Skip to main content
One idea at a time

Password reset creates a temporary credential

Maya forgets her password. The reset flow lets her regain access through control of her email address.

That makes the reset token a temporary credential powerful enough to replace the password. It deserves the same care as a session token.

The API accepts an email address and responds without confirming whether that account exists. Otherwise, the endpoint becomes an account-directory lookup for attackers.

The email carries the secretโ€‹

For a known account, Taskboard generates a random token and stores its hash with the password-reset purpose, user identifier, expiry, and consumed state. It records a job to send the reset message.

The raw token appears in the reset link. Production logs must not record that complete URL. The token row holds a hash, but the email job holds the raw link for delivery. That payload is sensitive and needs restricted access and removal after a deliberate retention period.

The reset endpoint accepts the token and a new password. It verifies the token's purpose, expiry, and unused state before committing the new password hash.

Replacement and revocation happen togetherโ€‹

Changing the password and consuming the token belong to one transaction. A failure must not leave a consumed token with the old password, or a new password with a still-reusable token.

The reference flow also invalidates existing sessions when the password changes. That matters when reset follows a suspected compromise. Updating the password alone does not remove a stolen session cookie.

The person signs in again using the new password. Automatically preserving old authenticated sessions weakens the recovery action and complicates its meaning.

Concurrent token submissions need a single-use guarantee in the database operation. A frontend that disables the submit button prevents one accidental double-click. It cannot stop requests from another browser or a script.

Abuse has operational costsโ€‹

An attacker can repeatedly request emails to a victim or exhaust a provider allowance. Rate limits, bounded jobs, delivery monitoring, and safe generic responses are part of a production reset flow.

A valid token is still not an excuse to accept an unbounded password body. Validation limits protect the derivation operation and define the accepted credential contract.

Why revoke sessions when the password is reset?

A password reset may be a recovery from compromise. A stolen session remains a credential until the server expires or revokes it, even after the password changes.

Reset uses a short-lived credential to replace another credential. Consume the token, update the password, and revoke sessions as one coordinated operation.

Read api/src/auth.ts Read api/src/security.ts