3 ms·
mschwaig replied with the answer above [0]: use the old password hash when creating the token. For an example in the wild, see how Django does it[1]. 0. https:
by aptwebapps 12y ago
mschwaig replied with the answer above [0]: use the old password hash when creating the token. For an example in the wild, see how Django does it[1].
0. https://news.ycombinator.com/item?id=9055749 https://news.ycombinator.com/item?id=9055749
1. https://github.com/django/django/blob/master/django/contrib/auth/tokens.py https://github.com/django/django/blob/master/django/contrib/...
- jholman 12y agoThank you for the reply, and once I read it enough times in a row, I got it through my thick head. It's still not clear to me, however, how to generalize this technique to create limited-use links that are not necessarily for resetting passwords.
- aptwebapps 12y agoIf you want to have limited-use links that don't cause any writes to the db, then no, you can't with this approach. All it does is use an already necessary db write, the password change, to avoid adding another one, a token.