Secure ways to reset password or to give old password

前端 未结 3 465
盖世英雄少女心
盖世英雄少女心 2021-01-02 12:13

What is the most secure way to handle forgotten passwords/password resets? Should I email the password to the user? If so do you then force them to reset it? Or do you let t

3条回答
  •  不知归路
    2021-01-02 12:40

    I suppose you are going to do it programmatically? Or is it a question for Server Fault?

    One of the ways is to send a link to the user's email account. He/she clicks on the link and is redirected to your secure web form where they reset the password.

    Do NOT email the password to the user

提交回复
热议问题