Wait. I missed that the reset password screen no longer accepts just the username. That makes sense only if people are harassing users with password resets, and I thought there was rate limit stuff in place to stop that. I wonder whet) what actual problem this change was fixing.
And I also know from experience that it’s not that uncommon for users in a long lasting community to no longer remember their email address.
So… my diatribe about how you should know what address you signed up with is completely wrong-headed. I was a jerk and I humbly reoent.
And now that I think I understand your problem, and it’s made by the owners of a community you’re in, apparently, on purpose. While it may be partly the fault of new defaults, I think those people can change the value of the hide_email_address_taken…
Wait. Why would hide_email_address_taken require users to enter their email address and not their username? Resetting the password with the username does not expose an email address. That’s the real problem.
There are several layers to this problem I didn’t understand. I’m sorry to have been so unhelpful.