fix: password reset to invalidate all existing reset tokens for that uid

v1.18.x
Julian Lam 4 years ago
parent ba2e1c4c7e
commit 30b3fedca4

@ -325,6 +325,7 @@ module.exports = function (User) {
password: hashedPassword, password: hashedPassword,
rss_token: utils.generateUUID(), rss_token: utils.generateUUID(),
}), }),
User.reset.cleanByUid(data.uid),
User.reset.updateExpiry(data.uid), User.reset.updateExpiry(data.uid),
User.auth.revokeAllSessions(data.uid), User.auth.revokeAllSessions(data.uid),
]); ]);

Loading…
Cancel
Save