I'm not sure if this is a LoginToboggan issue or if the problem starts somewhere else. I don't see this issue in the queue already. Two users have emailed us to let us know that when they try to click on a link to re-set their password, they get an error that the link has already been used, though they never clicked on it. (In fact our Mandrill reports show no links clicked in the emails they received).

I found hints about something similar to this in D6 caused by the need to "increase the maximum link text length in Input formats." Could something like that be at play here?

Thanks for any clues! Thanks for the module, too, we love it.
Mary