password-reset: strengthten security on password reset logic....
password-reset: strengthten security on password reset logic.
- generate token that has special password reset role
- set 10 minut expiration on the token
- add some sleep to prevent bruteforcing attacks
- use implicit messages to prevent user email discovery attacks