[wp-trac] [WordPress Trac] #32429: Password reset links should expire

WordPress Trac noreply at wordpress.org
Tue Jun 23 03:22:08 UTC 2015


#32429: Password reset links should expire
--------------------------+--------------------------
 Reporter:  markjaquith   |       Owner:  markjaquith
     Type:  defect (bug)  |      Status:  reviewing
 Priority:  normal        |   Milestone:  4.3
Component:  Security      |     Version:
 Severity:  normal        |  Resolution:
 Keywords:  has-patch     |     Focuses:
--------------------------+--------------------------

Comment (by dd32):

 I feel that breaking existing reset keys should be the expected behaviour
 here.

 Anyone with a now-expired link will just have to request them again - not
 a major hassle IMHO, and the added security outweighs the risks.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/32429#comment:20>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list