Document the Devise related vulnerabilities: - Password complexity - Devise token in source - No post password change email - No lockout