summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSytse Sijbrandij <sytse@gitlab.com>2015-01-23 10:55:12 -0800
committerSytse Sijbrandij <sytse@gitlab.com>2015-01-23 10:55:12 -0800
commit31bf578d67620dfc904ff2f980788fe38ee9ca92 (patch)
treeac8d443eb996987a6f7055efb500d1736f35330e
parentc6e24850a3ad662d82f8e0812eb2a38df4f43c13 (diff)
downloadgitlab-ce-31bf578d67620dfc904ff2f980788fe38ee9ca92.tar.gz
Increase password reset timeout since other people trigger it when they create an account for you.
-rw-r--r--CHANGELOG2
-rw-r--r--config/initializers/devise.rb3
2 files changed, 3 insertions, 2 deletions
diff --git a/CHANGELOG b/CHANGELOG
index bd519002531..63b70f8bc74 100644
--- a/CHANGELOG
+++ b/CHANGELOG
@@ -37,7 +37,7 @@ v 7.8.0
-
-
-
- -
+ - Password reset token validity increased from 2 hours to 2 days since it is also send on account creation.
-
-
-
diff --git a/config/initializers/devise.rb b/config/initializers/devise.rb
index c6eb3e51036..79abe3c695d 100644
--- a/config/initializers/devise.rb
+++ b/config/initializers/devise.rb
@@ -145,7 +145,8 @@ Devise.setup do |config|
# Time interval you can reset your password with a reset password key.
# Don't put a too small interval or your users won't have the time to
# change their passwords.
- config.reset_password_within = 2.hours
+ # When someone else invites you to GitLab this time is also used so it should be pretty long.
+ config.reset_password_within = 2.days
# ==> Configuration for :encryptable
# Allow you to use another encryption algorithm besides bcrypt (default). You can use