Verifies the OTP received from POST /auth-forgot-password and sets a new password.
password and confirm_password must match. OTP is consumed on success.
All existing sessions across every device are invalidated immediately after the password is updated.