Disallow users to change their email

From Kolmisoft Wiki
Jump to navigationJump to search

Why should I disallow users to change emails?

You should disallow users from changing their email addresses if you are using PayPal or another payment gateway. Reason: users will not be able to use a stolen PayPal or other payment gateway account if you additionally enable confirmation for suspicious payments in MOR. This bothers you because a user whose payment gateway account was hacked may ask the payment gateway provider for a refund.


P.S. If you are giving away some free balance, you might also consider using reCAPTCHA feature in MOR to defend yourself against automated bot registration attacks

How to allow/disallow users to change their emails?

To disallow users to change their emails tick a check box in Setup -> Settings -> Various menu:

Dont allow to change email.png


Other notes

  • If you are using payment gateways for security reasons, it is recommended to disallow users from editing their emails. Also please see the Payments Confirmation section