summaryrefslogtreecommitdiff
path: root/packages/backend/src/server/api/endpoints/reset-password.ts
diff options
context:
space:
mode:
authorsyuilo <Syuilotan@yahoo.co.jp>2021-11-12 02:02:25 +0900
committersyuilo <Syuilotan@yahoo.co.jp>2021-11-12 02:02:25 +0900
commit0e4a111f81cceed275d9bec2695f6e401fb654d8 (patch)
tree40874799472fa07416f17b50a398ac33b7771905 /packages/backend/src/server/api/endpoints/reset-password.ts
parentupdate deps (diff)
downloadsharkey-0e4a111f81cceed275d9bec2695f6e401fb654d8.tar.gz
sharkey-0e4a111f81cceed275d9bec2695f6e401fb654d8.tar.bz2
sharkey-0e4a111f81cceed275d9bec2695f6e401fb654d8.zip
refactoring
Resolve #7779
Diffstat (limited to 'packages/backend/src/server/api/endpoints/reset-password.ts')
-rw-r--r--packages/backend/src/server/api/endpoints/reset-password.ts45
1 files changed, 45 insertions, 0 deletions
diff --git a/packages/backend/src/server/api/endpoints/reset-password.ts b/packages/backend/src/server/api/endpoints/reset-password.ts
new file mode 100644
index 0000000000..53b0bfde0b
--- /dev/null
+++ b/packages/backend/src/server/api/endpoints/reset-password.ts
@@ -0,0 +1,45 @@
+import $ from 'cafy';
+import * as bcrypt from 'bcryptjs';
+import { publishMainStream } from '@/services/stream';
+import define from '../define';
+import { Users, UserProfiles, PasswordResetRequests } from '@/models/index';
+import { ApiError } from '../error';
+
+export const meta = {
+ requireCredential: false as const,
+
+ params: {
+ token: {
+ validator: $.str
+ },
+
+ password: {
+ validator: $.str
+ }
+ },
+
+ errors: {
+
+ }
+};
+
+export default define(meta, async (ps, user) => {
+ const req = await PasswordResetRequests.findOneOrFail({
+ token: ps.token,
+ });
+
+ // 発行してから30分以上経過していたら無効
+ if (Date.now() - req.createdAt.getTime() > 1000 * 60 * 30) {
+ throw new Error(); // TODO
+ }
+
+ // Generate hash of password
+ const salt = await bcrypt.genSalt(8);
+ const hash = await bcrypt.hash(ps.password, salt);
+
+ await UserProfiles.update(req.userId, {
+ password: hash
+ });
+
+ PasswordResetRequests.delete(req.id);
+});