|
|
|
|
|
by eterm
3529 days ago
|
|
For analytics this isn't a big problem. Once a reset link has been clicked, it should be immediately invalidated. So unless the server was able to respond to the link and provide the analytics stuff but not somehow invalidate the token, I can't see how this is a problem. Another related problem is that some third party mailers move all their links via URL redirectors. In that case there's a chance the host application fails and the link is left valid. |
|
I'm not sure about this... Couldn't this produce some unexpected reset failures in cases of browsers preloading links in webmail clients?