Every stale reset link produced a bare 'Ungültiges Token', which sent users into a loop of requesting ever more e-mails. The overridden core messages now explain that only the link from the newest e-mail counts, the auth message template offers a direct 'Neuen Link anfordern' button, and the change-password page asks for the 'Aktuelles Passwort' with a hint covering freshly reset passwords. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>