3 ms·
This makes more sense, random users being able to request RESETS. I agree sending a time bound link to registered email is better. What type of token generatio
by retrofit_brain 15y ago
This makes more sense, random users being able to request RESETS. I agree sending a time bound link to registered email is better.
What type of token generation mechanism would you use to send with the link to identify a user or to make sure that the link is being requested by the right user.
- drivebyacct2 15y agoI can't think of anything in particular you'd need to worry about. Something long enough that it would be infeasible to try and attack. We just use GUIDs, but those may be predictable if you know the generation time (I'm not sure about that, to be honest).
- dav-id 15y agoI do exactly the same thing. The guid is set to expire after a period of time and requires that registered email and the key together. It won't allow login, only changing of their password.