fix: password reset token (#4743)
This commit is contained in:
@@ -135,12 +135,13 @@ export class AuthResolver {
|
|||||||
@Args('token') token: string,
|
@Args('token') token: string,
|
||||||
@Args('newPassword') newPassword: string
|
@Args('newPassword') newPassword: string
|
||||||
) {
|
) {
|
||||||
const id = await this.session.get(token);
|
// we only create user account after user sign in with email link
|
||||||
if (!id || id !== user.id) {
|
const email = await this.session.get(token);
|
||||||
|
if (!email || email !== user.email || !user.emailVerified) {
|
||||||
throw new ForbiddenException('Invalid token');
|
throw new ForbiddenException('Invalid token');
|
||||||
}
|
}
|
||||||
|
|
||||||
await this.auth.changePassword(id, newPassword);
|
await this.auth.changePassword(email, newPassword);
|
||||||
await this.session.delete(token);
|
await this.session.delete(token);
|
||||||
|
|
||||||
return user;
|
return user;
|
||||||
|
|||||||
@@ -233,10 +233,13 @@ export class AuthService {
|
|||||||
return Boolean(user.password);
|
return Boolean(user.password);
|
||||||
}
|
}
|
||||||
|
|
||||||
async changePassword(id: string, newPassword: string): Promise<User> {
|
async changePassword(email: string, newPassword: string): Promise<User> {
|
||||||
const user = await this.prisma.user.findUnique({
|
const user = await this.prisma.user.findUnique({
|
||||||
where: {
|
where: {
|
||||||
id,
|
email,
|
||||||
|
emailVerified: {
|
||||||
|
not: null,
|
||||||
|
},
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -248,7 +251,7 @@ export class AuthService {
|
|||||||
|
|
||||||
return this.prisma.user.update({
|
return this.prisma.user.update({
|
||||||
where: {
|
where: {
|
||||||
id,
|
id: user.id,
|
||||||
},
|
},
|
||||||
data: {
|
data: {
|
||||||
password: hashedPassword,
|
password: hashedPassword,
|
||||||
|
|||||||
Reference in New Issue
Block a user