docs(backend): document the password-reset endpoints and table #8
Reference in New Issue
Block a user
No description provided.
Delete Branch "docs/password-reset"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What & why
Documents the new self-service password-reset flow in
website/BACKEND_DESIGN.md, keeping the canonical docs in lockstep with the code (per the repo's "docs must track code" rule). Counterpart to RunicGateway/website#75.POST /auth/password/forgotandGET|POST /auth/password/reset/:tokento the/authAPI-contract table, with the no-enumeration behaviour, session-revoke semantics, and no-auto-login note.password_resetstable to the §3 schema section (hashed opaque token, single-use, ~1h TTL).docs/android/PLAN.md§4.2) rather than shipping a native screen.How it was tested
Docs-only change — proofread against the implemented endpoints and the regenerated OpenAPI spec in website#75.
Checklist
AI-assisted contributions (required)
Claude Code (Claude Opus 4.8). I have reviewed and understand every change, and take responsibility for it. AI-authored commits are marked with aCo-Authored-Bytrailer.License
🤖 Generated with Claude Code
https://claude.ai/code/session_01NgyHnrNa8WwG3doxvxjuCr