network
network copied to clipboard
Magic Link recovery emails being sent when config is set to one time passwords
Preflight checklist
- [X] I could not find a solution in the existing issues, docs, nor discussions.
- [X] I agree to follow this project's Code of Conduct.
- [X] I have read and am following this repository's Contribution Guidelines.
- [X] I have joined the Ory Community Slack.
- [X] I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
wonderful-cannon-d0fw8m37wm
Describe the bug
When recovery is set to one-time passwords is is possible to trigger an email using magic link.
It is expected that the setting from the console would be carried across.
As we have recovery set to one-time password we cannot edit this template using the console, so this is sending an unbranded template.
Reproducing the bug
- When an expired recovery link is clicked
- A new recovery flow is triggered
- Upon completing this flow an email is received using the "magic link" template
Relevant log output
No response
Relevant configuration
No response
Version
0
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response