Password reset tokens should be invalidated after an email address change, so that any existing resets that went to a potentially compromised email address cannot be used.
Git: f9ac6e1a
And after a password change, for good measure.
https://forge-allura.apache.org/p/allura/git/merge-requests/12/
Log in to post a comment.
And after a password change, for good measure.
https://forge-allura.apache.org/p/allura/git/merge-requests/12/