Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

LOGOUT_ON_PASSWORD_CHANGE: Is this session based or token based #634

Open
sant527 opened this issue Dec 3, 2020 · 0 comments
Open

LOGOUT_ON_PASSWORD_CHANGE: Is this session based or token based #634

sant527 opened this issue Dec 3, 2020 · 0 comments

Comments

@sant527
Copy link

sant527 commented Dec 3, 2020

I am using django-rest-auth

I am implementing password change.

I found this option: at https://django-rest-auth.readthedocs.io/en/latest/api_endpoints.html

LOGOUT_ON_PASSWORD_CHANGE = False to keep the user logged in after password change

I wanted to understand the flow.

I sent my password details

old_password
new_password1
new_password2

to the endpoint /rest-auth/password/change/ (POST)

curl --location --request POST "http://127.0.0.1:8000/rest-auth/password/change/" \
--header "Authorization:Token a42fdd3938ad24d8abd064d3fedhsh599115e38b6a" \
--header 'Content-Type: application/json' \
--data-raw '{ 
	"old_password": "oldP"
	"new_password1": "newP"
	"new_password2": "newP"
}'

Now what happens to my token on LOGOUT_ON_PASSWORD_CHANGE = True

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant