Thanks for the suggestion, but I'm not understanding how forcing someone to change their password after it already has been changed will work.
The problem as I see it is:
Member forgets original password.
Member asks system to reset password.
Members gets stupid numeric password (SNP) that expires in 24 hours.
Member doesnot carefully read e-mail that says it is a temporary password.
Member tries again to use SAME numeric password that has expired.
Member then attempts to reset password, getting another stupid numeric password.
....and the process begins again.
What I want is to break the cycle.
Immediately after they log in using the SNP I want them to HAVE to reset to something that will work tomorrow and the next day and the next....
|