Add /auth/password/forgot and /auth/password/reset/:token to the API contract and the password_resets table to the schema section, matching the website change (RunicGateway/website feat/password-reset). Notes the no-enumeration behaviour, single-use hashed-token model, and that the Android app hands off to the web reset page (PLAN.md §4.2). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NgyHnrNa8WwG3doxvxjuCr