Ouch.
Ouch.
I contacted OKC about this but they said that it was not an issue.
It's an unfortunate change that has made single-use links a worse UX and less popular in the last couple of years.
This is exactly the pain I've experienced with my own site, https://alchemist.camp
I've manually tested it and seen the token consumed when clicking the link via gmail but had no issues when copying the link from the password reset email to a gmail account. A second manual tester confirmed the same, as have multiple support cases.
Password recovery links sporadically fail for gmail users. I had to add extra instructions to copy and paste rather than click through the link and am in the process of moving away from single-use tokens because a lot of people still click before reading those instructions and email me for support.
My increased customer support burden isn't something Gmail PMs worry about, but they may whitelist some larger service's emails.
Not quite as secure, but way better than never expires?
Gmail may fetch the page but wont run the js on it.
Edit: this works for situations when spam filters fetch the links as soon as the mail arrives.
Comment about a form and PUT/POST is good - it will work by standards in any browser, even when gmail starts executing javascript. Add auto-submit on top javascript if preferred.
We have a tool that sends me an email with a single use link when it's used.
I just now confirmed that I receive the email containing the single-use link, that I can click on it and view the page, and that the single-use link is no longer available after I've viewed the link.
Is this perhaps conditional behavior of some sort?
As mentioned in another comment: this is one of the reasons I laughed when they made a grab for everyone's phone numbers, claiming it was to prevent people from haxxoring your account.
But the messages could be interesting.
If there's literally no value in taking it over, then why password protect it in the first place?
I have an online photo album and while I could password protect it and share the password with people that I want to share it with, there's very little value (perhaps there's some small social engineering value) in protecting it. If there's no value in exposing it, why bother password protecting it?
Did you mean that it's valuable enough that someone should protect it, but shouldn't bother protecting it too much (like, anyone with the URL should have access to it) since it has little value? I'm not sure I really understand the nuance, but I'd be awfully surprised if I forwarded an email to someone from OKCupid and it gave them passwordless access to the account.
Even at a lower level, just sending a bunch of messages asking for money for a cab/train/airfare might yield good returns. People let their guard down when there's a possibility of getting laid.
You may say that getting exposed for trying to have an affair is a good thing, but that's a still a reason why someone may care how secure their OKCupid activity is.
In other nations, it may not be strictly illegal, but is more than enough information that, if publicly released, would result in death threats and other social pressures.