NewRedo/express-user-accounts

Changing email address to one that is already in use makes one account unavailable

Closed this issue · 1 comments

pluby commented

If you have two accounts with emails a@b.com and b@b.com, then change and confirm the email on the first account to b@b.com. Now one of these accounts can no longer log in.

Suggested solution is that the email address change doesn't work, but triggers the account recovery procedure for the new email. Custom messaging may be needed in the recovery email.

pluby commented

Resolved with pull request #6.