This MUST be a different endpoint from password change, with email validation
This MUST be a different endpoint from password change, with email validation