mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Merge pull request #3631 from Infisical/daniel/password-resets-fix
fix(password-resets): allow password resets when users don't have a password set
This commit is contained in:
@@ -189,16 +189,15 @@ export const authPaswordServiceFactory = ({
|
|||||||
throw new BadRequestError({ message: `User encryption key not found for user with ID '${userId}'` });
|
throw new BadRequestError({ message: `User encryption key not found for user with ID '${userId}'` });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!user.hashedPassword) {
|
|
||||||
throw new BadRequestError({ message: "Unable to reset password, no password is set" });
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!user.authMethods?.includes(AuthMethod.EMAIL)) {
|
if (!user.authMethods?.includes(AuthMethod.EMAIL)) {
|
||||||
throw new BadRequestError({ message: "Unable to reset password, no email authentication method is configured" });
|
throw new BadRequestError({ message: "Unable to reset password, no email authentication method is configured" });
|
||||||
}
|
}
|
||||||
|
|
||||||
// we check the old password if the user is resetting their password while logged in
|
// we check the old password if the user is resetting their password while logged in
|
||||||
if (type === ResetPasswordV2Type.LoggedInReset) {
|
if (type === ResetPasswordV2Type.LoggedInReset) {
|
||||||
|
if (!user.hashedPassword) {
|
||||||
|
throw new BadRequestError({ message: "Unable to change password, no password is set" });
|
||||||
|
}
|
||||||
if (!oldPassword) {
|
if (!oldPassword) {
|
||||||
throw new BadRequestError({ message: "Current password is required." });
|
throw new BadRequestError({ message: "Current password is required." });
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user