This reset flow stays tied to the Minecraft server itself. PluginManager prints a short-lived recovery code to the server console, then you use that code here to set a new password.
Enter the dashboard username. If that account exists, PluginManager will print a one-time recovery code to the server console. The page keeps the response generic on purpose, so outside visitors cannot confirm who has an account.
Use the code from the console within 10 minutes. Once the new password is saved, the old one stops working right away.
dashboard-accounts.yml as salted hashes, not plain text.