FIX: Clear the session after a reset token was used
This commit is contained in:
@@ -409,6 +409,7 @@ class UsersController < ApplicationController
|
||||
@user.auth_token = nil
|
||||
if @user.save
|
||||
Invite.invalidate_for_email(@user.email) # invite link can't be used to log in anymore
|
||||
session["password-#{params[:token]}"] = nil
|
||||
logon_after_password_reset
|
||||
end
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user