Parse Server密码重置:如何获取验证Token?
Got it, let's break this down for you. The core issue here is that Parse Server doesn't store password reset tokens directly in the User class documents—that's why you can't find it in the Parse Dashboard. Instead, these tokens live in a dedicated system collection, which defaults to _PasswordResetToken (if you're using MongoDB; it'll be a corresponding table for databases like PostgreSQL).
That said, querying this system collection directly isn't the recommended approach. Parse provides built-in, secure ways to validate reset tokens without digging into underlying storage. Here's how to do it properly:
Option 1: Validate via Parse Cloud Code
Write a Cloud Code function that takes the username and token from your URL, then leverages Parse's native validation logic:
Parse.Cloud.define("verifyPasswordResetToken", async (request) => { const { username, token } = request.params; try { // Use Parse's built-in method to verify the token and username match const user = await Parse.User.requestPasswordResetVerify(token, username); // Return success and user ID if validation passes return { success: true, userId: user.id }; } catch (error) { // Return error details if validation fails (e.g., invalid/expired token) return { success: false, error: error.message }; } });
Then, from your custom reset page, call this Cloud Function to confirm the token's validity—no need to mess with system collections directly.
Option 2: Validate via Parse REST API
If you prefer not to use Cloud Code, you can call Parse's REST API directly to verify the token:
Send a POST request to your Parse Server endpoint:
POST /parse/functions/requestPasswordResetVerify
Request body (JSON):
{ "token": "your-reset-token-from-url", "username": "username-from-url" }
Don't forget to include your app credentials in the request headers: X-Parse-Application-Id and (if configured) X-Parse-REST-API-Key.
Why avoid querying _PasswordResetToken directly?
- Security risks: Directly accessing system collections can introduce permission gaps, and Parse's internal storage structure might change with updates, breaking your code.
- Built-in expiration handling: Parse automatically manages token expiration, and the native validation methods will check this for you—you'd have to implement that logic yourself if querying the collection directly.
One last note: Once a user successfully resets their password, Parse automatically deletes the corresponding _PasswordResetToken entry, so you don't have to worry about cleaning up old tokens manually.
内容的提问来源于stack exchange,提问作者David Yeiser

