| AC | Result |
|---|---|
| 1. Forgot password end to end (email, OTP, new password, success, login) | ✅ Pass |
| 2. Resend OTP works; expired code returns to email step | ❌ Resend OTP fails (CORS). Expiry / ref 56: ⛔ blocked |
| 3. Wrong OTP stays on OTP screen | ❌ Fail: advances to password step, rejected only on final submit |
| 4. Password policy + confirm match | ✅ Pass |
| 5. Requests hit new user service | ✅ Pass on endpoints/payloads. Merchant comparison not done |
PUT init-reset-password returned 200 "00" and sent the OTP; the code screen loaded; PUT reset-password returned 200 "password reset successful"; the success screen showed; logging in with the new password reached /compliance.
Clicking Resend OTP shows a "Network Error" toast. The browser blocks POST https://dev.mypasspoint.com/userapp/user-app/resend-otp from origin admin-sandbox.mypasspoint.com: "blocked by CORS policy: Response to preflight request" (net::ERR_FAILED). Reproduced on two references. The PUT calls on the same host succeed. Sandbox-only or not is unconfirmed.
BLOCKED Expired code and reference 56 restarting from the email step: not exercised (Resend cannot be used, expiry window unknown).
Entering 000000 and Continue makes no API call and moves to Create New Password. Only PUT reset-password validates the code: 400 "otp validation failed". The user is then sent back to the OTP screen with the error. Outcome is right, timing is wrong: the wrong OTP does not stay on the OTP screen when entered.
"password" ticks only the length rule; Confirm Password stays disabled. A compliant password ticks all four rules and enables Confirm. A different confirm shows "Passwords do not match".
Captured against https://dev.mypasspoint.com/userapp/user-app/:
PUT init-reset-password {"username"} returns reference. POST resend-otp {"reference"}. PUT reset-password {"password","otp","reference"}. Not compared side by side with the merchant Go app.