I had to implement a "forgot password" feature in a web application. I implemented it via:
1) Take the user's email
2) Generate a 6 digit code
3) Send the code to the email
4) Send the hash of the code to the frontend and save it in local storage
5) Compare the code from user which they get via email to the hash in local storage
Someone could change the hash in the local storage and bypass this.Of course, I reverted to use Redis instead of local storage for this after like 3 days, fortunately with no mishaps.
I've since then made up my mind to not implement bad workarounds like this because it just felt so wrong.