Pengaturan Ulang Kata Sandi dan Verifikasi Email
Bangun alur pemulihan akun dan verifikasi email yang aman menggunakan token sekali pakai, masa kedaluwarsa, dan email transaksional agar pengguna dapat memperoleh kembali akses dengan aman.
Pengaturan Ulang Kata Sandi dan Verifikasi Email adalah pelajaran AI Powered SaaS: Stripe + Auth + Billing + Deploy gratis di CoddyKit. Ini adalah pelajaran 4 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar AI Powered SaaS: Stripe + Auth + Billing + Deploy, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus AI Powered SaaS: Stripe + Auth + Billing + Deploy mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Why Reset & Verify?
Users forget passwords and mistype emails. A safe password reset flow lets them recover without support, and email verification confirms the address really belongs to them, cutting spam and fake accounts.
The Token Strategy
Both flows rely on a one-time token: a random, unguessable string emailed to the user. Possessing it proves control of the inbox.
import crypto from 'crypto';
const token = crypto.randomBytes(32).toString('hex');Storing the Token Hashed
Never store the raw token. Hash it before saving so a database leak cannot be used to reset accounts. Compare hashes when the user returns.
const hash = crypto.createHash('sha256').update(token).digest('hex');
await prisma.resetToken.create({
data: { userId, hash, expiresAt }
});Adding Expiry
Tokens must expire — usually 15 to 60 minutes. Store an expiresAt timestamp and reject tokens past it.
const expiresAt = new Date(Date.now() + 30 * 60 * 1000);Requesting a Reset
The user submits their email. Generate a token, save its hash, and email a link containing the raw token. Always respond the same way to avoid leaking which emails exist.
const link = process.env.APP_URL + '/reset?token=' + token;
await sendEmail(email, 'Reset your password', link);Sending Transactional Email
Use a provider like Resend or SendGrid for reliable delivery. Keep the message short with a clear single action.
import { Resend } from 'resend';
const resend = new Resend(process.env.RESEND_API_KEY);
await resend.emails.send({ to, subject, html });Verifying the Token
When the user opens the link, hash the incoming token, look it up, and check it is unused and unexpired.
const hash = crypto.createHash('sha256').update(token).digest('hex');
const record = await prisma.resetToken.findFirst({
where: { hash, expiresAt: { gt: new Date() }, usedAt: null }
});Updating the Password
If valid, hash the new password and save it, then mark the token used so it cannot be replayed.
const pw = await bcrypt.hash(newPassword, 12);
await prisma.user.update({ where: { id: record.userId }, data: { password: pw } });
await prisma.resetToken.update({ where: { id: record.id }, data: { usedAt: new Date() } });Email Verification Flow
Verification works the same way: on signup, email a token. When clicked, set emailVerified on the user and invalidate the token.
await prisma.user.update({
where: { id }, data: { emailVerified: new Date() }
});Preventing Abuse
Protect these endpoints:
- Rate limit reset requests
- Give identical responses for known and unknown emails
- Allow only one active token per user
Best Practices
Build recovery securely:
- Use random, hashed tokens with expiry
- Send via a transactional email provider
- Mark tokens used after one use
- Rate limit and avoid email enumeration
Quick Check
Test your reset-flow knowledge.
Recap
You built account recovery:
- Generate random tokens, store them hashed with expiry
- Email links via a transactional provider
- Verify, then update the password and mark the token used
- Reuse the pattern for email verification and guard against abuse
Users can now safely recover and verify accounts.
Belajar AI Powered SaaS: Stripe + Auth + Billing + Deploy dengan tutor AI — gratis
Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.
- Kursus
- 12
- Pelajaran
- 48
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Pengaturan Ulang Kata Sandi dan Verifikasi Email” gratis?
Ya — teks lengkap “Pengaturan Ulang Kata Sandi dan Verifikasi Email” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus AI Powered SaaS: Stripe + Auth + Billing + Deploy, upgrade ke CoddyKit PRO. Kursus AI Powered SaaS: Stripe + Auth + Billing + Deploy mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Pengaturan Ulang Kata Sandi dan Verifikasi Email”?
Bangun alur pemulihan akun dan verifikasi email yang aman menggunakan token sekali pakai, masa kedaluwarsa, dan email transaksional agar pengguna dapat memperoleh kembali akses dengan aman. Kamu berlatih AI Powered SaaS: Stripe + Auth + Billing + Deploy dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai AI Powered SaaS: Stripe + Auth + Billing + Deploy?
Tidak diperlukan pengalaman sebelumnya. AI Powered SaaS: Stripe + Auth + Billing + Deploy di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 4 dari 4.
Berapa lama pelajaran “Pengaturan Ulang Kata Sandi dan Verifikasi Email” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran AI Powered SaaS: Stripe + Auth + Billing + Deploy ini?
Ya. Setiap pelajaran AI Powered SaaS: Stripe + Auth + Billing + Deploy menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Registrasi Pengguna & Hashing
- Login & Pembuatan JWT
- Rute Terlindungi & Middleware
- Pengaturan Ulang Kata Sandi dan Verifikasi Email