Misleading "email sent" message when recovering password for non-existing account

@jmangelo Auth0 signup API reports an error if you try to create an account with an email address that is already used. Given account existence is already exposed via the signup API, why try to hide it in the password reset api?

1 Like