LupinusBuildContact
← All guides
Guide 13 · Password Recovery

Recovering access to your account

The current LupinusBuild web recovery flow lets a user request a secure password-reset email and choose a new password after opening the recovery link.

Start password recovery

From the sign-in screen, choose Forgot password?.

LupinusBuild opens the Reset Password screen and carries over the email currently entered on the sign-in form when one is available.

Enter the account email and choose Send Recovery Email.

Email validation

An email address is required. The current recovery form checks that the value contains an @ symbol before submitting the request.

Recovery email

On the web version of LupinusBuild, the recovery request is sent through the authentication service using the entered email address.

The recovery request uses the current LupinusBuild site origin as the return destination for the recovery link.

Security-conscious confirmation

After submission, LupinusBuild says that if an account exists for the entered email, a recovery link has been sent. The confirmation does not disclose whether that email is registered.

The confirmation also advises the user that the recovery link expires and that the spam folder should be checked if the message does not arrive.

Choose a new password

When the recovery session reaches the password-reset screen, the user enters the new password twice:

New Password

Enter the new account password.

Confirm New Password

Enter the same password again for confirmation.

Both password fields include visibility controls so the user can temporarily display or hide the entered value.

Choose Update Password to submit the new password.

Password requirements

Minimum length
At least 8 characters.
Confirmation
The confirmation value must exactly match the new password.

The reset screen also advises users to choose a password they do not use elsewhere.

Errors and recovery-link problems

Authentication-service errors are shown to the user when a recovery request or password update fails.

For other unexpected failures, LupinusBuild displays a general message asking the user to try again.

The authentication utilities also support reading an error description returned through an authentication callback.

Expired recovery links

Recovery links are temporary. If a recovery link has expired or can no longer be used, return to the sign-in screen and request a new recovery email.

Current platform support

Web recovery is currently implemented

The current password-recovery request flow is configured for the web application. On a non-web platform, LupinusBuild currently displays a message that password recovery is not yet configured for that platform and directs the user to contact an administrator.

Mobile recovery and deep-link behavior should not be assumed to be available until those platform-specific recovery flows are completed and verified.

Successful password update

When the password update succeeds, LupinusBuild displays Password updated successfully. and continues through the application's configured post-reset flow.

Continue with common workflows
Common Workflows →