npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@itrocks/forgot-password

v0.4.0

Published

Forgot password management for @itrocks/user, including form, token generation, email sending, and secure reset

Readme

npm version npm downloads GitHub issues discord

forgot-password

Forgot password management for @itrocks/user, including form, token generation, email sending, and secure reset.

Requirements

  • Node.js 24 or newer.
  • An application using @itrocks/user.
  • An SMTP server configured through the shared smtp application configuration.

Installation

npm i @itrocks/forgot-password

The package contributes the public /user/forgot-password route through its config.yaml file. The it.rocks framework loads dependency configuration files automatically.

Usage

Configure the same SMTP source used by the rest of the application:

smtp:
  from:
    email: [email protected]
    name: Example
  host: smtp.example.com
  pass: "<SMTP_PASSWORD>"
  port: 465
  secure: true
  user: [email protected]

Opening /user/forgot-password displays the recovery form. Submitting an email always produces the same public response, whether the address exists, delivery fails, or the message is sent.

For a matching account, the action:

  1. creates a random one-hour token;
  2. stores only its SHA-256 fingerprint;
  3. sends the raw token once in an SMTP email;
  4. accepts one password reset before deleting the token.

Concurrent reset attempts are serialized by a unique persisted consumption record. Only one attempt can change the password.

API

Forgot

class Forgot<T extends User = User> extends Action<T> {
	async html(request: Request<T>): Promise<HtmlResponse>
}

Implements the HTML request, email delivery, token validation and password reset steps. The framework normally instantiates this action from the contributed route.

Dependencies

See dependency configuration for password-change lifecycle hooks and framework integration.