From: Yann GUERN Date: Tue, 11 Apr 2017 12:21:15 +0000 (+0200) Subject: Avoid user enumeration with devise paranoid mode (#1527) X-Git-Url: https://git.xn--scling-oua.cat.family/?a=commitdiff_plain;h=a85d4473aa2a6a619fcee851c642dca576e622f6;p=mastodon.git Avoid user enumeration with devise paranoid mode (#1527) --- diff --git a/config/initializers/devise.rb b/config/initializers/devise.rb index ede6640bb..3c23e7b2e 100644 --- a/config/initializers/devise.rb +++ b/config/initializers/devise.rb @@ -74,7 +74,8 @@ Devise.setup do |config| # It will change confirmation, password recovery and other workflows # to behave the same regardless if the e-mail provided was right or wrong. # Does not affect registerable. - # config.paranoid = true + # See : https://github.com/plataformatec/devise/wiki/How-To:-Using-paranoid-mode,-avoid-user-enumeration-on-registerable + config.paranoid = true # By default Devise will store the user in session. You can skip storage for # particular strategies by setting this option.