Quantcast
Channel: Best practice for resetting forgotten user passwords - Stack Overflow
Viewing all articles
Browse latest Browse all 4

Best practice for resetting forgotten user passwords

$
0
0

As far as I can think, there are two reasonable ways to reset a user's forgotten password.

  1. Have the user enter their email address and a new plaintext password is sent to their email address.

  2. A link is sent to their email address which has a UID number in the URL. Clicking on this takes the user to a form on the website where they can choose there own new password.

Which method is preferable and why?

If method 1 is used, perhaps a third party could read the email and obtain the new password.If method 2 is used, what is to stop someone methodically going through UID codes to try and access the form to change a user's password?


Viewing all articles
Browse latest Browse all 4

Latest Images

Trending Articles





Latest Images