Unused Rails Routes Command Discussion
It should be fine if the tokens are one-time use, have an expiration date, and the user's email isn't compromised. For further peace of mind, you should still use two-factor authentication (2FA).
You’re not receiving notifications from this thread.
It should be fine if the tokens are one-time use, have an expiration date, and the user's email isn't compromised. For further peace of mind, you should still use two-factor authentication (2FA).