feat(02-03): password reset flow, force-change interceptor, MailModule

- MailModule with SMTP transport configured from ENV variables
- MailService for password reset and welcome emails (plain text, i18n)
- Password reset flow: request-reset (public), reset-password (token-based)
- Change password for logged-in users with current password verification
- Admin reset password endpoint (ADMIN/SUPER_ADMIN only, D-03)
- ForcePasswordChangeInterceptor blocks all routes except change-password,
  logout, me when mustChangePassword=true (D-06, Pitfall 5)
- Frontend: reset-password request page, token reset page, change-password page
- Forgot password link added to login page
- MailHog service added to docker-compose.dev.yml for dev email testing
- SMTP env vars added to docker-compose.yml (defaults to MailHog)
- Complete DE/EN i18n coverage for reset and change password flows
- SUS packages installed: @nestjs-modules/mailer, nodemailer, ldapts

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-18 13:48:23 +02:00
parent eaaa9adfa5
commit ac617f4fe5
20 changed files with 4216 additions and 12 deletions
+7
View File
@@ -34,6 +34,13 @@ services:
TESSERA_ADMIN_EMAIL: ${TESSERA_ADMIN_EMAIL:-admin@tessera.local}
TESSERA_ADMIN_PASSWORD: ${TESSERA_ADMIN_PASSWORD:-admin123}
TESSERA_FORCE_CHANGE: ${TESSERA_FORCE_CHANGE:-false}
TESSERA_SMTP_HOST: ${TESSERA_SMTP_HOST:-mailhog}
TESSERA_SMTP_PORT: ${TESSERA_SMTP_PORT:-1025}
TESSERA_SMTP_SECURE: ${TESSERA_SMTP_SECURE:-false}
TESSERA_SMTP_USER: ${TESSERA_SMTP_USER:-}
TESSERA_SMTP_PASSWORD: ${TESSERA_SMTP_PASSWORD:-}
TESSERA_SMTP_FROM: ${TESSERA_SMTP_FROM:-Tessera <tessera@tessera.local>}
TESSERA_APP_URL: ${TESSERA_APP_URL:-http://localhost:3000}
healthcheck:
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:3001/health"]
interval: 10s