From 8bb9aa616ab2879e8b4fce3588e6225377e4c559 Mon Sep 17 00:00:00 2001 From: Ramiro Rikkert Date: Thu, 1 Mar 2012 11:14:45 +0100 Subject: [PATCH] Fix: recover e-mail is never revoked. --- casino/app/controllers/casino/Registration.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/casino/app/controllers/casino/Registration.java b/casino/app/controllers/casino/Registration.java index af361e9..7db419d 100755 --- a/casino/app/controllers/casino/Registration.java +++ b/casino/app/controllers/casino/Registration.java @@ -281,7 +281,7 @@ public static void lostPasswordNewPasswordFinish(@Required String code, } else { - Casino.setRecoveryPasswordCode(email, code); + Casino.setRecoveryPasswordCode(email, null); // compute hash... String passwordHash = Casino.getHashForPassword(password);