3 ms·
If that's the case, then why not hash the entire token and store hash(token) in the database. Then you can just query for: SELECT tokenid, userid FROM pass
by foo101 10y ago
If that's the case, then why not hash the entire token and store hash(token) in the database. Then you can just query for:
SELECT tokenid, userid FROM password_reset_tokens WHERE hashed_token = :hashed_token AND NOW() < expire_time
If you are worried that two tokens may collide to have the same hash, well that problem is there with your split-token solution too where token1 and token2 may collide such that token1 and token2 have the same selector and the same hash(verifier).