Password reset — one-time link
A reset that survives a lost inbox: the link is single-use and the old session dies.
Click a message, participant, or fragment chip to focus it · a after a label means that message carries details · ← → move between messages · Ctrl + scroll or pinch to zoom · Esc clears focus · on a card folds away the services only it uses
- Account holder to Web App (sync): Requests a reset
- Web App to Auth Service (sync): Ask for a reset link [HTTPS]
- Auth Service to Token Store (sync): SET token, ttl 15m [RESP]
- Auth Service to Email Provider (async): Send reset link [SMTP]
- Auth Service to Web App (reply): 202 Accepted
- Account holder to Web App (sync): Opens the emailed link
- Web App to Auth Service (sync): POST /reset-confirmations [HTTPS]
- Auth Service to Token Store (sync): GETDEL token [RESP]
- Auth Service to Auth Service (sync, self-message): Hashes the new password
- Auth Service to Token Store (async): Revoke every session
- Auth Service to Web App (reply): 200 OK
- Web App to Account holder (sync): Signed in with the new password
- Auth Service to Web App (reply): 410 Gone
- Web App to Account holder (sync): Asks for a fresh reset