[P2] Add password reset tokens #152
Labels
backend
Related to server / worker code
enhancement
New feature or request
help wanted
Extra attention is needed
Summary
Since we removed email-based forgot password flows (see
git log
for original code), we should add an alternative system for password resets. One way to do this is with "recovery tokens", as seen on sites with MFA flows. We could give a user one recovery token which can be used to validate a one-time password reset, which then grants a new recovery token. These could be stored as(user_id, token)
in a new Postgres table, and can be deleted after successful use.The text was updated successfully, but these errors were encountered: