Android / Build, or is the channel already serving this? (push) Successful in 4s
Android / Kotlin + Rust (APK) (push) Skipped
CI & Build / Build now, or wait for Android? (push) Successful in 2s
CI & Build / Web typecheck and unit tests (push) Successful in 11s
CI & Build / Python lint (push) Successful in 2s
CI & Build / Python tests (push) Successful in 15s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 3s
CI & Build / integration (push) Successful in 1m16s
CI & Build / Build & push image (push) Successful in 1m15s
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 2m49s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 3m26s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 4m26s
Desktop (Tauri) / Update manifest (push) Successful in 4s
The operator asked for self-service reset over SMTP. It reuses #5173's password_resets table, /reset-password page, one-hour single-use token and sign-out-everywhere. - Settings (rule 25, not env): a new Email group (SMTP server, port, encryption as a choice, username, password, from), General → Public address, and Security → Reset emails per account. The registry gains `choices`, `secret` (the value is never sent back, `is_set` says one is saved, an empty save keeps it) and `url` (http(s), trailing slash stripped). - mailer.py: stdlib smtplib on a worker thread, 20 s timeout, starttls | tls | none. mail_settings() is None until a server, a sender and the public address are set. Links are built from the public address because the Host header can be forged. - POST /api/auth/forgot-password: the same answer at the same speed for any address. The link is made and mailed off the request (send_later). It is throttled like a sign-in per visitor address, and capped per typed email by reset_emails_per_account; past the cap it answers the same and sends nothing. - POST /api/settings/test-email: mails the admin with the saved settings and shows the server's error if it fails. - Public config `password_reset_by_email`. Sign-in shows "Forgot password?" only then, linking to a new /forgot-password page. - docs/public-hosting.md: an "Email and forgotten passwords" section. Tests: the secret stays server-side; emailed link → reset; the same answer for unknown addresses; the cap; test email success and failure; validation units. #5266. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
85 lines
2.6 KiB
Vue
85 lines
2.6 KiB
Vue
<script setup lang="ts">
|
|
import { ref } from "vue";
|
|
import { useRoute } from "vue-router";
|
|
import { api } from "../api/client";
|
|
import { errorMessage } from "../api/errors";
|
|
import { useConfigStore } from "../stores/config";
|
|
import BaseInput from "../components/BaseInput.vue";
|
|
import BaseButton from "../components/BaseButton.vue";
|
|
|
|
// Ask for a password reset link by email (#5266). The server answers the same way
|
|
// whether or not the address has an account, so this page does too.
|
|
|
|
const config = useConfigStore();
|
|
const route = useRoute();
|
|
|
|
const email = ref(typeof route.query.email === "string" ? route.query.email : "");
|
|
const sent = ref("");
|
|
const error = ref("");
|
|
const loading = ref(false);
|
|
|
|
async function submit() {
|
|
error.value = "";
|
|
loading.value = true;
|
|
try {
|
|
const res = await api.post<{ message: string }>("/api/auth/forgot-password", { email: email.value });
|
|
sent.value = res.message;
|
|
} catch (e) {
|
|
error.value = errorMessage(e, "Couldn't send a reset link.");
|
|
} finally {
|
|
loading.value = false;
|
|
}
|
|
}
|
|
</script>
|
|
|
|
<template>
|
|
<main class="flex min-h-full items-center justify-center px-4 py-12">
|
|
<div class="w-full max-w-sm">
|
|
<div class="mb-8 text-center">
|
|
<img
|
|
src="/icon.svg"
|
|
:alt="config.siteName"
|
|
class="mx-auto mb-3 h-12 w-12 rounded-xl"
|
|
width="48"
|
|
height="48"
|
|
/>
|
|
<h1 class="text-2xl font-bold tracking-tight">Forgot your password?</h1>
|
|
<p class="mt-1 text-sm text-neutral-500 dark:text-neutral-400">We'll email you a link to choose a new one.</p>
|
|
</div>
|
|
|
|
<p
|
|
v-if="sent"
|
|
role="status"
|
|
class="rounded-lg bg-green-50 px-3 py-2 text-sm text-green-800 dark:bg-green-950/50 dark:text-green-300"
|
|
>
|
|
{{ sent }}
|
|
</p>
|
|
<form v-else class="flex flex-col gap-4" novalidate @submit.prevent="submit">
|
|
<BaseInput
|
|
id="email"
|
|
v-model="email"
|
|
label="Email"
|
|
type="email"
|
|
autocomplete="email"
|
|
placeholder="you@example.com"
|
|
required
|
|
/>
|
|
<p
|
|
v-if="error"
|
|
role="alert"
|
|
class="rounded-lg bg-red-50 px-3 py-2 text-sm text-red-700 dark:bg-red-950/50 dark:text-red-300"
|
|
>
|
|
{{ error }}
|
|
</p>
|
|
<BaseButton type="submit" :loading="loading">Send reset link</BaseButton>
|
|
</form>
|
|
|
|
<p class="mt-6 text-center text-sm text-neutral-500 dark:text-neutral-400">
|
|
<RouterLink to="/login" class="font-semibold text-brand-700 hover:underline dark:text-brand"
|
|
>Back to sign in</RouterLink
|
|
>
|
|
</p>
|
|
</div>
|
|
</main>
|
|
</template>
|