mirror of
https://github.com/documenso/documenso.git
synced 2026-10-03 10:13:52 +10:00
Merge branch 'main' into feat/instance-2fa
This commit is contained in:
@@ -18,6 +18,7 @@ import {
|
||||
resendVerifyEmailRateLimit,
|
||||
resetPasswordRateLimit,
|
||||
signupRateLimit,
|
||||
updatePasswordRateLimit,
|
||||
verifyEmailRateLimit,
|
||||
} from '@documenso/lib/server-only/rate-limit/rate-limits';
|
||||
import { getEmailBlocklistDomains } from '@documenso/lib/server-only/site-settings/get-email-blocklist-domains';
|
||||
@@ -282,7 +283,7 @@ export const emailPasswordRoute = new Hono<HonoAuthContext>()
|
||||
* Update password endpoint.
|
||||
*/
|
||||
.post('/update-password', sValidator('json', ZUpdatePasswordSchema), async (c) => {
|
||||
const { password, currentPassword } = c.req.valid('json');
|
||||
const { password, currentPassword, totpCode, backupCode } = c.req.valid('json');
|
||||
const requestMetadata = c.get('requestMetadata');
|
||||
|
||||
if (!isSigninEnabledForProvider('email')) {
|
||||
@@ -293,10 +294,25 @@ export const emailPasswordRoute = new Hono<HonoAuthContext>()
|
||||
|
||||
const { session, user } = await getSession(c);
|
||||
|
||||
const updateLimitResult = await updatePasswordRateLimit.check({
|
||||
ip: requestMetadata.ipAddress ?? 'unknown',
|
||||
identifier: String(user.id),
|
||||
});
|
||||
|
||||
const updateLimited = rateLimitResponse(c, updateLimitResult);
|
||||
|
||||
if (updateLimited) {
|
||||
throw new HTTPException(429, {
|
||||
res: updateLimited,
|
||||
});
|
||||
}
|
||||
|
||||
await updatePassword({
|
||||
userId: user.id,
|
||||
password,
|
||||
currentPassword,
|
||||
totpCode,
|
||||
backupCode,
|
||||
requestMetadata,
|
||||
});
|
||||
|
||||
|
||||
@@ -70,6 +70,8 @@ export type TResendVerifyEmailSchema = z.infer<typeof ZResendVerifyEmailSchema>;
|
||||
export const ZUpdatePasswordSchema = z.object({
|
||||
currentPassword: ZCurrentPasswordSchema,
|
||||
password: ZPasswordSchema,
|
||||
totpCode: z.string().trim().optional(),
|
||||
backupCode: z.string().trim().optional(),
|
||||
});
|
||||
|
||||
export type TUpdatePasswordSchema = z.infer<typeof ZUpdatePasswordSchema>;
|
||||
|
||||
Reference in New Issue
Block a user