ended9월 2일· 1 sources
Password Recovery Design: Anonymous Requests, Verified Resets, and Session Revocation
Why it matters
Short answer: make the forgot-password endpoint behave the same for a known and unknown address, then let a single-use, short-lived token move the account into a confirmed reset state before revoking ...
1
Sources
+0
24h
—
Growth
19d
Active