# Always allow username-based password reset

**URL:** https://meta.discourse.org/t/always-allow-username-based-password-reset/409326
**Category:** Feature
**Tags:** login
**Created:** [August 5, 2026, 1:53am UTC](https://meta.discourse.org/t/always-allow-username-based-password-reset/409326 "2026-08-05T01:53:33Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![awesomerobot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/awesomerobot/32/142900_2.png) [@awesomerobot](https://meta.discourse.org/u/awesomerobot)
#### Post date: [August 6, 2026, 9:18pm UTC](https://meta.discourse.org/t/always-allow-username-based-password-reset/409326/6 "2026-08-06T21:18:49Z")

</div>

This was an intentional change made here originally: [FEATURE: hide\_email\_address\_taken forces use of email in forgot password form - Pull Request #15362 - discourse/discourse - GitHub](https://github.com/discourse/discourse/pull/15362)

> This strengthens this site setting which is meant to be used to harden sites  
> that are experiencing abuse on forgot password routes.
> 
> Previously we would only deny letting people know if forgot password worked on not  
> **New change also bans usage of username for forgot password when enabled**

So not sure if @sam has any thoughts on walking this back for usernames, at the time of the change it wasn’t the default state, but as of ~2024 it is. I think the risk of allowing usernames is pretty low, someone could potentially use it to send any random user a bunch of emails… but it should be rate limited.

---

_[View the full topic](https://meta.discourse.org/t/always-allow-username-based-password-reset/409326)._
