Key risks covered
- - Request reset email for existing and unknown users without leaking account existence.
- - Valid, expired, reused, malformed, and older reset tokens.
- - Weak password, mismatch, same-as-old password, and password policy validation.
- - Old password rejection, new password success, and session invalidation after reset.
- - Rate limiting, email provider failure, safe token logging, wrong content type, and backend outages.