apache / apache/cloudstack

User password reset request responds as successful, but fails silently - TTL Issue

未關閉
#13,604 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
component:authentication
主要語言
Java
星號
3.1k
分支
1.4k
平均合併
6 天 19 小時
30 天內合併 PR
32

描述

### problem

When a user requests a password reset at the login page, with password reset emails enabled, it returns a successful message to the user and emails them a reset token.
If the user requests another reset within that token's window (user.password.reset.ttl), it will still return a successful message to the user but willl fail internally with the message:
`DEBUG [o.a.c.u.UserPasswordResetManagerImpl] Failed to reset token and send email. Password reset token is already set for user user@emaildomain.com in domain id: xy with account primary and email user@emaildomain.com`

This doesn't appear in the event log of the user either.

### versions

4.22.1.0

### The steps to reproduce the bug

1. Have settings enabled for user password reset (user.password.reset.enabled = true) and an email host configured (user.password.reset.smtp.host)
2. Request a password reset.
3. Observe the first reset email.
4. Request another password reset.

### What to do about it?

There's a few issues here I think should be addressed:
1. Consider if password reset attemps should be visible in the user's Event's page. It might create spam in the events list, so might not be a good idea.
2. Consider either:
- Allowing a user to re-request a new password reset token and reset the TTL window using the new token (my desired outcome, and what I'd expect end-users would be familiar with).
- If not the above, then wait for the email to be successfully queued/sent and return the success from that. If the email isn't sent due to the token being within the TTL, then return a user-friendly message that they cannot request a new token until a specified datetime.

貢獻指南

開啟貢獻指南

研究方向

首先,在設定了 user.password.reset.enabled 和 user.password.reset.smtp.host 的情況下重現第二次密碼重設請求。閱讀記錄到的失敗附近的 UserPasswordResetManagerImpl,並追蹤登入頁面回應是如何產生的。當重設權杖仍在其 TTL 內時,Done 應該是一個已定義且對使用者可見的結果,且相關的密碼重設測試應涵蓋此行為。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
java
領域
authentication, backend
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
冷清
描述清晰度
需要釐清
新手友好度
45/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。