Affects Version/s: 6.2.3 CE GA4, 6.2.10 EE GA1, 7.0.0 M7
Steps to reproduce - quick
Hit http://localhost:8080/c/portal/update_password?ticketKey=43e8d365-a531-4dae-aa8a-c541e365a688 --> You're redirected to the Home page without any notification
Steps to reproduce - detailed
1- Start the portal with proper mail configuration
2- Modify the Default Password Policy in the Users Admin and set the Reset Link "Max Age" to 5 minutes
3- Create a new a account with a valid email address
4- Click on "Forgot Password" in the Login portlet
5- Request a reset link
6- Wait for 5 minutes, so the ticket will expire
7- Click on the link you received in email
No error/warning message is shown when password reset link has expired and the user hits the portal using that URL. We just simply redirect the user to the Welcome page (COMMON_REFERER_JSP).
A message is shown to notify the user that the reset link has expired.