User tests: Successful: Unsuccessful:
This PR removes the authentication code {CODE} from the email subject line.
What problem am I trying to solve?
The email subject line is significantly less protected than the content:
It's often displayed in plain text, for example, on smartphone lock screens, in email notifications, or previews.
This makes it much easier for others to see the subject line without opening the email (shared inbox, office, support).
Forwarding and auto-replies also pose a problem; some systems only use the subject line and reply with it again, unintentionally including the code in other emails.
Activate the MFA plugin "Multi-factor Authentication - Authentication Code by Email" and configure it for a user.
Use this login method for the user. An email will arrive in the inbox.
Subject e.g.: "Your 610-alpha2 authentication code is -123456-"
Subject e.g.: "Your 610-alpha2 authentication code"
And the code is now only contained in the email body.
Please select:
Documentation link for docs.joomla.org:
No documentation changes for docs.joomla.org needed
Pull Request link for manual.joomla.org:
No documentation changes for manual.joomla.org needed
| Status | New | ⇒ | Pending |
| Category | ⇒ | Administration Language & Strings |
| Labels |
Added:
Language Change
PR-6.1-dev
|
||
| Category | Administration Language & Strings | ⇒ | Administration Language & Strings JavaScript Unit Tests |
| Status | Pending | ⇒ | Closed |
| Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2026-01-07 13:42:28 |
| Closed_By | ⇒ | tecpromotion | |
| Labels |
Added:
Unit/System Tests
|
||
Having the code in the subject allows to read the code without opening email. That actually is very useful on mobile.
I would suggest:
authenticationtoauthto make it shorter :)123456 is your FoobarSiteName authentication code