* fix: invalidate old password reset tokens when new one is requested
Security fix: Previously, old password reset tokens remained valid
even after requesting a new one, creating a potential account takeover
vulnerability. This change ensures that when a user requests a new
password reset link, all previous valid tokens for that email are
immediately invalidated.
Changes:
- Expire all existing valid tokens before creating new one
- Add E2E test to verify old tokens are invalidated
- Prevent potential account takeover scenario
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
* Clean up code by removing blank line
Removed unnecessary blank line in forgot-password.e2e.ts.
* test: fix strict mode violation in password reset test
Use getByRole to specifically target the heading element instead of
text locator which was matching both the heading and button.
Co-Authored-By: anik@cal.com <adhabal2002@gmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>