{"email":"user@example.com","token":"user@example.com|1776411298","link":"https://owaspsecure.com/demo/a04_insecure_design/attacks/reset_flow/reset.php?token=user%40example.com%7C1776411298","notes":"Token is predictable (email|timestamp), has no TTL, and can be reused."}