mirror of
https://github.com/complexcaresolutions/dak.c2s.git
synced 2026-03-17 21:53:41 +00:00
Adds "Passwort vergessen?" to login page with email-based password reset flow. Backend generates secure token (SHA-256 hashed, 1h expiry), sends reset link via SMTP, and validates on submission. Includes rate limiting (3 requests/hour/email), audit logging, and account unlock on successful reset. New ResetPasswordPage with password confirmation. New DB table: password_reset_tokens (migration 008). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| 005_add_disclosure_requests.py | ||
| 006_anonymize_fall_ids.py | ||
| 007_add_report_type.py | ||
| 008_password_reset_tokens.py | ||
| 062ccae5457b_initial_schema.py | ||
| 5717043d0f9d_add_profile_fields_to_users.py | ||