Reset password
import { Card, CardGrid, Steps, Aside } from ‘@astrojs/starlight/components’;
I. Overview
Section titled “I. Overview”/reset-password is the third and final step of the password-reset flow. After you have verified the 6-digit OTP, you choose a new password here. The session that authorised the reset is stored in sessionStorage and cleared the moment you submit successfully.

II. Step-by-step
Section titled “II. Step-by-step”
III. Password rules
Section titled “III. Password rules”| Rule | Why |
|---|---|
| Minimum 6 characters | Prevent trivial passwords |
| Confirm field must match exactly | Catches typos |
| New password ≠ old password | Enforced server-side to prevent reuse |
IV. Common errors
Section titled “IV. Common errors”
| Error | Where it shows | Fix |
|---|---|---|
Password must be at least 6 characters. | Inline under password | Type a longer password |
Passwords do not match. | Inline under confirm | Re-type the same password in both fields |
Reset session expired. | Red banner above the form | Restart from /forgot-password |
Invalid or expired reset token. | Red banner | Restart from /forgot-password |
What to do if your reset session expires
Section titled “What to do if your reset session expires”The reset token lives in sessionStorage, so it disappears when:
- You close the browser tab.
- You open the page in another tab.
- More than 15 minutes pass between Verify OTP and Reset password.
To recover: open /forgot-password and request a fresh code.
V. Related
Section titled “V. Related”- Verify OTP — Step 2.
- Cashier login — Where you land after success.
- Vendor login (Owner) — Owner landing.