Expire All Valid Forgot Password Tokens on Successful Password Reset

XMLWordPrintable

    • Type: Defect
    • Resolution: Done
    • Priority: Standard
    • 2.0.95
    • Affects Version/s: None
    • Component/s: Security
    • None
    • Sprint 146

      All valid forgot password tokens should be invalidated (or expired) after a successful password reset occurs for a user.

      This ticket was inspired by this article:
      https://paragonie.com/blog/2016/09/untangling-forget-me-knot-secure-account-recovery-made-simple

              Assignee:
              Nathan Hook
              Reporter:
              Nathan Hook
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: