It would be great if activator checks that the reset password token can be used only once. As you suggest in [issue #67](https://github.com/deitch/activator/issues/67), including the hash of the current password in the reset password token sounds great to me.