MyBB Community Forums

Full Version: Password reset
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Hello,

I recently started using MyBB forums and they are fantastic. I converted a Vanilla 2 forum to MyBB and with a couple of tweaks here and there it is perfect.

A piece of feedback which I find is the worst feature I have encountered on MyBB forums thus far:

Users have been having a hell of a time resetting their password. The process on MyBB forums is long winded and confusing.

  1. The user chooses to reset their password.
  2. The user receives an email with a code to reset their password.
  3. The user uses the link to reset the password, which sends a new password to their email.

The problem lies between 2 and 3, and the back and forth switching from forum-to-email. Users do not really tend to read what is in the emails since they're auto generated emails they feel they've read 1000 times before. My users have been clicking the first activation link and trying to log in with the "code" received in step 2, getting locked out of the forums and then sending me an email complaining they can't log in.

My suggestion: what would be much more ideal is if the user could choose their password once they've clicked the link in step 2. They've proved they have access to the original email account by that point, so the extra step of sending a newly generated password at that point, I feel, is redundant.

Thanks for your consideration
Jack
Quote:The problem lies between 2 and 3, and the back and forth switching from forum-to-email. Users do not really tend to read what is in the emails since they're auto generated emails they feel they've read 1000 times before. My users have been clicking the first activation link and trying to log in with the "code" received in step 2, getting locked out of the forums and then sending me an email complaining they can't log in.

You can't fix people not reading.

What I would like to see though is having it store the IP of the user who initiated the password request and then compare that to the user who is visiting the link to make it more secure. This would force a user to know the email address of the person whose account they would like to access.
dragonexpert Wrote:You can't fix people not reading.
This is true, and is exactly why I made the suggestion.