If a user has located their account (so they know its username and id), but does not know their password (nor have a 1FA authentication method added, like CTAP2), they are unable to acquire the e-mail address of the account by merely appending .json to the relevant profile URI.
Consequently, how are they to request a password reset, considering that the password reset form requires an e-mail address; it does not accept a username?
they can search their various email accounts for the forum domain? how many email addresses do they have?
If all else fails…
send the admin a list of possible email addresses to verify (the admin could send an email to the correct one, which would be fairly secure)
ask the admin if they’re willing to send an obscured version like a**********t@*****.com? sometimes that’s enough to help (but also does leak a little info, so they might not)
@awesomerobot and @NateDhaliwal, the problem with these approaches is that I recently experienced this at community.openAI.com, because I utilise an e-mail alias service, as many nowadays do. Though, it would be worse if one had merely sub-addressed their e-mail address, which is common practice, as that would be infeasible to remember. [1] Unfortunately, no avenue of contact is provided to the moderators, as is true for many Discourse instances, and another problem.
Had I not been able to discover my e-mail address, I would have been out of luck.
The first form field prompts for email or username.
The link below the first field works, regardless of whether you supplied the email or the username.
The I forgot my password link also works for either username or email, unless the Admins have enabled the Hide email address taken site setting.
On the OpenAI site, the forgot password form requires an email, but on another site where that setting is disabled, the form allows the entry of the username: