Skip to content

Archive

Password Reset

2 articles
Cybersecurity 20 Sep 2026 6 min read

Password Reset Links Need a Trusted Public Origin

Password Reset Links Need a Trusted Public Origin A password reset email often contains one of the most sensitive URLs an application creates. Possession of a valid reset token may be enough to establish a new credential for the associated account, so the destination embedded in that URL is part of the security boundary. A common implementation mistake is to construct the absolute reset URL from host information carried by the incoming HTTP request. Headers such as Host exist for request routing, and deployments behind proxies may also expose forwarded host or scheme metadata. Unless the application has explicitly established which intermediary is trusted and which values are valid, that request metadata is not a safe source of authority for a security-sensitive outbound link.

Cybersecurity 02 Sep 2026 5 min read

Design Secure Password Reset Flows

Password reset is an authentication mechanism. Anyone who can complete the reset flow can usually take control of the account, so recovery deserves protections comparable to login. A secure design must prevent token guessing, account enumeration, replay, accidental disclosure, and long-lived takeover opportunities. Return the same public response A reset form often accepts an email address or username. Do not reveal whether that identifier exists. Prefer a response such as: