The forgotten password recovery form says "Unable to recover password for this email" if you enter an email that is not in our database. This can be used to determine if an email address is in the system or not. Instead, we should always have a generic success message like "A password reset email has been sent, if the given email address is on record in our system."
allura:al/7543
Looks good.
I notice some EmailAddress lookup that will probably have to change when we do [#7527]
Related
Tickets:
#7527