By Philippe on Monday, 11 June 2018
Posted in Technical Issues
Replies 7
Likes 0
Views 500
Votes 0
Hello,

I observed that when the function "Use Email as Username" is activated.
And that a user changes his email from edit profile page, his username is not updated. While it must be the same as his email address.

Thank you,
Philippe
If you have originally rolled out the site initially with that option turned off, the usernames would not change to an e-mail automatically if you decide to turn it on later. However, the user would still be able to login to the site with username or e-mail.

The reason that the system does not automatically change their username, is primarily because not everyone is aware that they are required to use their e-mail. If you decide to just switch it on, they will not be able to login with their existing username.
·
Monday, 11 June 2018 21:11
·
0 Likes
·
0 Votes
·
0 Comments
·
Yes I see.

But if the option is activated from the start, it means that the user can connect with the email address given at registration and also with the new email address.
Does not this create a security breach ? If his address is in the meantime ceded to someone else ?

Thank you Mark
Philippe
·
Monday, 11 June 2018 22:27
·
0 Likes
·
0 Votes
·
0 Comments
·
Not sure where you are going with this but if you edit your profile and enter a new e-mail, your username would then be the e-mail address that you have changed to.
·
Monday, 11 June 2018 22:51
·
0 Likes
·
0 Votes
·
0 Comments
·
Yes it's correct.
But the user (or someone else) will be able to connect with the original Joomla username (original email address)...

In my humble opinion, if "Use Email as Username" is activated: this Joomla username should also be updated. That would make sense.
To avoid problems in the long term.
And avoid identity theft.


Imagine if the email address is attached to a personal domain name.
myenterprise.com for example.
And later, the domain myenterprise.com is abandoned.
A person will be able to bought the domain, and then simply reset the password for the account EasySocial.

In addition, I do not think it is honest to keep his original email address, while the user has decided to change it.
I opened this post in connection with the GDPR.

Thank you Mark
Philippe
·
Monday, 11 June 2018 23:28
·
0 Likes
·
0 Votes
·
0 Comments
·
I see, I get your point now. I have logged this into our issue tracker.
·
Monday, 11 June 2018 23:36
·
0 Likes
·
0 Votes
·
0 Comments
·
Thank you very much Mark for your understanding.
It is better to anticipate.

Philippe
·
Monday, 11 June 2018 23:44
·
0 Likes
·
0 Votes
·
0 Comments
·
No problem
·
Monday, 11 June 2018 23:59
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post