Skip to content

Reset password

import { Card, CardGrid, Steps, Aside } from ‘@astrojs/starlight/components’;

/reset-password is the third and final step of the password-reset flow. After you have verified the 6-digit OTP, you choose a new password here. The session that authorised the reset is stored in sessionStorage and cleared the moment you submit successfully.

Reset password — empty form

1. **Land on `/reset-password`** (auto-routed after Verify OTP). 2. **Enter the new password.** - Click the 👁 icon to show/hide while typing. - Min length: **6 characters**. 3. **Confirm the password** by typing it again. 4. **Click "Reset password".** 5. The reset session is cleared from `sessionStorage` and you are routed back to the **appropriate sign-in screen** (`/cashier-login` for cashier resets, `/login` or `/vendor-login` for dashboard resets).

Reset password — filled

RuleWhy
Minimum 6 charactersPrevent trivial passwords
Confirm field must match exactlyCatches typos
New password ≠ old passwordEnforced server-side to prevent reuse

Reset password — mismatch error

ErrorWhere it showsFix
Password must be at least 6 characters.Inline under passwordType a longer password
Passwords do not match.Inline under confirmRe-type the same password in both fields
Reset session expired.Red banner above the formRestart from /forgot-password
Invalid or expired reset token.Red bannerRestart from /forgot-password

The reset token lives in sessionStorage, so it disappears when:

  • You close the browser tab.
  • You open the page in another tab.
  • More than 15 minutes pass between Verify OTP and Reset password.

To recover: open /forgot-password and request a fresh code.