Links that expire can be found anywhere from Email Verification to Password Reset procedures, I understand in most cases this is considered "security theater", but wanted to know what a viable time-frame is for a link to be valid?
Is 10-15 minutes acceptable? With all the unknown factors of email delays etc?
Is a shorter duration considered more secure? Thanks.