by asmecher » Sun Feb 19, 2006 10:28 pm
Hi Sjones,
This is indeed the right forum for feature requests; thanks for your suggestions.
1. Since OJS makes use of email communications for many of its functions, we're assuming that it's a trustworthy medium. Also, since OJS only stores hashed passwords, emails containing "raw" passwords can only be sent at the time the password is entered as a confirmation (and the "new registration" password can be modified to remove this information); any other time the password is sent, it's a freshly generated random password (and will usually be changed upon the first login). We consider this sufficient security, but we're certainly open to suggestions if you have another technique in mind.
2. We've had a few requests for this and it's already on our list.
Regards,
Alec Smecher
Open Journal Systems Team