Patterns
Recover access
A request form and token-based reset serve both ordinary recovery and migrated accounts.
On this page
Task sequence
- Request a reset by email.
- Read the generic check-email guidance.
- Open the token reset route from the email.
- Set a new password and sign in.
Data and persistence
Reset requests create a hashed token with a one-hour expiry for a known user and return a generic success for unknown addresses. The source migration notice highlights accounts created before January 1, 2026.
Failure and recovery
Missing/expired tokens and password validation belong to the source reset endpoint. Captures use a nonfunctional example token and never request an actual email.
Acceptance criteria
- Avoid disclosing whether an address exists in request feedback.
- Do not submit an example token to production.
- Source sign-in notice stays visible in screenshots.
Source references
| Repository file | Responsibility |
|---|---|
| app/auth/forgot-password/ForgotPasswordClient.tsx | Request UI |
| app/auth/reset-password/ResetPasswordClient.tsx | Reset UI |
| app/api/auth/request-password-reset/route.ts | Generic response and expiry |
Examples from the app
Actual Startboard source UI with isolated fictional records; both native themes at 2× resolution or higher. No live integrations or account writes. Captured at 2× resolution or higher. Select an image to inspect it full size.
Related topics
Source audit: 2026-10-08 · Revision 08fa2595a668 · Documentation v1.0.0