From 95993a89ce6ca5f5e26b1c22b65c57dcb8c005e9 Mon Sep 17 00:00:00 2001 From: Nick Zaccardi Date: Sat, 27 May 2017 16:27:13 -0400 Subject: Fixed #28248 -- Fixed password reset tokens being valid for 1 day longer than PASSWORD_RESET_TIMEOUT_DAYS. --- docs/releases/2.0.txt | 6 ++++++ 1 file changed, 6 insertions(+) (limited to 'docs') diff --git a/docs/releases/2.0.txt b/docs/releases/2.0.txt index e4b7110560..39df2d891d 100644 --- a/docs/releases/2.0.txt +++ b/docs/releases/2.0.txt @@ -355,6 +355,12 @@ Miscellaneous connection, those queries could be included as part of the ``assertNumQueries()`` count. +* The ``PASSWORD_RESET_TIMEOUT_DAYS`` setting is more properly respected in + ``contrib.auth`` password reset. Previously, resets were allowed for one day + longer than expected. For example, with the default of + ``PASSWORD_RESET_TIMEOUT_DAYS = 3``, password reset tokens are now valid for + 72 hours rather than 96 hours. + .. _deprecated-features-2.0: Features deprecated in 2.0 -- cgit v1.3