> ## Documentation Index
> Fetch the complete documentation index at: https://translations.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Password Reset Post Challenge

> ユーザーがパスワードリセット中に最初のチャレンジを完了した後、新しいパスワードを設定する前に実行されるPassword Reset Post Challenge Actionsについて説明します。

`post-challenge` トリガーは、パスワードリセット中に、ユーザーが最初のチャレンジ (通常は[ユーザーのメールアドレス](/docs/ja-jp/secure/multi-factor-authentication/authenticate-using-ropg-flow-with-mfa/enroll-and-challenge-email-authenticators)へのリンク) を完了した後、新しいパスワードを設定する前に実行されます。このトリガーを使用すると、追加の<Tooltip tip="多要素認証（MFA）：SMSで送信されるコードなど、ユーザー名とパスワードに加えて認証要素を使用するユーザー認証プロセス。" cta="用語集を表示" href="/docs/ja-jp/glossary?term=multi-factor+authentication">多要素認証</Tooltip> (MFA) 認証要素でユーザーにチャレンジを行ったり、サードパーティの検証サービスなどの外部サイトにユーザーをリダイレクトしたりできます。検証後、ユーザーはアカウントの新しいパスワードを設定できます。`post-challenge` トリガーを利用するActionは、tenantごとに最大4つ作成できます。

<Frame>
  <img src="https://mintcdn.com/translations/eVsQcTnbClN-oB7d/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?fit=max&auto=format&n=eVsQcTnbClN-oB7d&q=85&s=b55ee347f6001721fc25485dd0f37eb6" alt="Password Reset Flowを使用するには、Auth0 Dashboard > Actions > Flowsに移動します。" data-og-width="1550" width="1550" data-og-height="564" height="564" data-path="docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/translations/eVsQcTnbClN-oB7d/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=280&fit=max&auto=format&n=eVsQcTnbClN-oB7d&q=85&s=d9a8676bd131bf5b0c3a52c12a420b22 280w, https://mintcdn.com/translations/eVsQcTnbClN-oB7d/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=560&fit=max&auto=format&n=eVsQcTnbClN-oB7d&q=85&s=e75db55657059dc068c4079864494d05 560w, https://mintcdn.com/translations/eVsQcTnbClN-oB7d/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=840&fit=max&auto=format&n=eVsQcTnbClN-oB7d&q=85&s=f20075008d1096f2a8a6b273d021d33b 840w, https://mintcdn.com/translations/eVsQcTnbClN-oB7d/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=1100&fit=max&auto=format&n=eVsQcTnbClN-oB7d&q=85&s=719bc5a1848687873a2500231a5df8c4 1100w, https://mintcdn.com/translations/eVsQcTnbClN-oB7d/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=1650&fit=max&auto=format&n=eVsQcTnbClN-oB7d&q=85&s=7acc137afb38f17308a82f1aad7df2d3 1650w, https://mintcdn.com/translations/eVsQcTnbClN-oB7d/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=2500&fit=max&auto=format&n=eVsQcTnbClN-oB7d&q=85&s=5204cd5d35389abf044faa78a70ca8e2 2500w" />
</Frame>

このフローのActionsはブロッキング (同期) です。トリガーの処理の一部として実行され、Actionが完了するまでAuth0 pipelineの残りの処理は実行されません。

<Note>
  これらのActionsを正しく実行するには、Universal Loginを有効にする必要があります。クラシックログインを使用している場合、これらのActionsはトリガーされません。
</Note>

<div id="references">
  ## リファレンス
</div>

* [イベントオブジェクト](/docs/ja-jp/customize/actions/reference/password-reset-post-challenge/password-reset-post-challenge-event-object): パスワードをリセットするユーザーに関するコンテキスト情報を提供します。
* [API object](/docs/ja-jp/customize/actions/reference/password-reset-post-challenge/password-reset-post-challenge-api-object): フローの動作を変更するためのメソッドを提供します。

<div id="limitations">
  ## 制限事項
</div>

Password Reset トリガーでは、[Active Directory/LDAP 接続](/docs/ja-jp/authenticate/identity-providers/enterprise-identity-providers/active-directory-ldap)はサポートされていません。

<div id="common-use-cases">
  ## 一般的なユースケース
</div>

<div id="secure-password-reset-with-additional-mfa-factors">
  ### 追加のMFA認証要素による安全なパスワードリセット
</div>

ユーザーが最初のチャレンジを完了した後、post-challenge ActionでMFAチャレンジを実行できます。たとえば、tenantでWebAuthnが認証要素として有効になっている場合、二次認証要素としてWebAuthnベースのチャレンジを実行できます。

```javascript lines theme={null}
/**
 * @param {Event} event - パスワードをリセットするユーザーに関する詳細。
 * @param {PasswordResetPostChallengeAPI} api - パスワードリセットの動作を変更できるメソッドを提供するインターフェース。
 */
exports.onExecutePostChallenge = async (event, api) => {
  const enrolledFactors = event.user.enrolledFactors.map((x) => ({
    type: x.type
  }));
  api.authentication.challengeWith({ type: 'webauthn-roaming' }, { additionalFactors: enrolledFactors });
};
```

<div id="redirect-users-to-a-third-party-application">
  ### ユーザーをサードパーティアプリケーションにリダイレクトする
</div>

MFAチャレンジに加えて、カスタムActionにリダイレクトを追加することもできます。たとえば、サードパーティの検証サービスやリスク評価サービスにリダイレクトできます。このサンプルActionでは、ユーザーをサンプルアプリケーションにリダイレクトした後、Actionの処理を再開し、MFA認証要素によるチャレンジをユーザーに提示します。

```javascript lines theme={null}
/**
 * @param {Event} event - パスワードをリセットするユーザーに関する情報。
 * @param {PasswordResetPostChallengeAPI} api - パスワードリセットの動作を変更するためのメソッドを提供するインターフェース。
 */
exports.onExecutePostChallenge = async (event, api) => {
  // ユーザーを https://my-app.example.com にリダイレクトする
  api.redirect.sendUserTo('https://my-app.example.com');
};

/**
 * @param {Event} event - パスワードをリセットするユーザーに関する情報。
 * @param {PasswordResetPostChallengeAPI} api - パスワードリセットの動作を変更するためのメソッドを提供するインターフェース。
 */
exports.onContinuePostChallenge = async (event, api) => {
  const enrolledFactors = event.user.enrolledFactors.map((x) => ({
    type: x.type
  }));

  // メール OTP または登録済みの別の認証要素でユーザーにチャレンジする
  api.authentication.challengeWith({ type: 'email' }, { additionalFactors: enrolledFactors });

  // 複数の選択肢でユーザーにチャレンジする例
  // この場合はメール OTP または SMS OTP
  // api.authentication.challengeWithAny([{ type: 'email' }, { type: 'sms' }]);
};
```

Auth0 がユーザーをリダイレクトしている間は、Actions pipeline は実行されません。ユーザーが Auth0 のログインプロセスを続行すると、Actions pipeline が再開されます。リダイレクト前に実行された Actions が再度実行されることはありません。詳細については、[Redirect with Actions](/docs/ja-jp/customize/actions/redirect-with-actions) を参照してください。
