Project

General

Profile

Actions

Task #6465

closed

Expire the password reset link [datacenterlight, dynamicweb]

Added by Nico Schottelius about 5 years ago. Updated 4 months ago.

Status:
Rejected
Priority:
High
Assignee:
Target version:
-
Start date:
02/15/2019
Due date:
% Done:

0%

Estimated time:
PM Check date:
07/15/2019

Description

According to a customer report the reset link can be reused. The following changes are necessary:

  • Expire after a certain time (I suggest 24h)
  • Expire after one use

If feasible, I suggest to focus on ramping up the new user service, implement the change in there and then adjust dynamicweb to use the new user service. This will probably also include to register users in LDAP.

Mondi, if you have time we can work on it this weekend.


Related issues 1 (0 open1 closed)

Related to queue - Task #5789: Some issues to be cleared about userserviceRejected10/09/2018

Actions
Actions

Also available in: Atom PDF