Request new password
Brought to you by:
lovellb
Currently, anyone who knows a user's accountname, can
request and create a new password.
The new password is then sent to the user's e-mail.
Request:
Could a verification be sent first to the e-mail, with
a link containing a parameter. When the user presses
the link, only then a new password is generated ?
Logged In: YES
user_id=606772
Originator: NO
Easy. Just needs a token that has a life of say 24 hours.