Password Reset

View saved

Goal

This snapshot advances Quaycart Market by teaching you to issue expiring one-use password reset tokens.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use PHP 8.2+, Composer, Node.js 20+, npm, and Docker for MySQL stages.

Port 8004 must be free. Copy .env.example before database stages.

  • PHP and Composer
  • Node.js and npm
  • Docker from part 4 onward

Concepts

Laravel's password broker stores hashed tokens and clears them after a successful reset.

Livewire keeps interactive UI on the server with components; Tailwind styles the storefront; Eloquent owns persistence and authorization checks.

Walkthrough

Wire forgot/reset Livewire forms around Password::sendResetLink and Password::reset; use the log mailer locally.

Read the example, then open the matching snapshot. The repository includes validation, CSRF, and the surrounding structure.

$status = Password::sendResetLink($this->only('email'));
# inspect storage/logs/laravel.log for the reset URL

Run and verify

Enter 11-Password-Reset, install PHP and Node dependencies, copy .env.example, migrate, seed, build assets, and serve on port 8004.

Open http://127.0.0.1:8004. From data lessons onward, Ada and Grace use password123.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-laravel-ecommerce.git
cd fcc-laravel-ecommerce/11-Password-Reset
composer install
npm install
cp .env.example .env
php artisan key:generate
php artisan migrate --seed
php artisan storage:link
npm run build
php artisan serve --host=0.0.0.0 --port=8004

Troubleshooting

Always show a generic success message whether or not the email exists.

For database failures, confirm Docker and the quaycart_NN name. Never commit .env, vendor, or node_modules.

  • Read the first exception first
  • Rebuild assets after Tailwind class changes
  • Never commit secrets

Try this

Request a reset for Ada, complete it once, then confirm the token cannot be reused.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Deploy

Comments

One comment per signed-in account. Comments are saved with this page’s URL.