Start password recovery
From the sign-in screen, choose Forgot password?.
LupinusBuild opens the Reset Password screen and carries over the email currently entered on the sign-in form when one is available.
Enter the account email and choose Send Recovery Email.
An email address is required. The current recovery form checks that the value contains an @ symbol before submitting the request.
Recovery email
On the web version of LupinusBuild, the recovery request is sent through the authentication service using the entered email address.
The recovery request uses the current LupinusBuild site origin as the return destination for the recovery link.
After submission, LupinusBuild says that if an account exists for the entered email, a recovery link has been sent. The confirmation does not disclose whether that email is registered.
The confirmation also advises the user that the recovery link expires and that the spam folder should be checked if the message does not arrive.
Choose a new password
When the recovery session reaches the password-reset screen, the user enters the new password twice:
New Password
Enter the new account password.
Confirm New Password
Enter the same password again for confirmation.
Both password fields include visibility controls so the user can temporarily display or hide the entered value.
Choose Update Password to submit the new password.
Password requirements
The reset screen also advises users to choose a password they do not use elsewhere.
Errors and recovery-link problems
Authentication-service errors are shown to the user when a recovery request or password update fails.
For other unexpected failures, LupinusBuild displays a general message asking the user to try again.
The authentication utilities also support reading an error description returned through an authentication callback.
Recovery links are temporary. If a recovery link has expired or can no longer be used, return to the sign-in screen and request a new recovery email.
Current platform support
The current password-recovery request flow is configured for the web application. On a non-web platform, LupinusBuild currently displays a message that password recovery is not yet configured for that platform and directs the user to contact an administrator.
Mobile recovery and deep-link behavior should not be assumed to be available until those platform-specific recovery flows are completed and verified.
Successful password update
When the password update succeeds, LupinusBuild displays Password updated successfully. and continues through the application's configured post-reset flow.
