Include Users IP Address When Sending Discord Notification for Forgot Password Usage #7
Labels
No labels
automated
code-quality
component: admin dashboard
component: backend
component: billing
component: content management
component: faqs
component: game genres
component: game lists
component: game reviews
component: game search
component: games
component: internal notifications
component: platforms
component: security
component: tests
component: user api
component: user badges
component: user blogs
component: user consoles
component: user favorites
component: user friends
component: user notifications
component: user profiles
component: user site notifications
component: user wishlists
component: web design
dependencies
php
priority
high
priority
low
priority
medium
security-hotspot
source: codex
source: sonarqube
status
awaiting feedback
status
backlog
status
done
status
in progress
status
in queue
status
in review
status
needs codex review
status
needs investigation
status
wontfix
type: bug
type: documentation
type: feature
type: improvement
type: regression
type: task
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
MyVideoGameList/myvideogamelist.com#7
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
When Discord sends a notification when someone submits the forgot password form, we should also include the IP from which the form was submitted from.
Closing this out as intentionally not planned. After reviewing the current forgot-password flow, this does not look worth implementing as-is: reset links are already protected by the account-based 24-hour broker throttle, unknown usernames keep the same generic response, and adding only the requester IP to Discord would be noisy without giving us much actionable security signal. If we revisit this later, I would rather frame it as structured audit/security events for forgot-password attempts, with enough context to be useful, instead of a Discord-only IP field.