# 3. Password Management

User Type: **Parent**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 3. Password Management

### 3.1 Change Password
**What it does:** Lets the Parent change their account password. The Parent enters their current password and a new password, and the platform verifies the current password and applies the new one. The new password must meet the strength requirements. Changing the password signs out other active sessions for security.

**Sub-features:**
- Change the account password
- Verify the current password
- New password strength requirements
- Confirm the new password
- Password change confirmation
- Other sessions signed out on change
- Password change event logging (changed)
- Audit logging of the change password

**Parent User Journey:**
1. Parent opens Profile → "Security" → "Change Password".
2. Parent enters the current password.
3. Parent enters the new password and confirms it.
4. The platform verifies the current password.
5. The new password is applied.
6. Other active sessions are signed out.
7. Parent opens Profile → "Activity" and confirms the password change event is recorded.

**Rules & Edge Cases:**
- The current password must be verified.
- The new password must meet the strength requirements.
- The new password must be confirmed.
- Other sessions are signed out on a password change.
- Password change events (changed) are logged with the account and the timestamp.
- The change password is audit-logged with the account and the timestamp.

### 3.2 Forgot Password
**What it does:** Lets the Parent reset a forgotten password. The Parent enters their registered email, and the platform sends a password reset link. The Parent clicks the link, sets a new password, and can sign in with it. The reset link expires after a short window. This recovers access for a Parent who forgot their password.

**Sub-features:**
- Request a password reset by email
- Password reset link sent to the email
- Reset link expiry
- Set a new password from the link
- New password strength requirements
- Reset link single-use
- Reset event logging (requested, link used, password reset)
- Audit logging of the forgot password

**Parent User Journey:**
1. Parent selects "Forgot Password" on the login screen.
2. Parent enters their registered email.
3. A password reset link is sent to the email.
4. Parent clicks the link and sets a new password.
5. The new password meets the strength requirements.
6. Parent signs in with the new password.
7. Parent opens Profile → "Activity" and confirms the reset events are recorded.

**Rules & Edge Cases:**
- The reset link is sent to the registered email.
- The reset link expires after the platform's window.
- The reset link is single-use.
- The new password must meet the strength requirements.
- Reset events (requested, link used, password reset) are logged with the account and the timestamp.
- The forgot password is audit-logged with the account and the timestamp.

### 3.3 Two-Factor Authentication (2FA)
**What it does:** Adds a second factor to the Parent's login for extra security. The Parent enables 2FA and, at login, enters a one-time code from an authenticator app or SMS after the password. The Parent can disable 2FA and has backup codes for recovery. This protects the Parent's account, which has access to their children's data.

**Sub-features:**
- Enable two-factor authentication
- 2FA code at login (authenticator app or SMS)
- Backup codes for recovery
- Disable two-factor authentication
- 2FA status shown on the account
- 2FA event logging (enabled, code verified, disabled)
- Audit logging of the two-factor authentication

**Parent User Journey:**
1. Parent opens Profile → "Security" → "Two-Factor Authentication".
2. Parent enables 2FA and scans the authenticator app QR code.
3. Backup codes are generated and shown.
4. At the next login, Parent enters the password and the 2FA code.
5. The 2FA code is verified and the login succeeds.
6. Parent can disable 2FA later.
7. Parent opens Profile → "Activity" and confirms the 2FA events are recorded.

**Rules & Edge Cases:**
- 2FA requires an authenticator app or SMS.
- A 2FA code is required at login when enabled.
- Backup codes can be used for recovery.
- 2FA can be disabled by the Parent.
- 2FA events (enabled, code verified, disabled) are logged with the account and the timestamp.
- The two-factor authentication is audit-logged with the account and the timestamp.
