style.css gains the classes the views spelled out in full: .section-label
(17 sites), .hint (20), .form-error (13), .alert-error (5), .row-card (5),
.list-empty (5), .field (5), .page-shell (3), and the small row action
.btn-sm (4) / .btn-sm-danger (3). Only exact runs moved, so nothing renders
differently; spacing a site adds beyond a run stays a utility beside it.
Kept: the Reminders and Timeline small buttons. They carry no text colour
and inherit it, so putting them on .btn-sm would recolour them.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The operator asked for self-service reset over SMTP. It reuses #5173's
password_resets table, /reset-password page, one-hour single-use token and
sign-out-everywhere.
- Settings (rule 25, not env): a new Email group (SMTP server, port,
encryption as a choice, username, password, from), General → Public
address, and Security → Reset emails per account. The registry gains
`choices`, `secret` (the value is never sent back, `is_set` says one is
saved, an empty save keeps it) and `url` (http(s), trailing slash
stripped).
- mailer.py: stdlib smtplib on a worker thread, 20 s timeout,
starttls | tls | none. mail_settings() is None until a server, a sender
and the public address are set. Links are built from the public address
because the Host header can be forged.
- POST /api/auth/forgot-password: the same answer at the same speed for
any address. The link is made and mailed off the request (send_later).
It is throttled like a sign-in per visitor address, and capped per typed
email by reset_emails_per_account; past the cap it answers the same and
sends nothing.
- POST /api/settings/test-email: mails the admin with the saved settings
and shows the server's error if it fails.
- Public config `password_reset_by_email`. Sign-in shows "Forgot
password?" only then, linking to a new /forgot-password page.
- docs/public-hosting.md: an "Email and forgotten passwords" section.
Tests: the secret stays server-side; emailed link → reset; the same
answer for unknown addresses; the cap; test email success and failure;
validation units. #5266.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>