4 ms·
in that case you don't send them a randomly generated string called a password but a randomly generated string called a token, right?
by premek 5y ago
in that case you don't send them a randomly generated string called a password but a randomly generated string called a token, right?
- ThePowerOfFuet 5y agoCorrect, but it's generated only when they initiate the reset-password flow, and should be time-limited and only usable once. It's not stored in the database for long periods.