere.

It appears that users are thrown the 15 minute message then get account locked out. I wonder if there is a logic error for the error message and the time wait. Also I wonder if there is a possible issue with time zones. Example is a user might have a cookie for one time zone but the code logic doesn't take that into account. Just not sure really where the problem lies.

I beg MyBB to do more to look into this matter.
Isn't this something that would fall under SQA? Just wondering. xD
And this bug has been around since about MyBB 1.6.4 which was a big maintenance release.
Definitely need to get this looked into. Anybody know if it's logged on redmine as a bug? If not, it should be. I'll have a look at how password resets are handled tomorrow if I get time to do so.
Pages: 1 2 3 4 5 6 7 8