Skip to main content

MAZENG-FT-3 · Recover a forgotten password

Feature intent

A user who has lost their password needs to regain access without administrator intervention.

Why it matters

A user who has lost their password needs to regain access without administrator intervention.

Expected outcome

Reduces account lockout and support effort while preserving account security.

In scope

  • Request a password reset using the account email address.
  • Deliver a single-use, time-limited password-reset link.
  • Choose and confirm a replacement password through a valid reset link.
Delivery status
IN_BACKLOG
Owner
RootAtSkic (product lead)
Parent Epic
MAZENG-EP-1
Solution approval
PENDING

Acceptance

Acceptance outcomes

  1. 01

    A reset request does not disclose unrelated account data or permit account access by itself.

  2. 02

    A valid, unused, unexpired reset token permits the user to set a compliant replacement password.

  3. 03

    Missing, used, or expired tokens are rejected.

  4. 04

    The replacement password works for subsequent sign-in and the superseded password no longer does.

Dependencies and risks

Dependencies

None recorded.

Risks

  • The outcome depends on reliable email delivery and correct public Maze URL configuration.
  • Token lifetime and password-strength policy need an explicit Next Gen decision and consistent client/server enforcement; legacy tokens expire after 24 hours and legacy rules differ by layer.

Authoritative Architecture tasks

No authoritative Architecture tasks are linked.

Original source