# TELSPAY Student Login Access v2026.9.5.1

## Purpose

Allows an authorized SACCO Administrator to resend secure Student Portal login access without exposing the student's existing password or 4-digit transaction PIN.

## Admin workflow

1. Open **Education Control Center → Student Login Access** or **Student Wallets → Student Login Access**.
2. Search by student name/reference, wallet number, email, phone or school.
3. Select **Resend Login**.
4. Choose Email, SMS, or both.
5. TELSPAY queues the wallet/login number and a single-use password setup/reset link.
6. The student follows the link and chooses a new password.
7. TELSPAY marks the link USED and revokes other unused links.

## Security rules

- Permission: `education.student_wallet.credentials`.
- Existing passwords are never readable or sent.
- Transaction PINs are never included in login messages.
- Only the one-time token's HMAC hash is stored in the access-token table.
- Notification content containing the one-time URL is redacted after successful delivery.
- Expired/revoked queued messages are cancelled and scrubbed by the notification worker.
- Default link expiry is 30 minutes.
- Default resend cooldown is 5 minutes.
- Issuance and use are audited.

## Deployment

Import:

`database/TELSPAY_EDUCATION_STUDENT_LOGIN_ACCESS_V2026_9_5_1.sql`

Ensure private `telspay_secure/education/local.php` contains a strong `token_pepper` and correct Student Portal URL. Optional policy overrides:

```php
'student_login_reset_minutes' => 30,
'student_login_resend_cooldown_seconds' => 300,
```

Keep the existing notification worker/cron enabled so queued Email/SMS can be delivered and expired secure messages can be scrubbed.
