Skip to content

Commit 419a328

Browse files
authored
Merge pull request #340 from Speelwolf/main
Replacing Static Fake Token with Randomized 32-Character Token
2 parents 59d02ee + d96b3be commit 419a328

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

src/ResetPasswordHelper.php

+3-1
Original file line numberDiff line numberDiff line change
@@ -168,7 +168,9 @@ public function generateFakeResetToken(?int $resetRequestLifetime = null): Reset
168168

169169
$generatedAt = ($expiresAt->getTimestamp() - $resetRequestLifetime);
170170

171-
return new ResetPasswordToken('fake-token', $expiresAt, $generatedAt);
171+
$fakeToken = bin2hex(random_bytes(16));
172+
173+
return new ResetPasswordToken($fakeToken, $expiresAt, $generatedAt);
172174
}
173175

174176
private function findResetPasswordRequest(string $token): ?ResetPasswordRequestInterface

0 commit comments

Comments
 (0)