|
|
|
|
|
by tvelichkov
3520 days ago
|
|
If you steal someones else password-reset link, change the password, then at the end of the day, won't you end up with a password, but missing email/username in order to log in? I mean the reset password link shouldn't reveal any other credentials about the account. (I know at some sites after reseting a password you may end up automatically logged in, but i think this is a bad practice). |
|
I feel like I've seen more of the former than the latter.