This makes more sense, random users being able to request RESETS. I agree sending a time bound link to registered email is better.
What type of token generation mechanism would you use to send with the link to identify a user or to make sure that the link is being requested by the right user.