The cookie exchange doesn't bring the password all the way back, starting from _bakery_register_submit().

Name and mail are stashed in $_SESSION for the slave to potentially refer to later. The easiest solution would involve this, but we might not want plain text passwords laying around $_SESSION. Otherwise, it would have to be carried through the two key exchanges.

Or, we could not send the password in email and rely on the login URL. I like this since passwords in email are not great. We could change the email content on enable/update if it is the default, or alert the user if it contains !password.

Comments

greggles’s picture

Or, we could not send the password in email and rely on the login URL. I like this since passwords in email are not great. We could change the email content on enable/update if it is the default, or alert the user if it contains !password.

Yes, please. I think that's a reasonable requirement that if someone wants to use bakery they can't have passwords in their welcome emails.

coltrane’s picture

Yeah, I meant to document this as a known issue. I think the best answer is to remove the token from the email.

drumm’s picture

Here is a draft of the new text:

!username,

Thank you for registering at !site. You may log in by clicking on this link or copying and pasting it in your browser:

!login_url

This is a one-time login, so it can be used only once.

After logging in, you will be redirected to !edit_uri so you can change your password.

-- !site team

greggles’s picture

Text looks great to me. That's how I rewrite it on every site where I remember to do it.

coltrane’s picture

What's the fix here? Document in README/handbooks?

greggles’s picture

Component: Code » Documentation

Yes.

purencool’s picture

Issue summary: View changes
Status: Active » Closed (outdated)