BallStateCBER / commentaries-cake3

CBER Data Center: Weekly Commentary
0 stars 0 forks source link

Remove or revise password reset time limit #20

Open PhantomWatson opened 6 years ago

PhantomWatson commented 6 years ago

The old system of giving out password-reset URLs that only work in the current month is

My recommendation is to remove this time limit entirely, but it would also be okay to change the limit to a specific period of time (like 24 hours, enforced by including a timestamp in the URL and making it part of the hash's input).