Skip to content

it's possible change a password without owning the account. #160

@tomivm

Description

@tomivm

it's possible to change the password of any account only with post an email on user/forgot and using the id of the user on user/store-password
image
Not only that, when post to /user/forgot endpoint is sending the private token in the response.
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions