keybase / keybase/keybase-issues

Password Reset Token Should Expire/Contain Nonce

Open
#342 15 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Would be nice if the reset password link sent via email expired the token and/or had it contain a nonce so that each reset link could only be used once within a specified block of time. Maybe I just haven't waited long enough for expiration?

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. First clarify whether expiration, single-use nonces, or both are required, then locate the password-reset token generation and validation flow; done means links expire within an agreed interval and cannot be reused.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.