Add a "Forgot your password?" flow off the login page. A 24-hour reset_password token is emailed on request, the landing page lets the user pick a new password, and all other tokens for the user are revoked on success. The request endpoint returns the same flash regardless of whether the email matches a user so that attackers can't enumerate accounts. |
||
|---|---|---|
| .. | ||
| scope.ex | ||
| user.ex | ||
| user_notifier.ex | ||
| user_token.ex | ||