mysql - How to update DB records using a dynamically generated link -
i have requirement generate email administrator whenever user sign up. administrator approve registration clicking on link provided in email , database should updated, without admin login administrator console.
i looking best practice code scenario keeping application security intact. can generate email dynamic rendom value attached link(provided in email) url, not sure how keep track of on application side?
any thoughts?
you generate random validation number when user signs up, , store in database user record. generate email link such
http://foo.bar.com/approveuser.action?userid=<theuserid>&validationtoken=<therandomnumber>
when approveuser
action invoked, check if validation token stored in database given user id matches token sent parameter, , if so, approve user.
Comments
Post a Comment