diff --git a/src/auth/session.ts b/src/auth/session.ts index 408794a..1c0fd27 100644 --- a/src/auth/session.ts +++ b/src/auth/session.ts @@ -165,17 +165,19 @@ export const MIN_PASSWORD_LENGTH = 6; /** * Sets the password on an account that has never had one. * - * `PUT /users/update` doubles as the password call. There is no dedicated - * endpoint and no reset flow — the controller says so in as many words - * (`userController.go:145`): "this endpoint also doubles as the - * password-setup/reset call (userid + password only, everything else left zero - * so GORM's `Updates` skips it)". Sending only those two fields is therefore - * load-bearing: a struct with any other field populated would write it. + * `POST /users/setpassword`, which is public — it has to be. This runs when + * nobody is signed in and cannot be: the account has no password yet, so there + * is no way to obtain a session first. * - * This is reachable only with the `userid` that `applogin` just handed back for - * an account it confirmed has an empty password. It is not a "change my - * password" call and must not be wired up as one — nothing here verifies the - * old password, because there is no old password. + * It used to call `PUT /users/update`, which doubles as a password write but + * sits behind the session guard. Once `WEB_AUTH_REQUIRED` began defaulting on, + * that returned "a session token is required; sign in again" to somebody who + * could not sign in — sign-in needs a password, and setting the password needed + * a sign-in. Every branch login created with an empty password was unusable. + * + * The server refuses this on any account that already HAS a password, which is + * what makes leaving it open safe. It is a setup call, never a reset — nothing + * here verifies an old password, because there is no old password. * * Passwords are stored in clear on this backend. That is not something the * console can fix, and it is the reason this flow exists at all rather than an @@ -185,7 +187,7 @@ export async function setInitialPassword(userid: number, password: string): Prom if (password.length < MIN_PASSWORD_LENGTH) { throw new Error(`Use at least ${MIN_PASSWORD_LENGTH} characters.`); } - await api.put(`${WEB}/users/update`, { userid, password }); + await api.post(`${WEB}/users/setpassword`, { userid, password }); } /**