mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 22:27:48 +00:00
fix: password resets not working
This commit is contained in:
@@ -19,7 +19,9 @@ export const registerUserRouter = async (server: FastifyZodProvider) => {
|
|||||||
schema: {
|
schema: {
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
user: UsersSchema
|
user: UsersSchema.extend({
|
||||||
|
encryptionVersion: z.number()
|
||||||
|
})
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { authRateLimit } from "@app/server/config/rateLimiter";
|
import { authRateLimit } from "@app/server/config/rateLimiter";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { validatePasswordResetAuthorization } from "@app/services/auth/auth-fns";
|
import { validatePasswordResetAuthorization } from "@app/services/auth/auth-fns";
|
||||||
@@ -41,13 +42,38 @@ export const registerPasswordRouter = async (server: FastifyZodProvider) => {
|
|||||||
rateLimit: authRateLimit
|
rateLimit: authRateLimit
|
||||||
},
|
},
|
||||||
onRequest: verifyAuth([AuthMode.JWT], { requireOrg: false }),
|
onRequest: verifyAuth([AuthMode.JWT], { requireOrg: false }),
|
||||||
handler: async (req) => {
|
handler: async (req, res) => {
|
||||||
|
const appCfg = getConfig();
|
||||||
|
|
||||||
await server.services.password.resetPasswordV2({
|
await server.services.password.resetPasswordV2({
|
||||||
type: ResetPasswordV2Type.LoggedInReset,
|
type: ResetPasswordV2Type.LoggedInReset,
|
||||||
userId: req.permission.id,
|
userId: req.permission.id,
|
||||||
newPassword: req.body.newPassword,
|
newPassword: req.body.newPassword,
|
||||||
oldPassword: req.body.oldPassword
|
oldPassword: req.body.oldPassword
|
||||||
});
|
});
|
||||||
|
|
||||||
|
void res.cookie("jid", "", {
|
||||||
|
httpOnly: true,
|
||||||
|
path: "/",
|
||||||
|
sameSite: "strict",
|
||||||
|
secure: appCfg.HTTPS_ENABLED
|
||||||
|
});
|
||||||
|
|
||||||
|
void res.cookie("infisical-project-assume-privileges", "", {
|
||||||
|
httpOnly: true,
|
||||||
|
path: "/",
|
||||||
|
sameSite: "strict",
|
||||||
|
secure: appCfg.HTTPS_ENABLED,
|
||||||
|
maxAge: 0
|
||||||
|
});
|
||||||
|
|
||||||
|
void res.cookie("aod", "", {
|
||||||
|
httpOnly: false,
|
||||||
|
path: "/",
|
||||||
|
sameSite: "lax",
|
||||||
|
secure: appCfg.HTTPS_ENABLED,
|
||||||
|
maxAge: 0
|
||||||
|
});
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user