login fix
This commit is contained in:
@@ -324,3 +324,50 @@ func (ctl *UserController) DeleteUser(c *fiber.Ctx) error {
|
||||
})
|
||||
}
|
||||
|
||||
// SetPassword gives a never-used account its first password.
|
||||
//
|
||||
// ── Why this endpoint exists ────────────────────────────────────────────────
|
||||
//
|
||||
// Because the flow was impossible without it. A branch login created by
|
||||
// `createtenantlocation` arrives with an empty password; the console signs in,
|
||||
// is told to set one, and does so — through `PUT /users/update`, which sits
|
||||
// behind the session guard. So the call answered "a session token is required;
|
||||
// sign in again" to a person who could not sign in, because they had no
|
||||
// password yet. Every such account was unusable.
|
||||
//
|
||||
// `publicWebPaths` has named `/users/setpassword` since the guard was written.
|
||||
// The path was reserved and the handler never built, so it answered 404 and the
|
||||
// console went on using the guarded one.
|
||||
//
|
||||
// ── Why not simply open up `/users/update` ──────────────────────────────────
|
||||
//
|
||||
// It writes whatever struct it is handed. Unauthenticated, it would let anybody
|
||||
// change any field of any user — their email, their role, their tenant. This
|
||||
// takes two fields and can only act on an account with no password, which is
|
||||
// what makes it safe to leave open. See the repository for the rest.
|
||||
func (ctl *UserController) SetPassword(c *fiber.Ctx) error {
|
||||
var req struct {
|
||||
Userid int `json:"userid"`
|
||||
Password string `json:"password"`
|
||||
}
|
||||
if err := c.BodyParser(&req); err != nil {
|
||||
return c.Status(http.StatusBadRequest).JSON(fiber.Map{
|
||||
"status": false, "code": http.StatusBadRequest, "message": "Invalid request body",
|
||||
})
|
||||
}
|
||||
|
||||
if err := ctl.userService.SetInitialPassword(req.Userid, req.Password); err != nil {
|
||||
// 409, not 401. Nothing about this is an authentication failure — the
|
||||
// caller is not supposed to have a session — and answering 401 would
|
||||
// send the console into its sign-out-and-reload path on the one screen
|
||||
// where there is nothing to sign out of.
|
||||
return c.Status(http.StatusConflict).JSON(fiber.Map{
|
||||
"status": false, "code": http.StatusConflict, "message": err.Error(),
|
||||
})
|
||||
}
|
||||
|
||||
return c.JSON(fiber.Map{
|
||||
"status": true, "code": http.StatusOK,
|
||||
"message": "Password set. Sign in with it.",
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user