feat(02-03): password reset flow, force-change interceptor, MailModule

- MailModule with SMTP transport configured from ENV variables
- MailService for password reset and welcome emails (plain text, i18n)
- Password reset flow: request-reset (public), reset-password (token-based)
- Change password for logged-in users with current password verification
- Admin reset password endpoint (ADMIN/SUPER_ADMIN only, D-03)
- ForcePasswordChangeInterceptor blocks all routes except change-password,
  logout, me when mustChangePassword=true (D-06, Pitfall 5)
- Frontend: reset-password request page, token reset page, change-password page
- Forgot password link added to login page
- MailHog service added to docker-compose.dev.yml for dev email testing
- SMTP env vars added to docker-compose.yml (defaults to MailHog)
- Complete DE/EN i18n coverage for reset and change password flows
- SUS packages installed: @nestjs-modules/mailer, nodemailer, ldapts

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-18 13:48:23 +02:00
parent eaaa9adfa5
commit ac617f4fe5
20 changed files with 4216 additions and 12 deletions
+30
View File
@@ -23,12 +23,42 @@
"password": "Password",
"rememberMe": "Remember me",
"submit": "Sign In",
"forgotPassword": "Forgot password?",
"error": {
"invalidCredentials": "Invalid username or password",
"networkError": "Connection error. Please try again."
},
"branding": {
"tagline": "Modular workflow platform for your organization"
},
"resetPassword": {
"title": "Reset Password",
"email": "Email address",
"submit": "Send Reset Link",
"success": "If an account with this email exists, a reset link has been sent.",
"backToLogin": "Back to Sign In",
"newPasswordTitle": "Set New Password",
"newPassword": "New Password",
"confirmPassword": "Confirm Password",
"submitReset": "Reset Password",
"resetSuccess": "Your password has been reset successfully.",
"redirecting": "You will be redirected to the sign in page in a few seconds...",
"tokenExpired": "This reset link has expired. Please request a new one.",
"tokenUsed": "This reset link has already been used. Please request a new one.",
"tokenInvalid": "This reset link is invalid.",
"passwordMismatch": "Passwords do not match."
},
"changePassword": {
"title": "Change Password",
"currentPassword": "Current Password",
"newPassword": "New Password",
"confirmPassword": "Confirm New Password",
"submit": "Change Password",
"success": "Your password has been changed successfully.",
"forceChangeNotice": "For security reasons, you must change your password before continuing.",
"wrongCurrentPassword": "The current password is incorrect.",
"networkError": "Connection error. Please try again.",
"passwordMismatch": "Passwords do not match."
}
},
"header": {