Open randygit opened 8 years ago
valid roles are:
we can leave out temporary token, just a link to the login page.
Just make the account active once logged in. Even if they don't want to change passwords. Adding a verification stage and putting status of user as pending would only add an extra step to check if password changed. Save extra use case/resources in case they have a mandatory change password rule every three months.