Hi Ory, I have a question about Kratos. When a use...
# ory-selfhosting
b
Hi Ory, I have a question about Kratos. When a user attempts to send a recovery code to an email address, the system does not verify if the email exists in the database. Instead, it returns a hint message rather than an error message, which is quite confusing. Has this been updated in the newer version, or are there any plans to change it? Thank you!
w
I think this is to avoid information exposure about who has accounts
b
That's reasonable, but maybe it can be added to config.