As an hardening measure we should expire password reset tokens after 12h and if the user has logged-in again successfully after the token was requested. |
||
|---|---|---|
| .. | ||
| avatar | ||
| command | ||
| lostpassword/controller | ||
As an hardening measure we should expire password reset tokens after 12h and if the user has logged-in again successfully after the token was requested. |
||
|---|---|---|
| .. | ||
| avatar | ||
| command | ||
| lostpassword/controller | ||