السيناريو
A Laravel API handles password reset by issuing a one-time password (OTP) via Twilio Verify and storing hashed OTPs in MySQL. The flow includes both request and verify endpoints.
ما الذي يتضمنه هذا الرسم
اقرأ القرارات الكامنة وراءه.
01
Return generic success for unknown email to prevent user enumeration
02
Store only hashed OTP with expiry in MySQL
03
Use Twilio Verify result to gate 200 versus 502 response
04
Invalid or expired OTP returns 401; successful verify issues a reset token
Reusable for any API that implements OTP-based password reset with external SMS provider and relational database.