Skip to main content

Purpose

Allows users to securely reset their password.

How It Works

  • User enters email address
  • System sends password reset link
  • User clicks link
  • User creates a new password

Result

  • Password is updated
  • Previous password becomes invalid
  • User can log in with the new password

Validation Rules

  • Email must exist
  • Reset link must be valid and not expired

Failure Scenarios

  • Email not found
  • Invalid link
  • Expired link

Developer Notes

  • Use secure, expiring reset tokens
  • Invalidate all active sessions after reset
  • Enforce password requirements
  • Prevent token reuse
  • Log reset activity for security auditing

Routing Logic

After email verification or login, the system should route the user based on account status:
  • Account Status
  • Destination
  • Email Not Verified
  • Email Verification
  • Setup Incomplete
  • Account Setup Wizard
  • Membership Not Activated
  • Membership Setup
  • Setup Complete
  • Dashboard

Key Rule

Users must complete all required onboarding and activation steps before receiving full access to the Creditor Portal.
  • Registration
  • Authentication
  • Email Verification
  • Password Management
  • Account Setup Wizard
  • Membership Activation
  • Dashboard Routing
Last modified on May 31, 2026