Lo scenario
A Spring Boot microservice handles password reset by generating a 6-digit OTP, storing its hash in Redis with a 10-minute TTL, sending it via AWS SES, and verifying user submission before updating the password.
Cosa contiene questo disegno
Leggi le decisioni che ne stanno alla base.
01
Account existence check returns generic success to prevent user enumeration
02
OTP validity and expiry check before password update
03
Email delivery failure returns 502 after logging
Use for any web service implementing one-time password based password reset with Redis and transactional email.