Looking for a some good options to send users reset password emails

后端 未结 2 342
面向向阳花
面向向阳花 2020-12-16 07:57

I want to send emails to users when the forget their passwords that prompt them to reset their passwords. I know this is debatable and was looking for a few good options/sug

2条回答
  •  甜味超标
    2020-12-16 08:23

    There is a danger of loosing out the url to anyone who sniffs network. To avoid this, you may generate a random short key such as vX4dq and save it in your database. Ask user to remember this. When a user resets via the link, ask him/her to enter this key only known to him.

    Advanced :- you may show this key in a captcha so that it doesn't get sniffed.

提交回复
热议问题