diff --git a/gluon/tools.py b/gluon/tools.py index b7f4abc6..f4f54f6d 100644 --- a/gluon/tools.py +++ b/gluon/tools.py @@ -3011,7 +3011,7 @@ class Auth(object): if self.settings.prevent_password_reset_attacks: key = request.vars.key - if not key and len(request.args)>0: + if not key and len(request.args)>1: key = request.args[-1] if key: session._reset_password_key = key