Git Merge Request #12: [#7786] Invalidate pwd reset tokens after email/password change (merged)

Merging...

Merged

Something went wrong. Please, merge manually

Checking if merge is possible...

Something went wrong. Please, merge manually

Heith Seewald wants to merge 0 commits from /u/heiths/hsallura/ to master, 2015-02-19

Determining commits...

Discussion

  • Dave Brondsema

    Dave Brondsema - 2015-02-11

    The main password reset form on /auth/preferences (different a forced change due to password expired) needs to reset the token.

    Also I think deleting an email address should clear the reset token, not only for adding a new address. (E.g. if you have multiple addresses recorded already and just remove a compromised one).

     
  • Heith Seewald - 2015-02-16

    Good point. I updated hs/7786 with those changes.

     
  • Heith Seewald - 2015-02-16

    Good point. I updated hs/7786 with those changes.

     
  • Dave Brondsema

    Dave Brondsema - 2015-02-16

    Getting there. It still doesn't get cleared out after a regular password change on /auth/preferences/.

     
  • Heith Seewald - 2015-02-17

    Got it :)

    I also wrote a test for resetting passwords via /auth/preferences.

     
  • Dave Brondsema

    Dave Brondsema - 2015-02-19
    • Status: open --> merged
     

Log in to post a comment.