CompleteForgotPasswordRequest
What CompleteForgotPasswordAsync takes to finish a reset. No signed-in caller is needed, because the token is what proves who is asking.
Fields
Token: string
The token from the reset link. It identifies the user on its own, so nothing else about the account is submitted with it.
NewPassword: string
The replacement, at least 8 characters and subject to the [PasswordSecure] rule. Raises PasswordReusedException when it verifies against the password already stored.
ConfirmPassword: string
The new password typed again. Compared by the service, not during validation, so a mismatch arrives as PasswordMismatchException.
Type signature
csharp
public sealed record CompleteForgotPasswordRequest
{
public required string Token { get; set; }
public required string NewPassword { get; set; }
public required string ConfirmPassword { get; set; }
}