התרחיש
A Spring Boot microservice handles password reset by generating a 6-digit OTP, storing its hash in Redis with a 10-minute TTL, sending it via AWS SES, and verifying user submission before updating the password.
מה מופיע בתרשים הזה
פענחו את ההחלטות שמאחוריו.
01
Account existence check returns generic success to prevent user enumeration
02
OTP validity and expiry check before password update
03
Email delivery failure returns 502 after logging
Use for any web service implementing one-time password based password reset with Redis and transactional email.