password-reset.txt
Implement password reset. Stack: <stack>.

Requirements, all of them:
- The token is random, long, and stored hashed — a database leak must
  not let someone reset every account.
- Single use, and expires in <30-60> minutes.
- The "check your email" response is identical whether or not the
  address exists. Don't leak which addresses are registered.
- Resetting invalidates existing sessions.
- Rate limited per address and per IP.
- The email says who requested it and what to do if it wasn't them.

Tell me what an attacker tries against this and which rule stops it.

The identical-response rule is the one most often skipped. A reset form that says "no account found" is a tool for discovering who has an account.