Implement reset password action and emails.
- The email should contain a link to a URL with an reset token present.
- The token should expire 24 hours after being created.
- If the user did not request the email, they should be instructed to ignore the email or change their password.