and also best practices?
1- Create a with a random password and force them to reset their password on first login.
2- Create without any password and send them a link to set their password (link has no expiration, but invalidate link after set password)
create without password but force to set one before using the API
so you mean latter?
just don't allow users with an incomplete account (password not yet set) to use API functions other than those that allow to complete the account
of course yes. admin creates a user, user receives a welcome message with reset password link. after reset their password they can login.
Обсуждают сегодня