I'd add:
* Not requiring any additional authentication once you have the reset link from the e-mail
even reddit is vulnerable to this:
https://np.reddit.com/r/funny/comments/3egphk/icets_seen_som...
* Not requiring any additional authentication once you have the reset link from the e-mail
even reddit is vulnerable to this:
https://np.reddit.com/r/funny/comments/3egphk/icets_seen_som...
It's fairly common to see reset tokens going in to the database verbatim, instead of treating them as passwords and stashing away a hash (single SHA is fine if your tokens are long and random).