Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Core allows reset password from different tenant #823

Open
sattvikc opened this issue Sep 21, 2023 · 2 comments
Open

Core allows reset password from different tenant #823

sattvikc opened this issue Sep 21, 2023 · 2 comments
Labels
bug Something isn't working

Comments

@sattvikc
Copy link
Collaborator

🐛 Bug Report

If reset password token was generated from tenant t1, core allows reset password / consume reset password token from a different tenant t2 as long as they are in the same user pool. Should core validate the originating tenant?

Useful informations

@sattvikc sattvikc added the bug Something isn't working label Sep 21, 2023
@Baibhab97
Copy link

Is it still not taken? If not, I would like to work on it.

@rituraj2000
Copy link

@sattvikc Please assign it to me if it is open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants