Personally, I have this particular bit of appsec down cold, and if I was building a new app, I wouldn't even think about it: I'd use a random token and save it in the database.
Personally, I have this particular bit of appsec down cold, and if I was building a new app, I wouldn't even think about it: I'd use a random token and save it in the database.
I wouldn't roll my own password reset feature if I can just take the builtin one from Django, which is what I did.
Note though that that's not the case for 3rd-party password reset libraries or, more likely, the all-purpose security library that provides it. I'd be very wary about using a 3rd party library for password reset unless they've got a credible for story for it having been reviewed.
Django: Good.
3rd Party Library: Less Good
Just Using A Random Token: Good
Cryptography: You Will Perish In Flames
Asking this since it's probably the most widely used authentication gem in Rails etc...