mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: improve password validation flow (#15132)
Refers to #14984 Currently, password validation is done backend side and is not explicit enough so it can be painful to create first users. We'd like to make this validation easier - but also duplicate it frontend side to make it smoother. Flows involved : - First user set password - New user set password - Change password --------- Co-authored-by: BrunoQuaresma <bruno_nonato_quaresma@hotmail.com>
This commit is contained in:
co-authored by
BrunoQuaresma
parent
8b5a18cade
commit
4fe2c5f09a
@@ -447,6 +447,41 @@ func (api *API) postChangePasswordWithOneTimePasscode(rw http.ResponseWriter, r
|
||||
}
|
||||
}
|
||||
|
||||
// ValidateUserPassword validates the complexity of a user password and that it is secured enough.
|
||||
//
|
||||
// @Summary Validate user password
|
||||
// @ID validate-user-password
|
||||
// @Security CoderSessionToken
|
||||
// @Produce json
|
||||
// @Accept json
|
||||
// @Tags Authorization
|
||||
// @Param request body codersdk.ValidateUserPasswordRequest true "Validate user password request"
|
||||
// @Success 200 {object} codersdk.ValidateUserPasswordResponse
|
||||
// @Router /users/validate-password [post]
|
||||
func (*API) validateUserPassword(rw http.ResponseWriter, r *http.Request) {
|
||||
var (
|
||||
ctx = r.Context()
|
||||
valid = true
|
||||
details = ""
|
||||
)
|
||||
|
||||
var req codersdk.ValidateUserPasswordRequest
|
||||
if !httpapi.Read(ctx, rw, r, &req) {
|
||||
return
|
||||
}
|
||||
|
||||
err := userpassword.Validate(req.Password)
|
||||
if err != nil {
|
||||
valid = false
|
||||
details = err.Error()
|
||||
}
|
||||
|
||||
httpapi.Write(ctx, rw, http.StatusOK, codersdk.ValidateUserPasswordResponse{
|
||||
Valid: valid,
|
||||
Details: details,
|
||||
})
|
||||
}
|
||||
|
||||
// Authenticates the user with an email and password.
|
||||
//
|
||||
// @Summary Log in user
|
||||
|
||||
Reference in New Issue
Block a user