gak112 / gak112/DearJobTesting

[WEB] [Forgot Password] Persistence of Password Reset Link After Use

Open
#915 0 comments 0 reactions 2 assignees Claimed by @Abhinavgunda25 View on GitHub
bug Severity:Medium
Dominant language
No language data
Stars
1
Forks
0
PR merge metrics
No merged PRs in 30d

Description

**Steps:**
1. Open a web browser and go to "https://dearjob.org".
2. Navigate to the login section.
3. Click on "Forgot Password?".
4. Enter the registered user's email and click "Submit".
5. Check the registered email for the password reset link.
6. Click on the password reset link received in the email.
7. Enter and submit the "New Password" and "Confirm Password" fields.
8. Use the same password reset link again.

**Actual Result:**
- Despite successfully using the password reset link to change the password, the link remains active and can be used again for a subsequent password reset.

**Expected Result:**
- Once the password reset link has been used to change the password, it should be rendered invalid or expired, preventing its subsequent use. The link should have a one-time use restriction for security purposes, ensuring it cannot be utilized multiple times.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.