No nonce is generated and nothing is stored. The user is emailed a link with her user ID and a token that's a hash of (last login timestamp + the user's ID + the user's (hashed) password + current timestamp). The token is HMAC-signed with the site's secret key.
This way the token automatically expires if the user either successfully changes her password (the password hash will change) or manages to log in (last login timestamp changes).
It seems that in Django password reset tokens are valid forever, but it would be trivial to add the current timestamp to the token and include it when computing the HMAC signature; then the password reset form would check if the token has been generated recently enough.
I like this method because you never need to touch the database and store tokens; it's all fairly stateless.