ChangePasswordRequest
What ChangePasswordAsync takes from a signed-in user. Validation checks shape and strength only; the three password comparisons are made by the service against the stored hash.
Fields
CurrentPassword: string
The password in force now. A wrong value raises InvalidCredentialsException, the same failure a wrong login password produces.
NewPassword: string
The replacement, at least 8 characters and subject to the [PasswordSecure] rule. Raises PasswordReusedException when it verifies against the password already stored.
ConfirmPassword: string
The new password typed again. Compared by the service, not during validation, so a mismatch arrives as PasswordMismatchException.
Type signature
csharp
public sealed record ChangePasswordRequest
{
public required string CurrentPassword { get; set; }
public required string NewPassword { get; set; }
public required string ConfirmPassword { get; set; }
}