Commit 0547013
authored
* fix(auth): enforce zxcvbn strength check on password reset (#3721)
The reset handler was calling hashPassword directly without first calling
checkPassword, allowing weak passwords through the token-based reset flow.
Add checkPassword call before hash (mirroring updatePassword), and add an
integration test asserting weak passwords are rejected with 422.
* test(auth): add checkPassword mock to silent-catch unit test
The auth.service mock in auth.silent.catch.unit.tests.js was missing
checkPassword, causing the reset handler to throw a TypeError when the
fix calls AuthService.checkPassword(). Add it as a pass-through stub.
* fix(auth): coerce newPassword to string before checkPassword in reset
Mirrors the String() coercion already applied to token and email inputs
in the same handler; guards against non-string body values reaching zxcvbn.
1 parent d42eb12 commit 0547013
3 files changed
Lines changed: 35 additions & 2 deletions
File tree
- modules/auth
- controllers
- tests
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
89 | 89 | | |
90 | 90 | | |
91 | 91 | | |
| 92 | + | |
92 | 93 | | |
93 | 94 | | |
94 | 95 | | |
95 | 96 | | |
| 97 | + | |
96 | 98 | | |
97 | | - | |
| 99 | + | |
98 | 100 | | |
99 | 101 | | |
100 | 102 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1245 | 1245 | | |
1246 | 1246 | | |
1247 | 1247 | | |
| 1248 | + | |
| 1249 | + | |
| 1250 | + | |
| 1251 | + | |
| 1252 | + | |
| 1253 | + | |
| 1254 | + | |
| 1255 | + | |
| 1256 | + | |
| 1257 | + | |
| 1258 | + | |
| 1259 | + | |
| 1260 | + | |
| 1261 | + | |
| 1262 | + | |
| 1263 | + | |
| 1264 | + | |
| 1265 | + | |
| 1266 | + | |
| 1267 | + | |
| 1268 | + | |
| 1269 | + | |
| 1270 | + | |
| 1271 | + | |
| 1272 | + | |
| 1273 | + | |
| 1274 | + | |
| 1275 | + | |
| 1276 | + | |
| 1277 | + | |
| 1278 | + | |
1248 | 1279 | | |
1249 | 1280 | | |
1250 | 1281 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
184 | 184 | | |
185 | 185 | | |
186 | 186 | | |
187 | | - | |
| 187 | + | |
188 | 188 | | |
189 | 189 | | |
190 | 190 | | |
| |||
0 commit comments