Vovy builds the forgot password form, the page where users choose a new password, and a branded reset email, then tests the full loop.
Add a forgot password flow to my app
How it works
- Add the forgot password form: In Cursor Vovy adds a form that calls resetPasswordForEmail with a redirectTo pointing at a new /reset-password page.
- Build the new password page: It creates the page users land on from the email, which calls updateUser with the new password once Supabase signs them in from the link.
- Allow the reset page URL: Vovy adds /reset-password to Redirect URLs in Authentication, URL Configuration so Supabase is allowed to send users there.
- Brand the Reset Password email: It edits the Reset Password template in Authentication, Emails with your subject line, app name and a clear button.
- Run the full reset: Vovy requests a reset, waits while you open the email, sets a new password, and confirms the old one no longer works.
What you provide
- A Supabase project with email login
- A test inbox
What you get
- A forgot password form
- A working new password page
- A branded reset email
- Proof the full loop works
FAQ
Why does the reset link log users in instead of asking for a password?
The link signs the user in, and your page must then show a new password form. If that page doesn't exist, users land on your home page signed in.
Does this tell attackers which emails have accounts?
It shouldn't. Vovy makes the form show the same message whether or not the email exists.
Why aren't reset emails arriving?
Supabase's built-in sender has a very low hourly limit and can land in spam. Custom SMTP fixes both.
Related tasks
All tasks