4 ms·
Hmm...interesting. Click wise it probably is less clicks and you are also forcing the user to change his password. Unless you add logic to ask the user to chang
by retrofit_brain 15y ago
Hmm...interesting. Click wise it probably is less clicks and you are also forcing the user to change his password. Unless you add logic to ask the user to change his password with one time token, it probably makes more sense to send a link to reset pwd.
- plasma 15y agoYou may want to look into using HMAC Urls (with a timed expiration date), see http://en.wikipedia.org/wiki/HMAC http://en.wikipedia.org/wiki/HMAC for a quick explanation. This lets you send a link like www.mysite.com/resetpassword?userid=123×tamp=...&hmac=.... without having to keep a database backed copy of 'reset password' emails and tracking sent links. You can make it so the link only works for say a few hours or any other combination of factors, the HMAC lets you 'sign' the URL you issue the user so it cannot be changed/forged, and you append a 'timestamp' argument to then let you determine if you consider the URL too old to take action on.
- ra 15y agoThat's a brilliant idea