Uploaded image for project: 'Gateway'
  1. Gateway
  2. GTWY-4750

Expire All Valid Forgot Password Tokens on Successful Password Reset

XMLWordPrintable

    • Icon: Defect Defect
    • Resolution: Done
    • Icon: Standard Standard
    • 2.0.95
    • None
    • Security
    • None
    • Sprint 146

      All valid forgot password tokens should be invalidated (or expired) after a successful password reset occurs for a user.

      This ticket was inspired by this article:
      https://paragonie.com/blog/2016/09/untangling-forget-me-knot-secure-account-recovery-made-simple

              nhook Nathan Hook
              nhook Nathan Hook
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: