All valid forgot password tokens should be invalidated (or expired) after a successful password reset occurs for a user.
This ticket was inspired by this article:
https://paragonie.com/blog/2016/09/untangling-forget-me-knot-secure-account-recovery-made-simple
This ticket was inspired by this article:
https://paragonie.com/blog/2016/09/untangling-forget-me-knot-secure-account-recovery-made-simple
- is related to
-
GTWY-4748 Forgot Password Tokens Stored in Plain Text
- Done