Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Expire token after 12h and if user logged-in again #18491

Merged
merged 1 commit into from
Aug 24, 2015

Conversation

LukasReschke
Copy link
Member

As an hardening measure we should expire password reset tokens after 12h and if the user has logged-in again successfully after the token was requested.

As an hardening measure we should expire password reset tokens after 12h and if the user has logged-in again successfully after the token was requested.
@scrutinizer-notifier
Copy link

A new inspection was created.

@ghost
Copy link

ghost commented Aug 22, 2015

🚀 Test PASSed.🚀
chuck

@LukasReschke
Copy link
Member Author

@owncloud/security-team This wants reviewers as well 🙊

@karlitschek
Copy link
Contributor

agreed! 👍 not tested

@rperezb
Copy link

rperezb commented Aug 24, 2015

@SergioBertolinSG can you please check this one?

@MorrisJobke
Copy link
Contributor

Tested and works 👍

@SergioBertolinSG
Copy link
Contributor

Working fine after 12h 👍

LukasReschke added a commit that referenced this pull request Aug 24, 2015
Expire token after 12h and if user logged-in again
@LukasReschke LukasReschke merged commit a67a227 into master Aug 24, 2015
@LukasReschke LukasReschke deleted the expire-token-after-12h-or-login branch August 24, 2015 12:08
@lock lock bot locked as resolved and limited conversation to collaborators Aug 10, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants