verify change of email address

Issue #367 resolved
Reimar Bauer
created an issue

We should only allow to change the email address by verifying the new address.

Can be done similiar to the recovery token for setting a new password.

  1. Thomas Waldmann repo owner

    yeah. in fact that should also include other value changes for email, even from <non-existing> to <defined> when the profile is created.

    I recently had to manually fix an email address with a typo. The user had seen pw recovery not working for him, but obviously didn't notice the typo before.

  2. Thomas Waldmann repo owner

    maybe the mail_verification setting should be removed.

    IF we have a working mail setup, we can always verify the email addrs. IF NOT, we can not... (make sure it behaves resonably for this case).

