login fix
This commit is contained in:
@@ -165,17 +165,19 @@ export const MIN_PASSWORD_LENGTH = 6;
|
||||
/**
|
||||
* Sets the password on an account that has never had one.
|
||||
*
|
||||
* `PUT /users/update` doubles as the password call. There is no dedicated
|
||||
* endpoint and no reset flow — the controller says so in as many words
|
||||
* (`userController.go:145`): "this endpoint also doubles as the
|
||||
* password-setup/reset call (userid + password only, everything else left zero
|
||||
* so GORM's `Updates` skips it)". Sending only those two fields is therefore
|
||||
* load-bearing: a struct with any other field populated would write it.
|
||||
* `POST /users/setpassword`, which is public — it has to be. This runs when
|
||||
* nobody is signed in and cannot be: the account has no password yet, so there
|
||||
* is no way to obtain a session first.
|
||||
*
|
||||
* This is reachable only with the `userid` that `applogin` just handed back for
|
||||
* an account it confirmed has an empty password. It is not a "change my
|
||||
* password" call and must not be wired up as one — nothing here verifies the
|
||||
* old password, because there is no old password.
|
||||
* It used to call `PUT /users/update`, which doubles as a password write but
|
||||
* sits behind the session guard. Once `WEB_AUTH_REQUIRED` began defaulting on,
|
||||
* that returned "a session token is required; sign in again" to somebody who
|
||||
* could not sign in — sign-in needs a password, and setting the password needed
|
||||
* a sign-in. Every branch login created with an empty password was unusable.
|
||||
*
|
||||
* The server refuses this on any account that already HAS a password, which is
|
||||
* what makes leaving it open safe. It is a setup call, never a reset — nothing
|
||||
* here verifies an old password, because there is no old password.
|
||||
*
|
||||
* Passwords are stored in clear on this backend. That is not something the
|
||||
* console can fix, and it is the reason this flow exists at all rather than an
|
||||
@@ -185,7 +187,7 @@ export async function setInitialPassword(userid: number, password: string): Prom
|
||||
if (password.length < MIN_PASSWORD_LENGTH) {
|
||||
throw new Error(`Use at least ${MIN_PASSWORD_LENGTH} characters.`);
|
||||
}
|
||||
await api.put<unknown>(`${WEB}/users/update`, { userid, password });
|
||||
await api.post<unknown>(`${WEB}/users/setpassword`, { userid, password });
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user