Hash activation and password-reset tokens at rest
Open
- Dominant language
- Java
- Stars
- 11
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
This issue has no description.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue body names no files, tests, or entry points. Start by locating where activation and password-reset tokens are generated and persisted in the OAuth2 SSO application, then trace how they are verified. Done means both token types are protected at rest without breaking their existing flows, with tests covering generation, storage, and verification.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, postgresql, spring-boot
- Domain
- authentication, databases, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100