Instead of reseting the password, send the user (through email) a unique link that will allow him to reset the password. <!--- @huboard:{"order":1.479114197289397e-29,"milestone_order":1.125} -->