Purpose
Allows users to securely reset their password.
How It Works
- User enters email address
- System sends password reset link
- User clicks link
- User creates a new password
Result
- Password is updated
- Previous password becomes invalid
- User can log in with the new password
Validation Rules
- Email must exist
- Reset link must be valid and not expired
Failure Scenarios
- Email not found
- Invalid link
- Expired link
Developer Notes
- Use secure, expiring reset tokens
- Invalidate all active sessions after reset
- Enforce password requirements
- Prevent token reuse
- Log reset activity for security auditing
Routing Logic
After email verification or login, the system should route the user based on account status:
- Account Status
- Destination
- Email Not Verified
- Email Verification
- Setup Incomplete
- Account Setup Wizard
- Membership Not Activated
- Membership Setup
- Setup Complete
- Dashboard
Key Rule
Users must complete all required onboarding and activation steps before receiving full access to the Creditor Portal.
- Registration
- Authentication
- Email Verification
- Password Management
- Account Setup Wizard
- Membership Activation
- Dashboard Routing
Last modified on May 31, 2026