Password Reset
Goal
This snapshot advances Circuit Daily by teaching you to issue expiring one-use password reset tokens.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use Node.js 20+, npm, and a terminal. You should recognize TypeScript modules, decorators, and HTTP verbs.
Port 3001 must be free. Copy .env.example before starting database stages.
- Node.js and npm
- A code editor and terminal
- Docker from part 4 onward
Concepts
Store a random token and expiry on the user. Locally print the link to the console instead of requiring SMTP.
Keep controllers thin: accept input, call services, render Handlebars views. Escape stays on by default in templates.
Walkthrough
Create a forgot-password form, save a token, and complete the reset only when the token is valid and unexpired.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
user.resetToken = randomBytes(24).toString('hex');
console.log('[mail]', link);
Run and verify
Enter 11-Password-Reset, install dependencies, copy .env.example when present, and start Nest on port 3001.
Open http://127.0.0.1:3001. Watch the terminal for validation and database errors.
docker compose up -d
git clone https://github.com/michaeldunga1/fcc-nestjs-blog.git
cd fcc-nestjs-blog/11-Password-Reset
npm install
cp .env.example .env
npm run start:dev
Troubleshooting
Always show a generic success message so attackers cannot probe which emails exist.
Missing-module errors usually mean npm install ran in another snapshot. For Postgres failures, confirm Docker and the circuit_NN database name.
- Read the first error first
- Restart after environment changes
- Never commit .env or node_modules
Try this
Request a reset for Ada and complete it from the console link.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Deploy
Comments
One comment per signed-in account. Comments are saved with this page’s URL.