hrfee/jfa-go

limit reset password identifiers

Closed this issue · 7 comments

please make it possible to set it so you have to enter an email and cant enter usernames etc
im sick of being spammed with password reset requests by bots

hrfee commented

Settings to enable/disable each way of initiating a PWR have been added to the userpage settings.

could you run a build pls

an option to disable password resets for the jellyfin website but still have them for the user login page would also be awesome !

since currently you can still spam users just by knowing their username

hrfee commented

You can do this by just setting the password reset directory to something wrong.

You can do this by just setting the password reset directory to something wrong.

would this stop emails etc too?

hrfee commented

Not quite sure what you mean, all this would do is make the "forgot password" page on Jellyfin from working.

sounds good tysm