0

In Red Hat Single Sign-On (and also in Keycloak), there is this Forgot Password? functionality. If you click it and then enter your username, you will get an email with a link to change your password.

Note: Visiting the URL of that link invalides it.

Problem: Some of our clients have security software which follow every link in emails, resulting in invalid tokens (“invalid code”) before the link even reaches the client.

Any suggestions?

Marcus
  • 1,857
  • 4
  • 22
  • 44
  • What about adding exceptions for the security software? :) – BlackPearl Aug 12 '18 at 19:07
  • I was hoping for something without having to irritate the client (person) in the first place. Maybe token invalidation after the password change, dunno. – Marcus Aug 13 '18 at 11:02

0 Answers0