KamoCRM

A work address on forgot-password asks for the account's own, shown masked

FeatureSecurityService
ส่งแล้ว
23 กันยายน 2569 เวลา 22:13 UTC
ผู้เขียน
Kamo
ตั้งค่า
d7ff5ed

Members open their account with a personal address (gmail, yahoo) and are later given a work address by their organization, which is the one they remember and type on forgot-password. That only ever resolved on their own org's login host, and then the letter went to the work inbox. For 20 of KamoCRM's members that is a KamoMail mailbox, which is read inside the product they have just been locked out of. On any other host the address matched nobody, and the page said "if this email is registered, a link has been sent" having sent nothing. /api/recover/email/initiate now answers the account e-mail exactly as before. For any other address it looks for a member work address: first in the org whose login page this is (Primary mailbox, then members.email), then in any live org. When that names an account with an address of its own, nothing is sent. The answer is a 409 with reason WORK_EMAIL and personalEmailHint, the account address with every character of the name between the first and the last starred, and the domain in full. It is a 409 on purpose: a login page that predates the hint shows `message` for a non-2xx, and `message` says the same thing in words. An account with no address of its own still gets the letter at the work inbox on its org's host, since that is the only inbox on record. The hint says an address belongs to somebody, which the generic answer never did, so each one is counted by CodeAttemptLimiter: five an hour per address typed, plus the caller's address limit shared with the code checks. Past that the request gets a 429.

เปลี่ยนแปลงทั้งหมด

เหมือนที่คุณเห็นการขนส่ง?

ทั้งหมดของมันมาถึง ในที่ทํางานของคุณเอง เริ่มที่แผนฟรี และอ่านหน้านี้อีกครั้งในเดือน.

เริ่ม เป็น อิสระ ตลอด ไปแสดงพริ้นซ์