password reset: an admin makes a one-hour link, and using it signs the account out everywhere
CI & Build / Python lint (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Skipped
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 3s
CI & Build / Web typecheck and unit tests (push) Successful in 9s
CI & Build / Python tests (push) Failing after 12s
CI & Build / integration (push) Successful in 49s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 1m41s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 2m4s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 3m5s
Desktop (Tauri) / Update manifest (push) Successful in 5s

There is no mail path, so a forgotten password needed a hand on the database
(#2939 §2). Settings → People lists the accounts; Reset password makes a link
that works once within an hour, shown once for the admin to hand over. Making
another link for the same account closes the earlier one.

Using it (/reset-password) sets the password, deletes the account's device
tokens, and moves users.session_epoch on. Sessions are signed cookies the
server can't delete, so each now carries the epoch it signed in under and
login_required reads the account's epoch by primary key. A cookie from before
this has no epoch and reads as 0, the starting value, so the upgrade signs
nobody out. A deleted account's session now stops working too.

The one-time link reveal moves out of InviteList into OneTimeLink, and the
link-building into router/links.ts, shared by invites and resets.

Migration 0033. #5173.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-07 14:35:58 -04:00
co-authored by Claude Opus 5.5
parent 28fa8badcb
commit 3dd0b44cb9
17 changed files with 696 additions and 61 deletions
+9
View File
@@ -72,6 +72,15 @@ const router = createRouter({
component: () => import("../views/RegisterView.vue"),
meta: { title: "Create account", guestOnly: true },
},
{
// Where an admin-made password reset link lands (#5173). Not guest-only: the
// link signs in whoever uses it as the account it was made for, whoever was
// signed in on this browser before.
path: "/reset-password",
name: "reset-password",
component: () => import("../views/ResetPasswordView.vue"),
meta: { title: "Reset password" },
},
],
});
+9
View File
@@ -0,0 +1,9 @@
import type { RouteLocationRaw } from "vue-router";
import router from "./index";
/** A full link to a page of this app, as people reach this server: what an admin
* copies into a message (an invite, a password reset link). Built here because only
* the browser knows the address people actually use. */
export function appLink(to: RouteLocationRaw): string {
return new URL(router.resolve(to).href, window.location.origin).href;
}