
Tinshed
Wellington, New Zealand
![]() ![]() |
Why it took you several days to receive the welcome email when it's triggered at registration, who knows? If sending out the password before it encrypts it is considered a security risk, then just about everyone with a Magento e-commerce website is in trouble. I'm sure there are already hundreds of Magento forums discussing this issue.
Please support Geekzone by subscribing, or using one of our referral links: Dosh referral: 00001283 | Sharesies | Goodsync | Mighty Ape | Backblaze
freitasm on Keybase | My technology disclosure
freitasm: Before you go ahead and tear your hair out, try recovering the password. Do you get the password or a reset link?
Tinshed
Wellington, New Zealand
MooreWilsons: Hi Tinshed, thanks for the feedback - as we've only just opened the doors on our new website, any constructive critricism is extremely welcome.
As has been pointed out by minigopher17, we are using Magento as the framework for our online shop, which sends out this info as the default setting - though there is NO saving of plain-text passwords in Magento and it is only sent at the time of registration before the password is hashed.
We have now removed the password from the email template (replaced with "The password you used during registration").
Thanks again for the feedback
MW
Tinshed
Wellington, New Zealand
![]() ![]() |