3 ms·
I just gave django.contrib.auth.tokens a read and shared my opinion on it :) I wouldn't roll my own password reset feature if I can just take the builtin one f
by wulczer 14y ago
I just gave django.contrib.auth.tokens a read and shared my opinion on it :)
I wouldn't roll my own password reset feature if I can just take the builtin one from Django, which is what I did.
- tptacek 14y agoThe good thing about taking your web stack's password reset feature, if it has one, is that you're probably going to find out quickly if there's a bug discovered in it. Note though that that's not the case for 3rd-party password reset libraries or, more likely, the all-purpose security library that provides it. I'd be very wary about using a 3rd party library for password reset unless they've got a credible for story for it having been reviewed. Django: Good. 3rd Party Library: Less Good Just Using A Random Token: Good Cryptography: You Will Perish In Flames
- thibaut_barrere 14y agoDoes Devise [1] qualifies as a properly reviewed 3rd Party Library, to your knowledge? Asking this since it's probably the most widely used authentication gem in Rails etc... [1] https://github.com/plataformatec/devise https://github.com/plataformatec/devise