What behaviour is observed?
When a player uses /email recover and the plugin is configured to generate a new password (no recovery codes), the password in the database is changed to a new randomly generated password before the recovery email is actually sent. If the email fails to deliver (SMTP misconfiguration, mail server down, rate limit, etc.), the player's original password has already been overwritten in the database. The player receives the message "We were unable to send the email. Please contact an administrator." but their old password no longer works. They are permanently locked out of their account with no way to recover unless an admin manually intervenes.
Expected behaviour
The password in the database should only be updated after the recovery email has been successfully sent. If the email fails, the player's original password should remain intact so they can still log in normally. Alternatively, the old password hash should be stored and restored on email failure.
To Reproduce
Set up AuthMe with Security.emailRecovery.recoveryCodeLength: 0 (disables recovery codes, uses direct password generation)
Configure an intentionally broken SMTP server (e.g. wrong port, bad credentials, or unreachable host)
Register an account and set an email via /email add test@example.com test@example.com
Log out and attempt /email recover test@example.com
Observe the error message "We were unable to send the email."
Attempt to log in with your original password -- it no longer works
The account is now permanently locked out
Plugin list
horrible mod..
Server Implementation
Standalone server (no proxy)
Database Implementation
SQLite
AuthMe Version
6.0.2-SNAPSHOT (latest master)
Error log (if applicable)
[AuthMe] Generating new password for 'PlayerName'
Configuration
BNA
What behaviour is observed?
When a player uses /email recover and the plugin is configured to generate a new password (no recovery codes), the password in the database is changed to a new randomly generated password before the recovery email is actually sent. If the email fails to deliver (SMTP misconfiguration, mail server down, rate limit, etc.), the player's original password has already been overwritten in the database. The player receives the message "We were unable to send the email. Please contact an administrator." but their old password no longer works. They are permanently locked out of their account with no way to recover unless an admin manually intervenes.
Expected behaviour
The password in the database should only be updated after the recovery email has been successfully sent. If the email fails, the player's original password should remain intact so they can still log in normally. Alternatively, the old password hash should be stored and restored on email failure.
To Reproduce
Set up AuthMe with Security.emailRecovery.recoveryCodeLength: 0 (disables recovery codes, uses direct password generation)
Configure an intentionally broken SMTP server (e.g. wrong port, bad credentials, or unreachable host)
Register an account and set an email via /email add test@example.com test@example.com
Log out and attempt /email recover test@example.com
Observe the error message "We were unable to send the email."
Attempt to log in with your original password -- it no longer works
The account is now permanently locked out
Plugin list
horrible mod..
Server Implementation
Standalone server (no proxy)
Database Implementation
SQLite
AuthMe Version
6.0.2-SNAPSHOT (latest master)
Error log (if applicable)
[AuthMe] Generating new password for 'PlayerName'
Configuration
BNA