# Mobile password recovery and verification — local acceptance complete

The mobile reset request omitted a redirectUrl, causing the backend to use its legacy stus.io default. ApiService now supplies EnvironmentConfig.passwordResetUrl: https://studio.appmint.io/reset-password by default; a STUDIO_URL build override supports the local preview. No token is rewritten, forged or bypassed. Nine existing real-form/provider/client recovery tests pass with the corrected request. [Tests](assets/mobile-recovery-live/tests.txt).

Rebuilt and installed the local Android app with API3311 and Studio3101. Forgot Password reached the existing organisation’s loopback SMTP provider. The newest captured email linked to the local Studio reset page. Submitted a new private password through its form, observed the success message, then signed in on Android with the new password. Private credential storage was updated; no password/token/secret is in this report. [Reset success](assets/mobile-local/27-reset-success.png), [new-password Home](assets/mobile-local/28-reset-password-home.png).

Also enrolled an authenticator through Studio User Management → owner row menu → View Profile → Security → Authenticator app → Turn on → Verify and turn on. After a fresh mobile password login, Verification required asked for a current authenticator code. A real time-based code completed login into the correct organisation. [Empty challenge](assets/mobile-local/24-authenticator-challenge.png), [authenticated Home](assets/mobile-local/25-authenticator-home.png). Restored the original verification setting through Turn all off with the owner password after the test. No developer bypass code was used.

Remembered-account behavior was exercised separately: its tile resumed a saved session after Logout; Forget this account removed the tile. The course now tells shared-device users to forget the account after logout. This matches the implemented saved-session feature; Logout alone is not presented as removing saved sign-in access.

Studio recovery runner now closes its filesystem watcher after listening while retaining HMR for dependency-optimizer reloads. Unrelated active source edits had repeatedly replaced the form mid-test. No other developer process was stopped.
