Password reset emails usually contain a token that expires rather quickly so unless I’m missing something, this should be a non-issue.
But you can generate such emails with a public username
But you can generate such emails with a public username