Password Reset
Goal
This snapshot advances Meridian Notes by teaching you to issue expiring one-use password reset tokens.
Every numbered folder is a complete application. Run this stage on its own, then compare it with the previous snapshot to isolate the new responsibility.
Prerequisites
Use Node.js 20 or newer, npm, and a terminal. You should be comfortable with JavaScript functions, objects, modules, and basic HTML forms.
The development server uses port 3000. Data-backed snapshots use PostgreSQL on host port 5433 and keep their data in a database unique to that folder.
- Node.js and npm installed
- A code editor and terminal
- Docker from part 4 onward
Concepts
Secure resets send a random token but store only its digest. Responses do not reveal account existence, tokens expire quickly, and successful use removes outstanding tokens.
Keep the server boundary visible: Server Components may read trusted data directly, while Server Actions and route handlers must validate all incoming values and re-check authorization.
Walkthrough
Generate a random token, hash it with SHA-256, store its expiry, print the development URL, then transactionally update the password and delete tokens.
Trace the example from request to rendered result, then inspect the matching snapshot for its surrounding types, validation, error handling, and configuration.
const token = randomBytes(32).toString("hex");
const tokenHash = createHash("sha256").update(token).digest("hex");
Run and verify
Enter 11-Password-Reset, install its dependencies, and copy .env.example when the snapshot includes one.
Open http://localhost:3000. Keep the terminal visible so framework, Prisma, and authentication errors can be matched to the browser action that caused them.
git clone https://github.com/michaeldunga1/fcc-nextjs-blog.git
cd fcc-nextjs-blog/11-Password-Reset
npm install
cp .env.example .env
docker compose -f ../docker-compose.yml up -d
npm run db:migrate
npm run db:seed
npm run dev
Troubleshooting
Compare digests, not raw tokens. Check the server log, expiry timezone, single-use deletion, and that the new bcrypt hash authenticates.
A missing-module error usually means npm ran in another snapshot. Database errors often mean Docker is stopped, the environment file is missing, or this folder points at the wrong numbered database.
- Read the first error first
- Restart after environment changes
- Never commit .env or node_modules
Try this
Request two reset links, use one, and verify neither link can be reused.
Test one expected path and one invalid or unauthorized path. A production-minded app gives useful feedback without exposing secrets or stack traces.
- Make one focused change
- Verify it in the browser
- Continue only after this snapshot works
Next: Deploy
Comments
One comment per signed-in account. Comments are saved with this page’s URL.