Auth
Authentication screens — sign in / sign up with split brand panels, testimonial sidebars and patterned backdrops, plus two-factor, password-recovery and email-verification cards.
Preview
{{--
Reset password: a card that sets a new password from a reset link and
posts it to `action` (for Fortify: route('password.update')).
layout="page" (default) centres the card in its own full-height section;
layout="card" renders only the card, for a host guest layout.
Pass the link's `token` (a hidden field) and the account `email` (a
visible email field, readonly with :email-readonly="true"); a null email
leaves the field out. The password rules drive the password-strength
checklist only: validate the same rules on the server. When the host
refuses the link, pass its message in `error` and a `requestHref` to ask
for a new link. Field errors come from the shared error bag (`email`,
`password`, `password_confirmation`). The `botCheck` slot renders just
above the submit button.
--}}
@props([
'layout' => 'page',
'heading' => 'Set a new password',
'subheading' => 'Your new password must be different from previously used passwords.',
'headingLevel' => 3,
'icon' => true,
'action' => '#',
'token' => null,
'email' => null,
'emailReadonly' => false,
'emailLabel' => 'Email address',
'passwordLabel' => 'New password',
'confirmLabel' => 'Confirm password',
'minLength' => 8,
'requireLowercase' => false,
'requireUppercase' => true,
'requireNumber' => true,
'requireSymbol' => false,
'status' => null,
'error' => null,
'requestHref' => null,
'requestLabel' => 'Request a new link',
'submitLabel' => 'Reset password',
'loginHref' => '#',
'loginLabel' => 'Back to sign in',
'formId' => null,
])
@php
$asCard = $layout === 'card';
$level = in_array((int) $headingLevel, [1, 2, 3], true) ? (int) $headingLevel : 3;
@endphp
@php ob_start(); @endphp
<x-ui.card @class(['w-full', 'max-w-sm' => ! $asCard]) :attributes="$asCard ? $attributes : new \Illuminate\View\ComponentAttributeBag()">
<x-ui.card.header @class(['items-center text-center' => $icon])>
@if ($icon)
<span class="mb-2 inline-flex size-12 items-center justify-center rounded-full bg-primary/10 text-primary" aria-hidden="true">
<svg class="size-6" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.75" stroke-linecap="round" stroke-linejoin="round">
<rect x="4" y="10" width="16" height="11" rx="2" />
<path d="M8 10V7a4 4 0 0 1 8 0v3" />
<path d="M12 14.5v2.5" />
</svg>
</span>
@endif
@if ($level === 3)
<x-ui.card.title class="text-xl">{{ __($heading) }}</x-ui.card.title>
@else
<h{{ $level }} data-slot="card-title" class="break-words text-xl font-semibold leading-none tracking-tight">{{ __($heading) }}</h{{ $level }}>
@endif
@if (filled($subheading))
<x-ui.card.description>{{ __($subheading, ['count' => (int) $minLength]) }}</x-ui.card.description>
@endif
</x-ui.card.header>
<x-ui.card.content class="space-y-6">
@if (filled($error))
<x-ui.alert variant="destructive">
<x-ui.alert.title>{{ __($error) }}</x-ui.alert.title>
@if (filled($requestHref))
<x-ui.alert.description>
<a href="{{ $requestHref }}" class="font-medium text-foreground underline underline-offset-4">{{ __($requestLabel) }}</a>
</x-ui.alert.description>
@endif
</x-ui.alert>
@elseif (filled($status))
<x-ui.alert variant="success" role="status">
<x-ui.alert.title>{{ __($status) }}</x-ui.alert.title>
</x-ui.alert>
@endif
<form method="POST" action="{{ $action }}" class="space-y-6" @if (filled($formId)) id="{{ $formId }}" @endif>
@csrf
@if (filled($token))
<input type="hidden" name="token" value="{{ $token }}">
@endif
@if (! is_null($email))
<x-ui.field name="email">
<x-ui.label for="reset-email" required>{{ __($emailLabel) }}</x-ui.label>
<x-ui.input id="reset-email" type="email" autocomplete="username" required :value="$email" :readonly="(bool) $emailReadonly" />
</x-ui.field>
@endif
{{-- The strength primitive owns the meter and checklist. Its input is not
`required` (the toggle button shares the wrapper), so the server must
still validate `password` with the same rules as the props. --}}
<x-ui.field name="password">
<x-ui.label for="reset-password" required>{{ __($passwordLabel) }}</x-ui.label>
<x-ui.password-strength
id="reset-password"
:min-length="(int) $minLength"
:require-lowercase="(bool) $requireLowercase"
:require-uppercase="(bool) $requireUppercase"
:require-number="(bool) $requireNumber"
:require-symbol="(bool) $requireSymbol"
/>
</x-ui.field>
<x-ui.field name="password_confirmation">
<x-ui.label for="reset-password-confirm" required>{{ __($confirmLabel) }}</x-ui.label>
<x-ui.input
id="reset-password-confirm"
type="password"
autocomplete="new-password"
required
/>
</x-ui.field>
{{ $botCheck ?? '' }}
<x-ui.button type="submit" class="w-full">{{ __($submitLabel) }}</x-ui.button>
</form>
</x-ui.card.content>
@if (filled($loginHref))
<x-ui.card.footer class="justify-center">
<a href="{{ $loginHref }}" class="inline-flex items-center gap-2 text-sm font-medium text-muted-foreground transition-colors hover:text-foreground">
<svg class="size-4 rtl:-scale-x-100" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true">
<path d="m12 19-7-7 7-7" />
<path d="M19 12H5" />
</svg>
{{ __($loginLabel) }}
</a>
</x-ui.card.footer>
@endif
</x-ui.card>
@php $card = new \Illuminate\Support\HtmlString(ob_get_clean()); @endphp
@if ($asCard)
{{ $card }}
@else
<x-ui.section space="md" class="flex min-h-svh items-center justify-center px-4" {{ $attributes }}>
{{ $card }}
</x-ui.section>
@endif
Installation
php artisan ui:add blocks/auth-reset-password
Registry contract
Install confidence
php artisan ui:add blocks/auth-reset-password
writes only the generated targets below. The CLI validates each file hash before writing and
prompts before replacing local changes unless --force is used.
- Version
- 1.2.2
- License
- open
- Stability
- stable
- Contract
- v1
- Foundation
- ≥ 1.0.0
| Type | Generated target |
|---|---|
| blade | resources/views/blocks/auth-reset-password.blade.php |
Registry dependencies
Package dependencies
composer: jml/brok:^0.2
Use with AI
A brief for your coding agent: what the block is, the install command, how to render it, its props and the rules. Copy it, or open a prompt about this block in an assistant.
# Brok UI block: Reset Password (`auth-reset-password`)
A set-new-password card with the reset token and email, a new-password field with a live strength meter and configurable rules, a confirm field, a refused-link error with a request-new-link action, and a back-to-sign-in link, as its own centred page or as a card in a host layout.
Brok UI is a Laravel Blade registry. `ui:add` copies this block into the app as plain Blade the app owns; it composes installed `<brok:*>` primitives and semantic design tokens.
## Install
```bash
php artisan ui:add blocks/auth-reset-password
```
## Render it
```blade
<x-blocks.auth-reset-password layout="page" />
```
## Props
- `layout` (page|card, default `page`) (variant) — 'page' centres the card in its own full-height section; 'card' renders only the card for a host guest layout that already frames the page. Host attributes go to the section in page layout and to the card in card layout.
- `heading` (string, default `Set a new password`) — Card heading, passed through __().
- `subheading` (string, default `Your new password must be different from previously used passwords.`) — Card description, passed through __() with :count set to minLength; empty hides it.
- `heading-level` (1|2|3, default `3`) — Heading element; 3 keeps the card title, 1 or 2 renders the page heading as h1 or h2.
- `icon` (boolean, default `true`) — Shows the lock icon chip above the heading.
- `action` (string, default `#`) — Form action, for example route('password.update').
- `token` (string|null, default `null`) — Reset token, posted as a hidden token field.
- `email` (string|null, default `null`) — Account email; null leaves the email field out.
- `email-readonly` (boolean, default `false`) — Makes the email field readonly.
- `email-label` (string, default `Email address`) — Email field label.
- `password-label` (string, default `New password`) — New password label.
- `confirm-label` (string, default `Confirm password`) — Confirmation label.
- `min-length` (integer, default `8`) — Minimum length shown in the checklist; validate the same rule on the server.
- `require-lowercase` (boolean, default `false`) — Checklist rule: a lowercase letter.
- `require-uppercase` (boolean, default `true`) — Checklist rule: an uppercase letter; false when the host sets no composition rules.
- `require-number` (boolean, default `true`) — Checklist rule: a number; false when the host sets no composition rules.
- `require-symbol` (boolean, default `false`) — Checklist rule: a symbol.
- `status` (string|null, default `null`) — Success status, shown as a polite alert.
- `error` (string|null, default `null`) — Refused-link message, shown as a destructive alert. Use one message for an unknown address, a wrong token and an expired token.
- `request-href` (string|null, default `null`) — Link to request a new reset link, shown with the error.
- `request-label` (string, default `Request a new link`) — Request-new-link label.
- `submit-label` (string, default `Reset password`) — Submit button label.
- `login-href` (string, default `#`) — Back-to-sign-in link; empty hides the footer.
- `login-label` (string, default `Back to sign in`) — Back-to-sign-in label.
- `form-id` (string|null, default `null`) — id of the form element.
## Use when
- Letting a user set a new password after following a reset link, with a live strength meter and a requirements checklist.
- Requiring the password twice (new and confirm) before enabling the full-width reset button.
## Avoid when
- Use auth-forgot-password for the preceding request-a-reset-link screen instead of the set-a-new-password screen.
## Rules
- Render the installed block with `<x-blocks.auth-reset-password />` and pass data through its props; edit the copied file only for structural changes.
- Keep the semantic design tokens (`bg-background`, `text-muted-foreground`); never swap in raw colour utilities.
- Keep the `data-slot` attributes and the logical (start/end) spacing so the markup still mirrors under `dir="rtl"`.
## Links
- Docs: https://brokui.dev/blocks/auth-reset-password
- Registry JSON (files, props, contract): https://brokui.dev/r/open/blocks/auth-reset-password.json
Working in Claude Code, Cursor or Codex? Give the agent the whole registry through the MCP server or the Brok UI skill.
Guidance
Use when
- Letting a user set a new password after following a reset link, with a live strength meter and a requirements checklist.
- Requiring the password twice (new and confirm) before enabling the full-width reset button.
Avoid when
- Use auth-forgot-password for the preceding request-a-reset-link screen instead of the set-a-new-password screen.
Anti-patterns
- Do not replace semantic props with conflicting utility classes.
- Do not remove labels, focus styles, or state attributes.
Usage
Render the block as a component, passing data where useful:
<x-blocks.auth-reset-password />
The controls above the preview are props on this composition. What you picked reads:
Built from primitives
This block composes installed <brok:*> primitives and semantic design
tokens only — it does not reimplement any primitive. Re-theme it (light, dark, admin, customer) by
editing CSS variables; flip the preview to RTL to confirm it mirrors.
Source
The exact, editable file ui:add writes
into your app. The preview above renders this same source — there are no preview-only blocks.
{{--
Reset password: a card that sets a new password from a reset link and
posts it to `action` (for Fortify: route('password.update')).
layout="page" (default) centres the card in its own full-height section;
layout="card" renders only the card, for a host guest layout.
Pass the link's `token` (a hidden field) and the account `email` (a
visible email field, readonly with :email-readonly="true"); a null email
leaves the field out. The password rules drive the password-strength
checklist only: validate the same rules on the server. When the host
refuses the link, pass its message in `error` and a `requestHref` to ask
for a new link. Field errors come from the shared error bag (`email`,
`password`, `password_confirmation`). The `botCheck` slot renders just
above the submit button.
--}}
@props([
'layout' => 'page',
'heading' => 'Set a new password',
'subheading' => 'Your new password must be different from previously used passwords.',
'headingLevel' => 3,
'icon' => true,
'action' => '#',
'token' => null,
'email' => null,
'emailReadonly' => false,
'emailLabel' => 'Email address',
'passwordLabel' => 'New password',
'confirmLabel' => 'Confirm password',
'minLength' => 8,
'requireLowercase' => false,
'requireUppercase' => true,
'requireNumber' => true,
'requireSymbol' => false,
'status' => null,
'error' => null,
'requestHref' => null,
'requestLabel' => 'Request a new link',
'submitLabel' => 'Reset password',
'loginHref' => '#',
'loginLabel' => 'Back to sign in',
'formId' => null,
])
@php
$asCard = $layout === 'card';
$level = in_array((int) $headingLevel, [1, 2, 3], true) ? (int) $headingLevel : 3;
@endphp
@php ob_start(); @endphp
<x-ui.card @class(['w-full', 'max-w-sm' => ! $asCard]) :attributes="$asCard ? $attributes : new \Illuminate\View\ComponentAttributeBag()">
<x-ui.card.header @class(['items-center text-center' => $icon])>
@if ($icon)
<span class="mb-2 inline-flex size-12 items-center justify-center rounded-full bg-primary/10 text-primary" aria-hidden="true">
<svg class="size-6" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.75" stroke-linecap="round" stroke-linejoin="round">
<rect x="4" y="10" width="16" height="11" rx="2" />
<path d="M8 10V7a4 4 0 0 1 8 0v3" />
<path d="M12 14.5v2.5" />
</svg>
</span>
@endif
@if ($level === 3)
<x-ui.card.title class="text-xl">{{ __($heading) }}</x-ui.card.title>
@else
<h{{ $level }} data-slot="card-title" class="break-words text-xl font-semibold leading-none tracking-tight">{{ __($heading) }}</h{{ $level }}>
@endif
@if (filled($subheading))
<x-ui.card.description>{{ __($subheading, ['count' => (int) $minLength]) }}</x-ui.card.description>
@endif
</x-ui.card.header>
<x-ui.card.content class="space-y-6">
@if (filled($error))
<x-ui.alert variant="destructive">
<x-ui.alert.title>{{ __($error) }}</x-ui.alert.title>
@if (filled($requestHref))
<x-ui.alert.description>
<a href="{{ $requestHref }}" class="font-medium text-foreground underline underline-offset-4">{{ __($requestLabel) }}</a>
</x-ui.alert.description>
@endif
</x-ui.alert>
@elseif (filled($status))
<x-ui.alert variant="success" role="status">
<x-ui.alert.title>{{ __($status) }}</x-ui.alert.title>
</x-ui.alert>
@endif
<form method="POST" action="{{ $action }}" class="space-y-6" @if (filled($formId)) id="{{ $formId }}" @endif>
@csrf
@if (filled($token))
<input type="hidden" name="token" value="{{ $token }}">
@endif
@if (! is_null($email))
<x-ui.field name="email">
<x-ui.label for="reset-email" required>{{ __($emailLabel) }}</x-ui.label>
<x-ui.input id="reset-email" type="email" autocomplete="username" required :value="$email" :readonly="(bool) $emailReadonly" />
</x-ui.field>
@endif
{{-- The strength primitive owns the meter and checklist. Its input is not
`required` (the toggle button shares the wrapper), so the server must
still validate `password` with the same rules as the props. --}}
<x-ui.field name="password">
<x-ui.label for="reset-password" required>{{ __($passwordLabel) }}</x-ui.label>
<x-ui.password-strength
id="reset-password"
:min-length="(int) $minLength"
:require-lowercase="(bool) $requireLowercase"
:require-uppercase="(bool) $requireUppercase"
:require-number="(bool) $requireNumber"
:require-symbol="(bool) $requireSymbol"
/>
</x-ui.field>
<x-ui.field name="password_confirmation">
<x-ui.label for="reset-password-confirm" required>{{ __($confirmLabel) }}</x-ui.label>
<x-ui.input
id="reset-password-confirm"
type="password"
autocomplete="new-password"
required
/>
</x-ui.field>
{{ $botCheck ?? '' }}
<x-ui.button type="submit" class="w-full">{{ __($submitLabel) }}</x-ui.button>
</form>
</x-ui.card.content>
@if (filled($loginHref))
<x-ui.card.footer class="justify-center">
<a href="{{ $loginHref }}" class="inline-flex items-center gap-2 text-sm font-medium text-muted-foreground transition-colors hover:text-foreground">
<svg class="size-4 rtl:-scale-x-100" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true">
<path d="m12 19-7-7 7-7" />
<path d="M19 12H5" />
</svg>
{{ __($loginLabel) }}
</a>
</x-ui.card.footer>
@endif
</x-ui.card>
@php $card = new \Illuminate\Support\HtmlString(ob_get_clean()); @endphp
@if ($asCard)
{{ $card }}
@else
<x-ui.section space="md" class="flex min-h-svh items-center justify-center px-4" {{ $attributes }}>
{{ $card }}
</x-ui.section>
@endif
Ownership & lifecycle
Owner, release state, review evidence and adoption for this item.
- Owner
- Platform UI (@JoshJML)
- Current version
-
1.2.2 - Status
- Stable
- License
-
open - Deprecation
- Not deprecated
- Contract
-
v1 - Foundation
-
≥ 1.0.0