No offense, but this isn't a new idea. I've built this feature into Flask-Security, a Flask extension I maintain.
Flask-Security looks like a good solution to every new web site having to roll their own code. BTW, It's not clear from Flask-Security that there is a no-password option given that the user model has a password field required.