{"email":"user@example.com","token":"user@example.com|1780346657","link":"https://owaspsecure.com/demo/a04_insecure_design/attacks/reset_flow/reset.php?token=user%40example.com%7C1780346657","notes":"Token is predictable (email|timestamp), has no TTL, and can be reused."}