Clarification on Email OTP Auth Flows
I am not clear on the flows of the
Email OTP auth flows.SignIn with OTP- I have regular credentials setup. Seems like it replaces the
passwordin credentials? And I would have only anemailfield with a buttonSign In with Passcode? Or does this happen in addition topasswordkinda like two-factor auth without thetwoFactorplugin.
- I have regular credentials setup. Seems like it replaces the
Verify Email- self explanatory. Sent on Sign Up, user auto Signed In. Authenticated Form to input OTP and resend verification email button.
Reset Password- Is this for currently logged out user it seems? Reset password form with just
emailfield. This email gets sent with the OTP and a link to your public password change password form:otp,email,new password,confirm new password? I'm generally familiar with reset links. But I think somewhere in OWASP, OTP are recommended.
- Is this for currently logged out user it seems? Reset password form with just
SignIn with OTP for instance.