Prefill the recovery email from the login identifier on "Forgot password?"
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 72/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- react, typescript
- Ambito
- authentication, frontend
Direzione di ricerca
Start with packages/elements-react/src/theme/default/components/form/label.tsx and packages/elements-react/src/components/form/form-helpers.ts, as linked in the issue. Trace how the hidden identifier node is used on the password step and how recovery fields are prefilled; check that only email identifiers are passed as login_hint. Done when recovery prefills the appropriate email field, including recovery_address when enabled, without passing usernames or phone numbers.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
No response
Describe your problem
In the two-step login form, the user enters their email, clicks continue, and lands on the password step. If they then click "Forgot password?", Elements opens a new recovery flow without the email, so the user has to type it again.
Requested by an Ory Network customer.
Describe your ideal solution
LabelActionaddslogin_hint=<identifier>to the "Forgot password?" link. On the password step the identifier is in the hiddenidentifiernode.- The
login_hintprefill inform-helpers.tsalso covers recovery flows. TodayprefillIdentifierFieldsonly listsidentifierandtraits.email. Recovery usesemail, orrecovery_addresswhen the choose-recovery-address feature is on.
Only pass the hint when the identifier is an email address, since the login identifier can also be a username or phone number.
Workarounds or alternatives
Users can build this today:
- Override
components.Node.Labelto addlogin_hintto the link. This means taking over label rendering for the whole form. - On the recovery page, read
login_hintfromflow.request_urland set theemail/recovery_addressnode value before passing the flow to<Recovery>.
This puts the email in the URL, so it ends up in browser history and request logs. Passing it through sessionStorage avoids that, since login and recovery are on the same origin. The built-in version could be opt-in for the same reason.
Version
@ory/elements-react 1.2.1 and 1.3.0-rc.0
Additional Context
No Kratos change is needed. Kratos keeps extra query params on the recovery init URL: /self-service/recovery/[email protected] comes back unchanged in the flow's request_url.
- Lingua principale
- TypeScript
- Stelle
- 187
- Fork
- 79
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ory/elements
-
Needs Triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
good first issue help wanted upstream
Difficoltà 2/5 1-3 ore Idoneità per principianti 45/100
-
good first issue help wanted upstream
Difficoltà 3/5 1-2 giorni Idoneità per principianti 25/100
-
Add React-only examplesApertaNeeds Triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 52/100
-
guessPotentiallyProxiedOrySdkUrl breaks flows in production behind a non-Vercel reverse proxyApertabug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
Tutte le issue di ory/elements
Issue simili
-
Table: Space fires onActivate in single-selection mode — the reference doc and the JSDoc disagreeAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
sidorares/react-x11-components#764 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
backnotprop/plannotator#1840 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
JoviDeCroock/pracht#432 ·
I maintainer di solito rispondono entro 1 giorno
-
Add: CNN en Espanol SDApertaapproved check:passed streams:add
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
Hardware attribute name "app Connection Support" has inconsistent casingForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
walletbeat/walletbeat#1628 ·
I maintainer di solito rispondono entro 1 giorno