Password reset page loads but fails on "Save new password" submission (v2 custom domain)

Hello,

We are experiencing a recurring issue affecting multiple clients across our two systems:

Observed behaviour:

  1. Client receives password reset link (remind_link).

  2. Link opens correctly.

  3. Password creation page loads without issue.

  4. After entering a valid password and clicking “Save new password”, an error appears.

  5. The password is not saved.

Important clarifications:

  • This is NOT a browser issue.

  • It occurs across Safari and Chrome.

  • It occurs on iPhone and PC.

  • It occurs on WiFi and 4G.

  • It occurs with Gmail, Protonmail, Yahoo, Me and Hotmail.

  • Client merges have already been completed.

  • The issue does NOT happen consistently in controlled testing.

  • The failure occurs specifically at the password submission stage.

This suggests:

• Backend validation failure
• CSRF/session token issue
• SameSite cookie restriction
• Cross-domain submission conflict (custom domain v2 → secure.simplybook.it)
• Token lifecycle conflict at submission

The reset link itself is valid (page loads normally).
The error happens only on form submission.

We kindly request:

  1. Server-side logs for failed password submissions.

  2. Confirmation of any known issues with v2 custom domains.

  3. Verification of CSRF/session validation on password save.

  4. Confirmation if any recent updates affected password reset handling.

This issue is business-critical as login is mandatory in our system.

We are available to perform a live monitored test if needed.

Thank you.

We are available to perform a live password reset test today while your team monitors logs in real time. Please confirm a time window.

Hi Joana,
To further investigate the root cause of this error, we need additional data from specific cases:

  1. Company login and Client ID(s) affected.

  2. The full URL from the browser’s address bar after clicking the reset link.

  3. (Optional) A screenshot of the email showing the date/time received and the time of the reset attempt.

Note: For privacy reasons, please mask or hide any personal client information (name, email, etc.) on the screenshots. We only need the technical details and timestamps.

Looking forward to your reply.