The scenario
A Next.js app uses Auth.js for authentication and SendGrid for email. Users request a password reset by entering their email, receive a one-time password, and submit it with a new password.
What is in this drawing
Read the decisions behind it.
01
Return generic success for non-existent users to prevent account enumeration
02
Delete stored OTP if email sending fails
03
Verify OTP validity and expiry before allowing password reset
Reusable for any password reset flow using OTP via email, especially serverless/Next.js API routes with third-party email providers.
More like this