Replace the broken csrf_exempt handler (responses never returned) with a working DRF endpoint, use FRONTEND_BASE_URL for reset links, and harden set-password against reuse and short passwords.
Replace the broken csrf_exempt handler (responses never returned) with a working DRF endpoint, use FRONTEND_BASE_URL for reset links, and harden set-password against reuse and short passwords.