[wp-trac] [WordPress Trac] #32429: Password reset links should expire

WordPress Trac noreply at wordpress.org
Tue Jun 4 14:42:46 UTC 2024


#32429: Password reset links should expire
--------------------------+--------------------------
 Reporter:  markjaquith   |       Owner:  markjaquith
     Type:  defect (bug)  |      Status:  closed
 Priority:  normal        |   Milestone:  4.3
Component:  Security      |     Version:
 Severity:  normal        |  Resolution:  fixed
 Keywords:  has-patch     |     Focuses:
--------------------------+--------------------------

Comment (by audrasjb):

 In [changeset:"58333" 58333]:
 {{{
 #!CommitTicketReference repository="" revision="58333"
 Login and Registration: Flush `user_activation_key` after successfully
 login.

 This changeset ensures the `user_activation_key` is flushed after
 successful login, so reset password links can not be used anymore after
 the user successfully log into their dashboard.

 Props nsinelnikov, rajinsharwar, Rahmohn, oglekler, hellofromTonya.
 Fixes #58901.
 See #32429
 }}}

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/32429#comment:35>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list