in reply to Where is password expiry enforced in Catalyst, using Catalyst::Plugin::Authentication?

I'm supposed to add a password timeout, after which a new password is required.

As a security feature, this practice has been thoroughly refuted. You can do it if you like, just don't be lulled into thinking that it will improve security.


🦛

  • Comment on Re: Where is password expiry enforced in Catalyst, using Catalyst::Plugin::Authentication?