Opening the shared document…
Diagram playground
Write a diagram as text and it renders here as you type. Canvas editing for six of ten notations. Nothing leaves your browser. Syntax reference ·
1
archlab 1.0 sequence
2
title "Password reset — one-time link"
3
description "A reset that survives a lost inbox: the link is single-use and the old session dies."
4
5
@sequence
6
autonumber
7
user:actor "Account holder"
8
web "Web App" [Next.js]
9
auth:participant "Auth Service" [Go]
10
store:participant "Token Store" [Redis]
11
mail:participant "Email Provider" [Postmark]
12
13
user -> web : "Requests a reset"
14
web ->+ auth : "Ask for a reset link" [HTTPS]
15
desc "POST /api/v1/reset-requests\nbody { email }\n202 always — the response cannot say whether the address exists"
16
auth -> store : "SET token, ttl 15m" [RESP]
17
auth ~> mail : "Send reset link" [SMTP]
18
auth ..>- web : "202 Accepted"
19
note over web user : "Same response whether or not the address exists"
20
loop "until the link is used or expires"
21
user -> web : "Opens the emailed link"
22
web ->+ auth : "POST /reset-confirmations" [HTTPS]
23
auth -> store : "GETDEL token" [RESP]
24
alt "token valid"
25
auth -> auth : "Hashes the new password"
26
auth ~> store : "Revoke every session"
27
auth ..>- web : "200 OK"
28
web -> user : "Signed in with the new password"
29
else "token missing or expired"
30
auth ..>- web : "410 Gone"
31
web -> user : "Asks for a fresh reset"
Tab indents · Esc then Tab leaves the editor · syntax reference
Read-only
- Account holder to Web App (solid line with an arrowhead): Requests a reset
- Web App to Auth Service (solid line with an arrowhead): Ask for a reset link [HTTPS]
- Auth Service to Token Store (solid line with an arrowhead): SET token, ttl 15m [RESP]
- Auth Service to Email Provider (solid line with an open head): Send reset link [SMTP]
- Auth Service to Web App (dotted line with an arrowhead): 202 Accepted
- Account holder to Web App (solid line with an arrowhead): Opens the emailed link
- Web App to Auth Service (solid line with an arrowhead): POST /reset-confirmations [HTTPS]
- Auth Service to Token Store (solid line with an arrowhead): GETDEL token [RESP]
- Auth Service to Auth Service (solid line with an arrowhead, self-message): Hashes the new password
- Auth Service to Token Store (solid line with an open head): Revoke every session
- Auth Service to Web App (dotted line with an arrowhead): 200 OK
- Web App to Account holder (solid line with an arrowhead): Signed in with the new password
- Auth Service to Web App (dotted line with an arrowhead): 410 Gone
- Web App to Account holder (solid line with an arrowhead): Asks for a fresh reset