That still doesn't make it good practice to send the old password (hashed or not) to the client.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies:
That still doesn't make it good practice to send the old password (hashed or not) to the client.