# 将登录链接发送到所输入的电子邮件地址（而非主电子邮件）

**URL:** <https://meta.discourse.org/t/send-the-email-login-link-to-the-entered-email-address-not-to-the-primary-email/367016>\
**Category:** Feature\
**Tags:** login\
**Created:** [2025年五月21日 10:22 UTC](https://meta.discourse.org/t/send-the-email-login-link-to-the-entered-email-address-not-to-the-primary-email/367016 "2025-05-21T10:22:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nathank](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nathank/32/290039_2.png) [@nathank](https://meta.discourse.org/u/nathank)\
**Post date:** [2025年五月21日 10:22 UTC](https://meta.discourse.org/t/send-the-email-login-link-to-the-entered-email-address-not-to-the-primary-email/367016/1 "2025-05-21T10:22:26Z")

</div>

今天，我有机会观察到我的几位用户尝试登录我们的网站。许多用户忘记了密码，并尝试使用电子邮件登录链接：

 ![Screenshot 2025-05-21 22.16.15](https://global.discourse-cdn.com/meta/original/4X/e/b/b/ebbc730024dd40a18438796109e483087c5677be.png)

然而，预期的电子邮件链接从未到达。经过进一步调查，发现该链接被发送到了他们的主电子邮件，而他们却使用辅助电子邮件尝试登录。

虽然我可以理解在 Discourse 中几乎所有情况下都会使用主电子邮件（这就是为什么它是“主”的），但这有点不同，因为用户实际上会输入一个电子邮件地址——并且自然期望链接发送到该地址。

重现步骤：

1. 确保您的帐户中有辅助电子邮件。
2. 在您的网站上打开一个隐身浏览器会话。
3. 在登录页面的电子邮件字段中输入您的辅助电子邮件。
4. 单击出现的“跳过密码；给我发送登录链接”。
5. 去寻找电子邮件，它 **不在** 您的辅助电子邮件收件箱中。

---

<div class="post-metadata">

**Author:** ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)\
**Post date:** [2025年五月22日 00:38 UTC](https://meta.discourse.org/t/send-the-email-login-link-to-the-entered-email-address-not-to-the-primary-email/367016/2 "2025-05-22T00:38:26Z")

</div>

> [@nathank](#):
>
> 这有点不同，因为用户实际输入了电子邮件地址 - 并自然期望链接发送到该地址。

这似乎是一个合理的期望！

---

<div class="post-metadata">

**Author:** ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)\
**Post date:** [2025年五月22日 00:46 UTC](https://meta.discourse.org/t/send-the-email-login-link-to-the-entered-email-address-not-to-the-primary-email/367016/3 "2025-05-22T00:46:45Z")

</div>

我喜欢这个请求，但感觉更像是会员体验方面的功能请求，而不是漏洞。

目前的行为让人困惑，但这是有意为之的。

同意，尝试将电子邮件发送到你输入的内容是有意义的。（此外，为了这个，跳过规范化，直接将你输入的完整地址发送出去也可以）
