Hmm, I don't think I've seen a site that doesn't let you modify your email address. What if the user makes an error when registering or subsequently changes their email address -- they then have to abandon their account and sign up for a new one?
On Thursday, June 6, 2013 3:24:44 AM UTC-4, Lio wrote: > > Hello guys, > > In my app I use email as login user name, but I found in > app/default/user/profile the email can be modified. This seems to be a risk > either the user may lose his account by accidentally change email or hacked > by others in some way. The solution I can think of is customize the profile > page and hide email field. Is there better practice which show the email > but forbid modifying it like the id field of most tables. > > regards, > Lio > -- --- You received this message because you are subscribed to the Google Groups "web2py-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to web2py+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/groups/opt_out.