Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review password recovery flow #297

Closed
ctizen opened this issue Feb 27, 2023 · 0 comments
Closed

Review password recovery flow #297

ctizen opened this issue Feb 27, 2023 · 0 comments

Comments

@ctizen
Copy link
Member

ctizen commented Feb 27, 2023

  • We can't nullify reset token code on first visit, as it doesn't allow sharing links via messengers with auto-previews.
  • There's some questionable logic with temporary passwords that is probably to be deleted.
  • Maybe use some digit-code to prevent nullifying token with auto-previews
@ctizen ctizen added the audit label Feb 28, 2023
@ctizen ctizen added this to the Fixathon Jan 3-5 2024 milestone Jan 2, 2024
@ctizen ctizen closed this as completed in 7dbf7e6 Jan 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: Done
Development

No branches or pull requests

1 participant