KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I was wondering what would be the safer option when users have forgotten their password Send a randomly generated new password to the email address (all email addresses in my database are confirmed to work). Or Send an email with a link that expires within a certain time frame where the user can reset their password. Aside from the fact the latter uses an extra table, what do you think is safer/better practice?
Tags (comma-separated)
Save Edits
Cancel