# Better error message for uneditable "user\_notifications.confirm\_old\_email" texts

**URL:** <https://meta.discourse.org/t/better-error-message-for-uneditable-user-notifications-confirm-old-email-texts/111853>\
**Category:** UX\
**Created:** [March 17, 2019, 3:25pm UTC](https://meta.discourse.org/t/better-error-message-for-uneditable-user-notifications-confirm-old-email-texts/111853 "2019-03-17T15:25:47Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![gerhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/gerhard/32/119479_2.png) [@gerhard](https://meta.discourse.org/u/gerhard)\
**Post date:** [March 17, 2019, 9:08pm UTC](https://meta.discourse.org/t/better-error-message-for-uneditable-user-notifications-confirm-old-email-texts/111853/3 "2019-03-17T21:08:45Z")

</div>

The ability to edit those strings was removed last May as a reaction to a social engineering attack.

> [@Discourse hacked via sophisticated social engineering](https://meta.discourse.org/t/discourse-hacked-via-sophisticated-social-engineering/87905/2):
>
> we [just implemented a change](https://github.com/discourse/discourse/commit/9f422c93f67f156c3216a57cdf1afc0c5fc94e28) such that _nobody_, not even an admin, can modify that particular email template.

I guess there should be a friendly error message instead of a generic error 404 to make it less confusing.

---

_[View the full topic](https://meta.discourse.org/t/better-error-message-for-uneditable-user-notifications-confirm-old-email-texts/111853)._
