summaryrefslogtreecommitdiff
path: root/packages/backend/src/server/api/endpoints/request-reset-password.ts
diff options
context:
space:
mode:
authorsyuilo <Syuilotan@yahoo.co.jp>2021-11-12 02:02:25 +0900
committersyuilo <Syuilotan@yahoo.co.jp>2021-11-12 02:02:25 +0900
commit0e4a111f81cceed275d9bec2695f6e401fb654d8 (patch)
tree40874799472fa07416f17b50a398ac33b7771905 /packages/backend/src/server/api/endpoints/request-reset-password.ts
parentupdate deps (diff)
downloadsharkey-0e4a111f81cceed275d9bec2695f6e401fb654d8.tar.gz
sharkey-0e4a111f81cceed275d9bec2695f6e401fb654d8.tar.bz2
sharkey-0e4a111f81cceed275d9bec2695f6e401fb654d8.zip
refactoring
Resolve #7779
Diffstat (limited to 'packages/backend/src/server/api/endpoints/request-reset-password.ts')
-rw-r--r--packages/backend/src/server/api/endpoints/request-reset-password.ts73
1 files changed, 73 insertions, 0 deletions
diff --git a/packages/backend/src/server/api/endpoints/request-reset-password.ts b/packages/backend/src/server/api/endpoints/request-reset-password.ts
new file mode 100644
index 0000000000..f9928c2ee6
--- /dev/null
+++ b/packages/backend/src/server/api/endpoints/request-reset-password.ts
@@ -0,0 +1,73 @@
+import $ from 'cafy';
+import { publishMainStream } from '@/services/stream';
+import define from '../define';
+import rndstr from 'rndstr';
+import config from '@/config/index';
+import * as ms from 'ms';
+import { Users, UserProfiles, PasswordResetRequests } from '@/models/index';
+import { sendEmail } from '@/services/send-email';
+import { ApiError } from '../error';
+import { genId } from '@/misc/gen-id';
+import { IsNull } from 'typeorm';
+
+export const meta = {
+ requireCredential: false as const,
+
+ limit: {
+ duration: ms('1hour'),
+ max: 3
+ },
+
+ params: {
+ username: {
+ validator: $.str
+ },
+
+ email: {
+ validator: $.str
+ },
+ },
+
+ errors: {
+
+ }
+};
+
+export default define(meta, async (ps) => {
+ const user = await Users.findOne({
+ usernameLower: ps.username.toLowerCase(),
+ host: IsNull()
+ });
+
+ // 合致するユーザーが登録されていなかったら無視
+ if (user == null) {
+ return;
+ }
+
+ const profile = await UserProfiles.findOneOrFail(user.id);
+
+ // 合致するメアドが登録されていなかったら無視
+ if (profile.email !== ps.email) {
+ return;
+ }
+
+ // メアドが認証されていなかったら無視
+ if (!profile.emailVerified) {
+ return;
+ }
+
+ const token = rndstr('a-z0-9', 64);
+
+ await PasswordResetRequests.insert({
+ id: genId(),
+ createdAt: new Date(),
+ userId: profile.userId,
+ token
+ });
+
+ const link = `${config.url}/reset-password/${token}`;
+
+ sendEmail(ps.email, 'Password reset requested',
+ `To reset password, please click this link:<br><a href="${link}">${link}</a>`,
+ `To reset password, please click this link: ${link}`);
+});