Skip to Content

Editing one security answer no longer deletes the others

Shipped 2026-09-21

Same-day follow-up to TUN-873, found while verifying it in production.

Security answers are stored hashed, so the profile editor cannot show a member what they already set — every answer box is blank when the page loads. The writer shipped that morning treated a blank answer as “this question is gone” and deleted its row. A member who opened the screen to change one answer, typed into one box and saved, lost the other two without being told.

A blank now means leave this question alone. Only a question the member did not submit at all is removed, which is what happens when they change the question in a slot rather than the answer. planSecurityAnswers returns the two sets separately — keep, every question submitted, and write, those with an answer to store — so the delete and the upsert no longer share one list.

The form blocked it too: all three answer boxes were required, so the browser would not submit until every answer was retyped. A slot whose question is unchanged is now optional, labelled “Leave blank to keep your current answer”. Change the question and its answer is required again — three answers remain mandatory, so a swapped question needs a new answer or the member would end up with two.

The behaviour it replaced was worse, for what it is worth: before TUN-873 the same edit stored empty strings for the untouched answers, which counted as “has security questions” while never matching anything a member could type. That left them being offered a fallback they could not complete. Neither version let a member update a single answer; this one does.

Last updated on