Email address change confirmation sent to wrong address?

Email address change confirmation sent to wrong address?

by Dale Davies -
Number of replies: 2

I just changed my email address on moodle.org and it sent a confirmation email to the NEW email address.  As a security precaution, should this be sent to the old email address instead with a message like "someone is trying to change the email address at moodle.org, click below to confirm this was you"?

Average of ratings: -
In reply to Dale Davies

Re: Email address change confirmation sent to wrong address?

by Richard Oelmann -
Picture of Core developers Picture of Plugin developers Picture of Testers

May need to be sent to both - some people may be changing their email address because they no longer have access to the old one smile

In reply to Richard Oelmann

Re: Email address change confirmation sent to wrong address?

by Dale Davies -

Yes of course, should it follow this pattern then...

  • Send an e-mail to the new address with a confirmation link.
  • Send an e-mail to the old e-mail address with the option to revoke the change.
This way we can verify the new email address is correct but also alert the old email address in case the account has become compromised.
Average of ratings: Useful (1)