### 1. User clicks forget password from email ``` http://rak-dev.bambu.life/reset-password?access_token=gAaDKvaXzGQxzgoODpmTRZEigsFsYIAUrGG3sd3E58aN0XKVimlzv5YRP8b1Xhj1 ``` ### 2. user is redirected to reset password screen ![](https://i.imgur.com/Vrwoist.png) ### 3. The querystring {access_token} is retrieved by from-end e.g ```javascript const resetPaswordToken = parseQueryString().access_token ``` ### 4. user enters password and click reset password ``` POST /api/user/reset-password?access_token={resetPasswordToken} ``` Payload: ```javascript { newPassword: "blbalbblablbal", } ``` There is no success response object/message but http 204 status code Not sure about error response.