Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Strip resetToken and resetTokenExpiresAt from dbAuth forgotPassword handler #6778

Merged
merged 4 commits into from
Nov 3, 2022

Conversation

cannikin
Copy link
Member

@cannikin cannikin commented Nov 2, 2022

Closes #6343

@cannikin cannikin added topic/auth release:fix This PR is a fix labels Nov 2, 2022
@cannikin cannikin self-assigned this Nov 2, 2022
@cannikin cannikin merged commit 82780ae into main Nov 3, 2022
@cannikin cannikin deleted the rc-resettoken branch November 3, 2022 21:49
@redwoodjs-bot redwoodjs-bot bot added this to the next-release milestone Nov 3, 2022
github-actions bot pushed a commit that referenced this pull request Nov 3, 2022
…andler (#6778)

* Clear reset token with built-in function

* Remove any resetToken or resetTokenExpiresAt from forgotPassword handler response

* Updates test for forgotPassword return data
jtoar pushed a commit that referenced this pull request Nov 3, 2022
…andler (#6778)

* Clear reset token with built-in function

* Remove any resetToken or resetTokenExpiresAt from forgotPassword handler response

* Updates test for forgotPassword return data
dac09 added a commit that referenced this pull request Nov 7, 2022
…aching

* 'main' of github.com:redwoodjs/redwood: (21 commits)
  [Tutorial]: Fix Typescript code blocks inconsistency (#6801)
  chore: update all contributors
  Custom auth: Fix comment in template (#6804)
  fix(deps): update dependency eslint to v8.26.0 (#6785)
  [CRWA]: Switch to using enquirer, add engine compatibility override option (#6723)
  (docs): Minor Command update about Storybook (#6722)
  docs: Add mocking useLocation to docs (#6791)
  Update generated render.yaml (#6771)
  fix flightcontrol config template (#6789)
  fix: publish canary using premajor (#6794)
  Strip resetToken and resetTokenExpiresAt from dbAuth forgotPassword handler (#6778)
  Fix WebAuthn when event body is base64 encoded (like when deploying to Vercel) (#6757)
  fix(deps): update jest monorepo (#6787)
  fix(deps): update dependency react-hook-form to v7.39.1 (#6786)
  fix(deps): update dependency fastify to v4.9.2 (#6781)
  fix(deps): update dependency @apollo/client to v3.7.1 (#6780)
  chore: fix and rebuild test project fixture (#6775)
  fix: add prisma resolutions to tutorial e2e test proj (#6772)
  fix(deps): update prisma monorepo to v4.5.0 (#6485)
  Fix dbauth webauthn template (redundant type import) (#6769)
  ...
jtoar pushed a commit that referenced this pull request Nov 8, 2022
…andler (#6778)

* Clear reset token with built-in function

* Remove any resetToken or resetTokenExpiresAt from forgotPassword handler response

* Updates test for forgotPassword return data
jtoar pushed a commit that referenced this pull request Nov 8, 2022
…andler (#6778)

* Clear reset token with built-in function

* Remove any resetToken or resetTokenExpiresAt from forgotPassword handler response

* Updates test for forgotPassword return data
jtoar pushed a commit that referenced this pull request Nov 8, 2022
…andler (#6778)

* Clear reset token with built-in function

* Remove any resetToken or resetTokenExpiresAt from forgotPassword handler response

* Updates test for forgotPassword return data
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

[Bug?]: Default dbAuth workflow leaks resetToken
2 participants