-
Lukas Reschke authored
As an hardening measure we should expire password reset tokens after 12h and if the user has logged-in again successfully after the token was requested.
Lukas Reschke authoredAs an hardening measure we should expire password reset tokens after 12h and if the user has logged-in again successfully after the token was requested.