apache / apache/cloudstack

User password reset request responds as successful, but fails silently - TTL Issue

Offen
#13,604 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
component:authentication
Vorherrschende Sprache
Java
Sterne
3.1k
Forks
1.4k
Ø Merge
6 T. 19 Std.
Gemergte PRs (30 T.)
32

Beschreibung

### problem

When a user requests a password reset at the login page, with password reset emails enabled, it returns a successful message to the user and emails them a reset token.
If the user requests another reset within that token's window (user.password.reset.ttl), it will still return a successful message to the user but willl fail internally with the message:
`DEBUG [o.a.c.u.UserPasswordResetManagerImpl] Failed to reset token and send email. Password reset token is already set for user user@emaildomain.com in domain id: xy with account primary and email user@emaildomain.com`

This doesn't appear in the event log of the user either.

### versions

4.22.1.0

### The steps to reproduce the bug

1. Have settings enabled for user password reset (user.password.reset.enabled = true) and an email host configured (user.password.reset.smtp.host)
2. Request a password reset.
3. Observe the first reset email.
4. Request another password reset.

### What to do about it?

There's a few issues here I think should be addressed:
1. Consider if password reset attemps should be visible in the user's Event's page. It might create spam in the events list, so might not be a good idea.
2. Consider either:
- Allowing a user to re-request a new password reset token and reset the TTL window using the new token (my desired outcome, and what I'd expect end-users would be familiar with).
- If not the above, then wait for the email to be successfully queued/sent and return the success from that. If the email isn't sent due to the token being within the TTL, then return a user-friendly message that they cannot request a new token until a specified datetime.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne damit, die zweite Anfrage zum Zurücksetzen des Passworts mit konfigurierten user.password.reset.enabled und user.password.reset.smtp.host nachzustellen. Lies UserPasswordResetManagerImpl rund um den protokollierten Fehler und verfolge, wie die Antwort der Anmeldeseite erzeugt wird. Done sollte ein definierter, für Benutzer sichtbarer Ausgang sein, wenn ein Zurücksetzungstoken noch innerhalb seiner TTL liegt, wobei das Verhalten durch die relevanten Tests zum Zurücksetzen des Passworts abgedeckt wird.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
authentication, backend
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
45/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.