Steps to reproduce the issue:
Send request POST /auth/forgot-password with an email registered in the platform
Send request PUT /auth/reset-password with the token retrieved in the previous step and a new password
Login with the new credentials
Suggested solution
The Forgot Password endpoint should return an empty response (even if the user doesnโt exist) and send the token via email.



Please authenticate to join the conversation.
Completed
Bug & Fixes
High Priority
11 months ago

Ivan Ligotino
Get notified by email when there are changes.
Completed
Bug & Fixes
High Priority
11 months ago

Ivan Ligotino
Get notified by email when there are changes.