Password reset, done safely
A well-known flow with a well-known set of mistakes.
Implement password reset. Stack: <stack>. Requirements, all of them: - The token is random, long, and stored hashed — a database leak must not let someone reset every account. - Single use, and expires in <30-60> minutes. - The "check your email" response is identical whether or not the address exists. Don't leak which addresses are registered. - Resetting invalidates existing sessions. - Rate limited per address and per IP. - The email says who requested it and what to do if it wasn't them. Tell me what an attacker tries against this and which rule stops it.
The identical-response rule is the one most often skipped. A reset form that says "no account found" is a tool for discovering who has an account.