makeplane / makeplane/plane

Password Reset with Valid But Non-Existent User ID Returns Unhandled 500

Open
#9,172 2 comments 0 reactions 1 assignee View on GitHub

@sangeethailango is already working on this.

Since Jun 8, 2026.

🐛bug plane
Dominant language
TypeScript
Stars
59.6k
Forks
5.8k
Avg merge
1d 22h
Merged PRs (30d)
49

Description

Is there an existing issue for this?
  • I have searched the existing issues
Current behavior

When I follow a password reset link that contains a valid base64-encoded but non-existent user ID, the server crashes with an unhandled DoesNotExist exception and I see the error message attached below:

User.DoesNotExist: User matching query does not exist.

What I expect is a redirect to the error page with a clear message that the reset link is invalid.

File: apps/api/plane/authentication/views/space/password_management.py — ResetPasswordSpaceEndpoint.post() calls User.objects.get(id=id) but only catches DjangoUnicodeDecodeError, leaving User.DoesNotExist unhandled

Steps to reproduce
  1. Construct a password reset URL with a valid base64-encoded UUID that doesn't correspond to any user
    1. Submit the reset form
    1. See 500 error instead of a redirect to the error page
Environment

Production

Browser

Google Chrome

Variant

Cloud

Version

v0.17.0-dev

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.