6 Replies - 2368 Views - Last Post: 27 January 2016 - 07:02 AM Rate Topic: -----

#1 wseng92  Icon User is offline

  • D.I.C Regular

Reputation: 9
  • View blog
  • Posts: 312
  • Joined: 23-September 15

Send a reset password request to e-mail from android

Posted 27 January 2016 - 06:08 AM

Hey guys, I'm new to android here :gun_bandana:

I have developed a login form (username,password and submit button) using a MySQL connection through php in my android application. Now I'm trying to send a password (stored in MySQL) to e-mail if user forgotten their password.

I've been searched for this for an hour but can't find a tutorial on this. Someone told that sending a password to e-mail is not advisable since it may be hacked by other users, use reset instead of recovery.

What are the best way to solve this ? Can someone give me a hints or some useful example for me to refer ? Thanks. :bananaman:

Is This A Good Question/Topic? 0
  • +

Replies To: Send a reset password request to e-mail from android

#2 no2pencil  Icon User is online

  • Professor Snuggly Pants
  • member icon

Reputation: 6580
  • View blog
  • Posts: 30,734
  • Joined: 10-May 07

Re: Send a reset password request to e-mail from android

Posted 27 January 2016 - 06:23 AM

The way I've always approached this in the past with PHP, is to not deal with the client side. Dealing only with pre-authenticated values, from the server flip some database values : validated from true to false, reset the password to junk, & then create a reset key/hash. Then send to the authenticated client email a URL with GET VALUES including the reset key/hash. Once they click that link, capture the IP, force them to create a new password, & then flip validated from false back to true. While validated is false, don't allow the account to login, which they won't be able to do anyhow, as their password is now garbage.

Again, this has nothing to do with mobile/Android development, but in my opinion, you shouldn't be dealing with server side items in your app. Only the transfer to the credentials. All of what I suggested above should be handled by the server & administration code.
Was This Post Helpful? 0
  • +
  • -

#3 wseng92  Icon User is offline

  • D.I.C Regular

Reputation: 9
  • View blog
  • Posts: 312
  • Joined: 23-September 15

Re: Send a reset password request to e-mail from android

Posted 27 January 2016 - 06:37 AM

View Postno2pencil, on 27 January 2016 - 06:23 AM, said:

The way I've always approached this in the past with PHP, is to not deal with the client side. Dealing only with pre-authenticated values, from the server flip some database values : validated from true to false, reset the password to junk, & then create a reset key/hash. Then send to the authenticated client email a URL with GET VALUES including the reset key/hash. Once they click that link, capture the IP, force them to create a new password, & then flip validated from false back to true. While validated is false, don't allow the account to login, which they won't be able to do anyhow, as their password is now garbage.

Again, this has nothing to do with mobile/Android development, but in my opinion, you shouldn't be dealing with server side items in your app. Only the transfer to the credentials. All of what I suggested above should be handled by the server & administration code.



Thanks for your prompt reply. Do you know where can I find such useful tutorial ? :dontgetit:
Was This Post Helpful? 0
  • +
  • -

#4 no2pencil  Icon User is online

  • Professor Snuggly Pants
  • member icon

Reputation: 6580
  • View blog
  • Posts: 30,734
  • Joined: 10-May 07

Re: Send a reset password request to e-mail from android

Posted 27 January 2016 - 06:41 AM

Being that this is my own solution, no. Additionally I'll add (again) since this is the mobile app section, I have no clear indication of what server side language you are using. So you're asking for a tutorial that covers............... what language, exactly?
Was This Post Helpful? 0
  • +
  • -

#5 wseng92  Icon User is offline

  • D.I.C Regular

Reputation: 9
  • View blog
  • Posts: 312
  • Joined: 23-September 15

Re: Send a reset password request to e-mail from android

Posted 27 January 2016 - 06:45 AM

View Postno2pencil, on 27 January 2016 - 06:41 AM, said:

Being that this is my own solution, no. Additionally I'll add (again) since this is the mobile app section, I have no clear indication of what server side language you are using. So you're asking for a tutorial that covers............... what language, exactly?


I'm connecting android with php and MySQL. I found this but it not enough for me
Was This Post Helpful? 0
  • +
  • -

#6 no2pencil  Icon User is online

  • Professor Snuggly Pants
  • member icon

Reputation: 6580
  • View blog
  • Posts: 30,734
  • Joined: 10-May 07

Re: Send a reset password request to e-mail from android

Posted 27 January 2016 - 06:49 AM

** Moved to PHP **

Assuming that you've not taken the time to look over our PHP tutorials, this tutorial is like the 2nd one listed on the page.
Was This Post Helpful? 0
  • +
  • -

#7 wseng92  Icon User is offline

  • D.I.C Regular

Reputation: 9
  • View blog
  • Posts: 312
  • Joined: 23-September 15

Re: Send a reset password request to e-mail from android

Posted 27 January 2016 - 07:02 AM

View Postno2pencil, on 27 January 2016 - 06:49 AM, said:

** Moved to PHP **

Assuming that you've not taken the time to look over our PHP tutorials, this tutorial is like the 2nd one listed on the page.



Thanks... :gunsmilie:
Was This Post Helpful? 0
  • +
  • -

Page 1 of 1