From 588f63505d46d5f283890f776fabd54dedc917f0 Mon Sep 17 00:00:00 2001 From: DarkSky <25152247+darkskygit@users.noreply.github.com> Date: Fri, 27 Oct 2023 04:52:29 -0500 Subject: [PATCH] fix: password reset token (#4743) --- packages/backend/server/src/modules/auth/resolver.ts | 7 ++++--- packages/backend/server/src/modules/auth/service.ts | 9 ++++++--- 2 files changed, 10 insertions(+), 6 deletions(-) diff --git a/packages/backend/server/src/modules/auth/resolver.ts b/packages/backend/server/src/modules/auth/resolver.ts index afce7b787..f225a000d 100644 --- a/packages/backend/server/src/modules/auth/resolver.ts +++ b/packages/backend/server/src/modules/auth/resolver.ts @@ -135,12 +135,13 @@ export class AuthResolver { @Args('token') token: string, @Args('newPassword') newPassword: string ) { - const id = await this.session.get(token); - if (!id || id !== user.id) { + // we only create user account after user sign in with email link + const email = await this.session.get(token); + if (!email || email !== user.email || !user.emailVerified) { throw new ForbiddenException('Invalid token'); } - await this.auth.changePassword(id, newPassword); + await this.auth.changePassword(email, newPassword); await this.session.delete(token); return user; diff --git a/packages/backend/server/src/modules/auth/service.ts b/packages/backend/server/src/modules/auth/service.ts index 822d0e525..91652c34d 100644 --- a/packages/backend/server/src/modules/auth/service.ts +++ b/packages/backend/server/src/modules/auth/service.ts @@ -233,10 +233,13 @@ export class AuthService { return Boolean(user.password); } - async changePassword(id: string, newPassword: string): Promise { + async changePassword(email: string, newPassword: string): Promise { const user = await this.prisma.user.findUnique({ where: { - id, + email, + emailVerified: { + not: null, + }, }, }); @@ -248,7 +251,7 @@ export class AuthService { return this.prisma.user.update({ where: { - id, + id: user.id, }, data: { password: hashedPassword,