Forgot Password Workflow (Frontend + Backend) - #1799
Merged
Conversation
|
@Aditya8369 is attempting to deploy a commit to the Om Roy's projects Team on Vercel. A member of the Team first needs to authorize it. |
Thanks for creating a PR for your Issue!
|
Contributor
Author
|
@omroy07 merge under nsoc |
|
🎉 Congrats @Aditya8369 on getting your PR merged! 🙌 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The flow is wired end to end now. I’m not making more changes unless validation uncovers a concrete defect, because the remaining risk is operational mail configuration rather than the reset workflow itself.
Implemented the forgot-password flow across backend and frontend.
The backend now persists reset tokens in token.py, uses them in the auth service, and exposes a validation endpoint at auth.py so the reset page can reject expired or invalid tokens before showing the form. The reset email now points at the frontend reset page, and the password update path still uses the existing secure hash update in the user model.
On the frontend, forgot-password.html now posts to the Flask forgot-password API instead of Firebase, and reset-password.html validates the token first, then submits the new password to the backend. I also normalized the theme persistence key on login.html and the forgot/reset pages so dark mode continues to carry across those auth screens.
closes #278