Password Reset

View saved

Goal

This snapshot advances Cedarline Post by teaching you to issue expiring one-use password reset tokens.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Go 1.22+, a terminal, and a code editor. You should recognize packages, functions, and HTTP verbs.

Port 8081 must be free. Copy .env.example before starting. Stages from the data layer use a per-snapshot SQLite file (no Docker required).

  • Go 1.22 or newer
  • A code editor and terminal
  • Optional: Docker only if you prefer another database later

Concepts

Store a random token and expiry on the user. Locally print the link to the console instead of requiring SMTP.

Keep handlers thin: routes accept input, SQL and helpers enforce rules, and html/template escapes output by default.

Walkthrough

Create a forgot-password form, save a token, and complete the reset only when the token is valid and unexpired.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

token := randomHex(24)
db.Exec(`UPDATE users SET reset_token=?, reset_expires=? WHERE id=?`, token, time.Now().UTC().Add(time.Hour), u.ID)

Run and verify

Enter 11-Password-Reset, copy .env.example, run go mod tidy, and start the server on port 8081.

Open http://127.0.0.1:8081. Watch the terminal for validation and database errors.

git clone https://github.com/michaeldunga1/fcc-go-blog.git
cd fcc-go-blog/11-Password-Reset
cp .env.example .env
go mod tidy
go run .

Troubleshooting

Always show a generic success message so attackers cannot probe which emails exist.

Missing module errors usually mean go mod tidy was not run in this snapshot. For SQLite failures, delete a corrupt *.db file and restart so migrate/seed can recreate it.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or *.db

Try this

Request a reset for Ada and complete it from the console link.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Deploy

Comments

One comment per signed-in account. Comments are saved with this page’s URL.