Password Reset with Valid But Non-Existent User ID Returns Unhandled 500
@sangeethailango is already working on this.
Since Jun 8, 2026.
- Dominant language
- TypeScript
- Stars
- 59.6k
- Forks
- 5.8k
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 49
Description
Is there an existing issue for this?
- I have searched the existing issues
Current behavior
When I follow a password reset link that contains a valid base64-encoded but non-existent user ID, the server crashes with an unhandled DoesNotExist exception and I see the error message attached below:
User.DoesNotExist: User matching query does not exist.
What I expect is a redirect to the error page with a clear message that the reset link is invalid.
File: apps/api/plane/authentication/views/space/password_management.py — ResetPasswordSpaceEndpoint.post() calls User.objects.get(id=id) but only catches DjangoUnicodeDecodeError, leaving User.DoesNotExist unhandled
Steps to reproduce
- Construct a password reset URL with a valid base64-encoded UUID that doesn't correspond to any user
-
- Submit the reset form
-
- See 500 error instead of a redirect to the error page
Environment
Production
Browser
Google Chrome
Variant
Cloud
Version
v0.17.0-dev
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.