A password reset link should go out at the bare minimum. The original reason that sites stopped sending passwords out is that an attacker the got control of an email account now potentially has a password that may be reused elsewhere. Things like not allowing the last N passwords as well as complexity requirements are considered par for the course these days.