0Pricing
AI Powered SaaS: Stripe + Auth + Billing + Deploy · درس

إعادة تعيين كلمة المرور والتحقق من البريد الإلكتروني

ابنِ تدفقات آمنة لاستعادة الحساب والتحقق من البريد الإلكتروني باستخدام الرموز أحادية الاستخدام، وانتهاء الصلاحية، والبريد الإلكتروني transactional، ليتمكن المستخدمون من استعادة الوصول بأمان.

إعادة تعيين كلمة المرور والتحقق من البريد الإلكتروني درس مجاني في AI Powered SaaS: Stripe + Auth + Billing + Deploy على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في AI Powered SaaS: Stripe + Auth + Billing + Deploy، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة AI Powered SaaS: Stripe + Auth + Billing + Deploy 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Why Reset & Verify?

Users forget passwords and mistype emails. A safe password reset flow lets them recover without support, and email verification confirms the address really belongs to them, cutting spam and fake accounts.

The Token Strategy

Both flows rely on a one-time token: a random, unguessable string emailed to the user. Possessing it proves control of the inbox.

import crypto from 'crypto';
const token = crypto.randomBytes(32).toString('hex');

Storing the Token Hashed

Never store the raw token. Hash it before saving so a database leak cannot be used to reset accounts. Compare hashes when the user returns.

const hash = crypto.createHash('sha256').update(token).digest('hex');
await prisma.resetToken.create({
  data: { userId, hash, expiresAt }
});

Adding Expiry

Tokens must expire — usually 15 to 60 minutes. Store an expiresAt timestamp and reject tokens past it.

const expiresAt = new Date(Date.now() + 30 * 60 * 1000);

Requesting a Reset

The user submits their email. Generate a token, save its hash, and email a link containing the raw token. Always respond the same way to avoid leaking which emails exist.

const link = process.env.APP_URL + '/reset?token=' + token;
await sendEmail(email, 'Reset your password', link);

Sending Transactional Email

Use a provider like Resend or SendGrid for reliable delivery. Keep the message short with a clear single action.

import { Resend } from 'resend';
const resend = new Resend(process.env.RESEND_API_KEY);
await resend.emails.send({ to, subject, html });

Verifying the Token

When the user opens the link, hash the incoming token, look it up, and check it is unused and unexpired.

const hash = crypto.createHash('sha256').update(token).digest('hex');
const record = await prisma.resetToken.findFirst({
  where: { hash, expiresAt: { gt: new Date() }, usedAt: null }
});

Updating the Password

If valid, hash the new password and save it, then mark the token used so it cannot be replayed.

const pw = await bcrypt.hash(newPassword, 12);
await prisma.user.update({ where: { id: record.userId }, data: { password: pw } });
await prisma.resetToken.update({ where: { id: record.id }, data: { usedAt: new Date() } });

Email Verification Flow

Verification works the same way: on signup, email a token. When clicked, set emailVerified on the user and invalidate the token.

await prisma.user.update({
  where: { id }, data: { emailVerified: new Date() }
});

Preventing Abuse

Protect these endpoints:

  • Rate limit reset requests
  • Give identical responses for known and unknown emails
  • Allow only one active token per user

Best Practices

Build recovery securely:

  • Use random, hashed tokens with expiry
  • Send via a transactional email provider
  • Mark tokens used after one use
  • Rate limit and avoid email enumeration

Quick Check

Test your reset-flow knowledge.

Recap

You built account recovery:

  • Generate random tokens, store them hashed with expiry
  • Email links via a transactional provider
  • Verify, then update the password and mark the token used
  • Reuse the pattern for email verification and guard against abuse

Users can now safely recover and verify accounts.

الأسئلة الشائعة

هل درس «إعادة تعيين كلمة المرور والتحقق من البريد الإلكتروني» مجاني؟

نعم — نص درس «إعادة تعيين كلمة المرور والتحقق من البريد الإلكتروني» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة AI Powered SaaS: Stripe + Auth + Billing + Deploy، انتقل إلى CoddyKit PRO. تتضمن دورة AI Powered SaaS: Stripe + Auth + Billing + Deploy 4 دروس في المجموع.

ماذا ستتعلم في «إعادة تعيين كلمة المرور والتحقق من البريد الإلكتروني»؟

ابنِ تدفقات آمنة لاستعادة الحساب والتحقق من البريد الإلكتروني باستخدام الرموز أحادية الاستخدام، وانتهاء الصلاحية، والبريد الإلكتروني transactional، ليتمكن المستخدمون من استعادة الوصول بأمان. تتمرن على AI Powered SaaS: Stripe + Auth + Billing + Deploy مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ AI Powered SaaS: Stripe + Auth + Billing + Deploy؟

لا تُشترط خبرة سابقة. AI Powered SaaS: Stripe + Auth + Billing + Deploy على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «إعادة تعيين كلمة المرور والتحقق من البريد الإلكتروني»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس AI Powered SaaS: Stripe + Auth + Billing + Deploy هذا؟

نعم. كل درس في AI Powered SaaS: Stripe + Auth + Billing + Deploy يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. تسجيل المستخدمين والتجزئة
  2. تسجيل الدخول وإنشاء JWT
  3. المسارات المحمية والبرمجيات الوسيطة
  4. إعادة تعيين كلمة المرور والتحقق من البريد الإلكتروني
← العودة إلى AI Powered SaaS: Stripe + Auth + Billing + Deploy