# Password reset email should send IP info

**URL:** https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492
**Category:** Feature
**Created:** [August 4, 2017, 11:58pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492 "2017-08-04T23:58:22Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![pain](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pain/32/89202_2.png) [@pain](https://meta.discourse.org/u/pain)
#### Post date: [August 4, 2017, 11:58pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/1 "2017-08-04T23:58:22Z")

</div>

is there a way to make it so that when a user requests a password reset, it sends the ip in the email as well?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [August 5, 2017, 12:00am UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/2 "2017-08-05T00:00:39Z")

</div>

For what purpose? Can you cite examples? Is this a security concern issue?

---

<div class="post-metadata">

### Author: ![pain](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pain/32/89202_2.png) [@pain](https://meta.discourse.org/u/pain)
#### Post date: [August 5, 2017, 12:04am UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/3 "2017-08-05T00:04:16Z")

</div>

for security reasons, users can do it for spammy purpose, so if someone’s doing it to spam person can report it or something or if its an admin account, he and or she can block ip

---

<div class="post-metadata">

### Author: ![elijah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elijah/32/104055_2.png) [@elijah](https://meta.discourse.org/u/elijah)
#### Post date: [August 5, 2017, 12:30am UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/4 "2017-08-05T00:30:17Z")

</div>

I’ve seen that sort of thing before. The wiki associated with Nextthing’s CHIP computer did it for me:

```plaintext
Someone, probably you, from IP address 10.0.0.70,
has registered an account "Elijah" with this email address on www.chip-community.org.

To confirm that this account really does belong to you and activate
email features on www.chip-community.org, open this link in your browser:
 ...

```

Complete with that not-useful IP address.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [August 5, 2017, 1:30am UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/5 "2017-08-05T01:30:25Z")

</div>

Couple different ways to approach this..

```
Here are the details of the sign-in attempt:
Thursday, July 07/20/17 at 17:03 MST
Account: name@example.com
Location: US
IP Address: 12.34.56.7
Operating system: Windows 10 64-bit
Browser: Chrome

```

and

 ![image](https://global.discourse-cdn.com/meta/original/3X/0/e/0e4040486347d0d0c25b627333f1b49b9c044e90.jpg)

---

<div class="post-metadata">

### Author: ![pain](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pain/32/89202_2.png) [@pain](https://meta.discourse.org/u/pain)
#### Post date: [August 5, 2017, 1:33am UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/6 "2017-08-05T01:33:49Z")

</div>

so how do i set that up then?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [August 11, 2017, 5:29pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/7 "2017-08-11T17:29:15Z")

</div>

You can not set this up, it would require changes to Discourse. I think we kind of support at least allowing this optionally.

---

<div class="post-metadata">

### Author: ![pain](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pain/32/89202_2.png) [@pain](https://meta.discourse.org/u/pain)
#### Post date: [August 11, 2017, 9:07pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/8 "2017-08-11T21:07:34Z")

</div>

well if you guys could implement this in an update that’d be great, that way users can use it and if their account is breached or something, they can resolve it and its also good for admins/mods

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [August 11, 2017, 9:08pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/9 "2017-08-11T21:08:46Z")

</div>

Our plate is very very full 🍽

---

<div class="post-metadata">

### Author: ![pain](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pain/32/89202_2.png) [@pain](https://meta.discourse.org/u/pain)
#### Post date: [August 11, 2017, 9:18pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/10 "2017-08-11T21:18:45Z")

</div>

understandable, but for future updates? like add it to a to-do list? im sure many would enjoy this

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [August 11, 2017, 9:20pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/11 "2017-08-11T21:20:03Z")

</div>

Up to @codinghorror if he wants this to be #pr-welcome or plugin material. I am kind of on the fence here.

---

<div class="post-metadata">

### Author: ![pain](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pain/32/89202_2.png) [@pain](https://meta.discourse.org/u/pain)
#### Post date: [August 11, 2017, 9:29pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/12 "2017-08-11T21:29:05Z")

</div>

ah ok, well if he wants to do it that’d be great, would be great if it’s built into the software and not plugin

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [August 11, 2017, 10:17pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/13 "2017-08-11T22:17:36Z")

</div>

It is not a bad idea @elijah did you want to work on this? V1 can be simple, use any of the existing templates above, or pick your own from (insert how Internet web site does it here).

---

<div class="post-metadata">

### Author: ![elijah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elijah/32/104055_2.png) [@elijah](https://meta.discourse.org/u/elijah)
#### Post date: [August 12, 2017, 6:17am UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/14 "2017-08-12T06:17:44Z")

</div>

Sure, I could look at this shortly.

---

<div class="post-metadata">

### Author: ![elijah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elijah/32/104055_2.png) [@elijah](https://meta.discourse.org/u/elijah)
#### Post date: [August 18, 2017, 6:21pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/15 "2017-08-18T18:21:02Z")

</div>

In my test instance, it is working now, sending messages like this (text part, email part is the md-to-html version):

```markdown
Somebody asked to reset your password on [Discourse](http://my.example.net).

The request came from 142.254.30.0 using "Mozilla/5.0 (X11; Linux x86_64; rv:55.0) Gecko/20100101 Firefox/55.0". If it was not you, you can safely ignore this email.

Click the following link to choose a new password:
http://my.example.net/u/password-reset/316696edbc17931b61a7a5edc69be11a

```

People can leave out the {user-agent} param from the message, if they don’t like it. I’m going to test injecting HTML through the UA before I make a pull request. Does anyone think it is worthwhile trying to parse the UA? I worry that’s an ocean of messy heuristics.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [August 18, 2017, 7:34pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/16 "2017-08-18T19:34:07Z")

</div>

Hell no definitely do NOT parse the UA! 😉

---

<div class="post-metadata">

### Author: ![elijah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elijah/32/104055_2.png) [@elijah](https://meta.discourse.org/u/elijah)
#### Post date: [August 19, 2017, 6:41am UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/17 "2017-08-19T06:41:22Z")

</div>

This is a bit harder than I expected. Trying to escape the HTML in a User-Agent at time of save works:

```plaintext
#<EmailToken id: 23, user_id: 2, email: "qaz@qaz.wsx",
token: "520e6d016c2b78630e6eac35d884c22b",
confirmed: false,
expired: false,
created_at: "2017-08-19 06:30:40",
updated_at: "2017-08-19 06:30:40",
remote_ip: #<IPAddr: IPv4:142.254.30.0/255.255.255.255>,
user_agent: "Mozilla/5.0 (&lt;a href=&quot;http://exploitme.inv...">

```

Then I pull it out and put it in email. In the text part I get a nice straight-forward:

```html
using "Mozilla/5.0 (&lt;a href=&quot;http://exploitme.invalid/&quot;&gt;Phishing&lt;/a&gt;)

```

And in the HTML part I get:

```html
using “Mozilla/5.0 (<a href="http://exploitme.invalid/" rel="nofollow noopener">Phishing</a>)

```

Why is it talking my disarmed HTML and rearming it?

---

<div class="post-metadata">

### Author: ![elijah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elijah/32/104055_2.png) [@elijah](https://meta.discourse.org/u/elijah)
#### Post date: [August 20, 2017, 11:52pm UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/18 "2017-08-20T23:52:46Z")

</div>

I went with a belt-and-suspenders fix. Drop any `<`, `>`, and ``` in the UA, then wrap the UA in backticks so Markdown will treat it as code.

[https://github.com/discourse/discourse/pull/5069](https://github.com/discourse/discourse/pull/5069)

---

<div class="post-metadata">

### Author: ![tgxworld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tgxworld/32/106117_2.png) [@tgxworld](https://meta.discourse.org/u/tgxworld)
#### Post date: [August 21, 2017, 12:30am UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/19 "2017-08-21T00:30:13Z")

</div>

I was thinking that the country and city should be provided along with the IP address as well. To a non-technical user, showing them a bunch of random digits might not make any sense to them. 💭

---

<div class="post-metadata">

### Author: ![elijah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elijah/32/104055_2.png) [@elijah](https://meta.discourse.org/u/elijah)
#### Post date: [August 21, 2017, 12:50am UTC](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492/20 "2017-08-21T00:50:06Z")

</div>

Is Discourse using a geo-ip library already? I didn’t want to add one just for this.

[Next page](https://meta.discourse.org/t/password-reset-email-should-send-ip-info/67492.md?page=2)
