Email notification to old address when verified email address is changed or removed
Closed, ResolvedPublic

Description

If a verified email address is changed or removed, an email notification should be sent to the old address. The email is for informational purposes only, it should not contain any verification codes. The main purpose of this is a reasonable defense against account cracking.

Discussion on en.wp: [[Wikipedia:Village pump (proposals)/Account security#Notify of removal of verified email address]]


Version: unspecified
Severity: enhancement

Details

Blocked By
T34281: MediaWiki needs a sane notification system (tracking)
Security
None
Reference
bz29856
bzimport added a subscriber: Unknown Object (MLST).
bzimport set Reference to bz29856.
MER-C created this task.Jul 13 2011, 3:34 AM
werdna removed a subscriber: werdna.Dec 10 2014, 6:16 PM
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptJan 14 2016, 3:24 PM
Devirk claimed this task.Jan 14 2016, 5:53 PM
Devirk set Security to None.
Haritha28 removed a subscriber: Haritha28.
Devirk removed Devirk as the assignee of this task.Mar 10 2016, 6:09 AM
Devirk added a subscriber: Devirk.

Change 276563 had a related patch set uploaded (by Galorefitz):
User.php: Update 'setEmailWithConfirmation' for notification email

https://gerrit.wikimedia.org/r/276563

@01tonythomas and @Parent5446 could you please review the submitted patch?

Change 276563 merged by jenkins-bot:
User.php: Update 'setEmailWithConfirmation' for notification email

https://gerrit.wikimedia.org/r/276563

Parent5446 closed this task as "Resolved".Sun, Apr 10, 5:32 AM

Add Comment