4 ms·
> I think the point was, if I request a password reset X times for the same email within the duration of the expiration time, there'll be X amount of valid pass
by aptwebapps 12y ago
> I think the point was, if I request a password reset X times for the same email within the duration of the expiration time, there'll be X amount of valid password reset URLs that can potentially be bruteforced.
What does this have to do with whether you're storing tokens or using a hash?
- raziel2p 12y agoSorry for the late reply. In the apps I have, I delete any existing tokens for the given e-mail address when a new one is requested, so only one is valid at any given time.