password reset: an admin makes a one-hour link, and using it signs the account out everywhere
CI & Build / Python lint (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Skipped
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 3s
CI & Build / Web typecheck and unit tests (push) Successful in 9s
CI & Build / Python tests (push) Failing after 12s
CI & Build / integration (push) Successful in 49s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 1m41s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 2m4s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 3m5s
Desktop (Tauri) / Update manifest (push) Successful in 5s

There is no mail path, so a forgotten password needed a hand on the database
(#2939 §2). Settings → People lists the accounts; Reset password makes a link
that works once within an hour, shown once for the admin to hand over. Making
another link for the same account closes the earlier one.

Using it (/reset-password) sets the password, deletes the account's device
tokens, and moves users.session_epoch on. Sessions are signed cookies the
server can't delete, so each now carries the epoch it signed in under and
login_required reads the account's epoch by primary key. A cookie from before
this has no epoch and reads as 0, the starting value, so the upgrade signs
nobody out. A deleted account's session now stops working too.

The one-time link reveal moves out of InviteList into OneTimeLink, and the
link-building into router/links.ts, shared by invites and resets.

Migration 0033. #5173.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-07 14:35:58 -04:00
co-authored by Claude Opus 5.5
parent 28fa8badcb
commit 3dd0b44cb9
17 changed files with 696 additions and 61 deletions
+108
View File
@@ -0,0 +1,108 @@
<script setup lang="ts">
import { computed, ref } from "vue";
import { useRoute, useRouter } from "vue-router";
import { api } from "../api/client";
import { errorMessage } from "../api/errors";
import { useSessionStore } from "../stores/session";
import { useConfigStore } from "../stores/config";
import BaseInput from "../components/BaseInput.vue";
import BaseButton from "../components/BaseButton.vue";
// Where a password reset link an admin made lands (#5173). Setting the password signs
// this browser in and every other session and linked app out.
const session = useSessionStore();
const config = useConfigStore();
const router = useRouter();
const route = useRoute();
const token = computed(() => (typeof route.query.token === "string" ? route.query.token : ""));
const password = ref("");
const confirm = ref("");
const error = ref("");
const loading = ref(false);
async function submit() {
error.value = "";
if (password.value.length < 8) {
error.value = "Password must be at least 8 characters.";
return;
}
if (password.value !== confirm.value) {
error.value = "The two passwords don't match.";
return;
}
loading.value = true;
try {
await api.post("/api/auth/reset-password", { token: token.value, password: password.value });
await session.fetchMe();
await router.replace("/");
} catch (e) {
error.value = errorMessage(e, "Couldn't set your password.");
} finally {
loading.value = false;
}
}
</script>
<template>
<main class="flex min-h-full items-center justify-center px-4 py-12">
<div class="w-full max-w-sm">
<div class="mb-8 text-center">
<img
src="/icon.svg"
:alt="config.siteName"
class="mx-auto mb-3 h-12 w-12 rounded-xl"
width="48"
height="48"
/>
<h1 class="text-2xl font-bold tracking-tight">Choose a new password</h1>
<p class="mt-1 text-sm text-neutral-500 dark:text-neutral-400">
You'll be signed out everywhere else, and your apps will ask you to sign in again.
</p>
</div>
<p
v-if="!token"
role="alert"
class="rounded-lg bg-red-50 px-3 py-2 text-sm text-red-700 dark:bg-red-950/50 dark:text-red-300"
>
This link is incomplete. Ask your admin for a new one.
</p>
<form v-else class="flex flex-col gap-4" novalidate @submit.prevent="submit">
<BaseInput
id="password"
v-model="password"
label="New password"
type="password"
autocomplete="new-password"
placeholder="At least 8 characters"
required
/>
<BaseInput
id="confirm"
v-model="confirm"
label="Again"
type="password"
autocomplete="new-password"
required
/>
<p
v-if="error"
role="alert"
class="rounded-lg bg-red-50 px-3 py-2 text-sm text-red-700 dark:bg-red-950/50 dark:text-red-300"
>
{{ error }}
</p>
<BaseButton type="submit" :loading="loading">Set password</BaseButton>
</form>
<p class="mt-6 text-center text-sm text-neutral-500 dark:text-neutral-400">
<RouterLink to="/login" class="font-semibold text-brand-700 hover:underline dark:text-brand"
>Back to sign in</RouterLink
>
</p>
</div>
</main>
</template>
+4 -2
View File
@@ -4,6 +4,7 @@ import { api } from "../api/client";
import { useConfigStore } from "../stores/config";
import BaseButton from "../components/BaseButton.vue";
import InviteList from "../components/InviteList.vue";
import AccountList from "../components/AccountList.vue";
import { errorMessage } from "../api/errors";
interface SettingItem {
@@ -172,8 +173,9 @@ onMounted(load);
</div>
</form>
<!-- Outside the settings form: each invite action saves on its own, and the
form's Save button has nothing to do with them. -->
<!-- Outside the settings form: each invite and account action saves on its own,
and the form's Save button has nothing to do with them. -->
<InviteList v-if="items.length" class="mt-10" />
<AccountList v-if="items.length" class="mt-10" />
</div>
</template>