Currently a new password is sent immediately upon request in then login module. With that just anybody can reset the password for every single user since the emails are publicly available on my site which is a business directory. I would need a double opt in for the password reset so that only after receiving the request validation the account owner can initiate the reset.
CB 2.0