Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2FA and password reset emails are still sent to user's old email address even after primary email address is updated #16761

Open
Thespi-Brain opened this issue Sep 19, 2024 · 0 comments
Labels
bug 🐛 requires triaging maintainers need to do initial inspection of issue

Comments

@Thespi-Brain
Copy link

Describe the bug
After the account recovery process is completed through the "Start Account Recovery" tool, even after the primary email address is updated, both users and user logs indicate receiving the 2FA and password reset emails in their old email addresses. Note: subsequent emails do get sent to the newly updated primary email address, it seems that emails being sent to the old email address occurs right during the recovery process.

Expected behavior
The 2FA/password reset emails should go to users' newly updated primary email addresses, not their previous email addresses.

To Reproduce

  • Use "Start Account Recovery" process with an alternate email/new primary email for user
  • Upon completion of the process, 2FA/recovery codes/password should be reset and the primary email checkbox will show the updated email address
  • But logs will indicate the notification sent to the old email address even if the checkbox for this email under "Primary" will be unchecked

Additional context
Related to this issue and this issue.

@Thespi-Brain Thespi-Brain added requires triaging maintainers need to do initial inspection of issue bug 🐛 labels Sep 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug 🐛 requires triaging maintainers need to do initial inspection of issue
Projects
None yet
Development

No branches or pull requests

1 participant