Password reset — one-time link
A reset that survives a lost inbox: the link is single-use and the old session dies.
- Account holder to Web App (solid line with an arrowhead): Requests a reset
- Web App to Auth Service (solid line with an arrowhead): Ask for a reset link [HTTPS]
- Auth Service to Token Store (solid line with an arrowhead): SET token, ttl 15m [RESP]
- Auth Service to Email Provider (solid line with an open head): Send reset link [SMTP]
- Auth Service to Web App (dotted line with an arrowhead): 202 Accepted
- Account holder to Web App (solid line with an arrowhead): Opens the emailed link
- Web App to Auth Service (solid line with an arrowhead): POST /reset-confirmations [HTTPS]
- Auth Service to Token Store (solid line with an arrowhead): GETDEL token [RESP]
- Auth Service to Auth Service (solid line with an arrowhead, self-message): Hashes the new password
- Auth Service to Token Store (solid line with an open head): Revoke every session
- Auth Service to Web App (dotted line with an arrowhead): 200 OK
- Web App to Account holder (solid line with an arrowhead): Signed in with the new password
- Auth Service to Web App (dotted line with an arrowhead): 410 Gone
- Web App to Account holder (solid line with an arrowhead): Asks for a fresh reset