User password reset request responds as successful, but fails silently - TTL Issue
- 主要言語
- Java
- スター
- 3.1k
- フォーク
- 1.4k
- 平均マージ
- 6日 19時間
- マージ済み PR(30日)
- 32
説明
### problem
When a user requests a password reset at the login page, with password reset emails enabled, it returns a successful message to the user and emails them a reset token.
If the user requests another reset within that token's window (user.password.reset.ttl), it will still return a successful message to the user but willl fail internally with the message:
`DEBUG [o.a.c.u.UserPasswordResetManagerImpl] Failed to reset token and send email. Password reset token is already set for user user@emaildomain.com in domain id: xy with account primary and email user@emaildomain.com`
This doesn't appear in the event log of the user either.
### versions
4.22.1.0
### The steps to reproduce the bug
1. Have settings enabled for user password reset (user.password.reset.enabled = true) and an email host configured (user.password.reset.smtp.host)
2. Request a password reset.
3. Observe the first reset email.
4. Request another password reset.
### What to do about it?
There's a few issues here I think should be addressed:
1. Consider if password reset attemps should be visible in the user's Event's page. It might create spam in the events list, so might not be a good idea.
2. Consider either:
- Allowing a user to re-request a new password reset token and reset the TTL window using the new token (my desired outcome, and what I'd expect end-users would be familiar with).
- If not the above, then wait for the email to be successfully queued/sent and return the success from that. If the email isn't sent due to the token being within the TTL, then return a user-friendly message that they cannot request a new token until a specified datetime.
コントリビューションガイド
調査の方向性
まず、user.password.reset.enabled と user.password.reset.smtp.host を設定した状態で、2 回目のパスワードリセットリクエストを再現します。記録された失敗箇所の周辺にある UserPasswordResetManagerImpl を読み、ログインページのレスポンスがどのように生成されるかを追跡します。リセットトークンがまだ TTL 内にある場合、Done は定義されたユーザーに表示される結果であるべきで、その動作は関連するパスワードリセットテストでカバーされている必要があります。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- java
- 領域
- authentication, backend
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 45/100