Roll20 uses cookies to improve your experience on our site. Cookies enable you to enjoy certain features, social sharing functionality, and tailor message and display ads to your interests on our site and others. They also help us understand how our site is being used. By continuing to use our site, you consent to our use of cookies. Update your cookie preferences .
×
Create a free account

Logins & password recovery problems with site

When not logged in, going to community.roll20.net has logon options. It's not clear that it doesn't use your Roll20 account here (or if you're supposed to be able to, it doesn't work) -- the right half of the sign in popup does have a "sign in with roll20" link, but it's easy to overlook. Doing password recovery in there (to a valid account email address) gives error message "Could not instantiate mail function". Using an unknown email address both here on forgot password and on forgot password at <a href="http://app.roll20.net/sessions/new" rel="nofollow">http://app.roll20.net/sessions/new</a> give different error messages whether you give a known email address or not. It's standard practice always to tell the user something like "if this is a valid account, a password reset message has been sent" to prevent snooping of register usernames/addresses depending on the different error messages. There do not appear to be any serial failed login delays, lockouts, timers or captchas -- not a big deal though. Tested in both FFX 12 and IE 8 on WinXP.
We'll look at some of this, thanks.
The forum software has no account information stored in it, which is why trying to log in without using the Sign in with Roll20 links or recover your password using it just doesn't work. If you follow the "Forums" link on the Roll20 app when you're logged in it tries to just log you into the forum before you even get there so hopefully most people don't even realize what's going on. It's not perfect, though, but it's worth it to not make people have yet another account to remember the credentials for. I will add some more generic error message to the forgot password link, and in general things like that (serial failed delays) will be strengthened as we approach public launch...of course we monitor the server logs and would know if someone was launching a massive attack against the forgot password form, but for now we're trying to get the main app to be polished and bug free.