# Registration: Change password ###### Sprint: 2 ### Outcome: Users can change login password by entering old and new password and confirm OTP code ### Implementation description: #### Endpoints: PUT {$domain}/api/v2/barong/resource/users/password POST {$domain}/api/v2/barong/identity/confirm_password #### File destination: {$Dalan_Path}/app/api/v2/resource/users.rb #### Commits: fb5162e5 8b16cc49 fb9db4ee 70104499 63f69ed0 0ee97595 9e17677b 5bb29d79 #### What did we implement: In the Opendax, users can change their current password without confirming the OTP code that must be sent to its mail. Also, there is not any limitation for attempting to enter the current password. In Zagros, if users enter the wrong current password more than 3 times, they are kicked out from the logged state and the new password is just accepted after entering the valid OTP code. ``` TODO: Number of failed attempts to enter the current password must be dynamic and changeable by the admin panel ``` ```mermaid sequenceDiagram Title: Change password note over User,Ranj: old password parameter is the same as current password User->>Ranj:old_password, new_password, confirm_password Ranj->>Dalan:Put: after client side checking Dalan->>Ranj:4xx if attempt number for entering the valid current password is over Dalan->>Ranj:4xx if new_password is not same to confirm_password Dalan->>Ranj:4xx if old_password is not valid Dalan->>Ranj:4xx if new_password is same to old_password Dalan->>Ranj:4xx if length of new password is not valid Dalan->>User:2xx send otp to his or her mail Ranj->>User:Ask OTP code for confirming User-->>Ranj:if OTP code not received, try for resend after 120 seconds Ranj-->>Dalan: Ask for sending OTP code again Dalan-->>User:2xx send otp to his or her mail User->>Ranj: enter OTP code Dalan->>Ranj:4xx if user does not exist in the system Ranj->>Dalan:Post : OTP code for checking ice Dalan->>Ranj:4xx if OTP code expired Dalan->>Ranj:2xx change user password Ranj->>User:notify user that password changed ```