Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Docs]: password reset security imporvement #1451

Closed
mohamedhoss123 opened this issue Feb 20, 2024 · 1 comment
Closed

[Docs]: password reset security imporvement #1451

mohamedhoss123 opened this issue Feb 20, 2024 · 1 comment
Labels
documentation Improvements or additions to documentation

Comments

@mohamedhoss123
Copy link

Description

there is a problem with password reset example as it don't mention hashing reset token before storing it into database ,
to explain what will happend if we didn't hash we basically make a way to ignore the normal password hashing as if database leaked password reset token will be leaked to and then the normal hashed password will be useless just get the token (the plain text) and make new password

@mohamedhoss123 mohamedhoss123 added the documentation Improvements or additions to documentation label Feb 20, 2024
@pilcrowonpaper
Copy link
Member

Yup, fixed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

2 participants