fix(coderd): allow user-admin password resets to succeed (#26537)

User Admin password resets could update the target user's hashed
password but fail while revoking that user's API keys. The transaction
then rolled back and returned HTTP 500, so the password was never
changed.

Add a user-scoped API key revoker actor and use it in both password
reset flows so key revocation succeeds without broader system auth.

Refs: https://linear.app/codercom/issue/PLAT-316
This commit is contained in:
George K
2026-07-07 09:05:14 -07:00
committed by GitHub
parent bfbacd64f4
commit ba094c5706
7 changed files with 146 additions and 3 deletions
+3 -2
View File
@@ -430,8 +430,9 @@ func (api *API) postChangePasswordWithOneTimePasscode(rw http.ResponseWriter, r
return xerrors.Errorf("update user hashed password: %w", err)
}
//nolint:gocritic // We need the system auth context to be able to delete all API keys for the user.
err = tx.DeleteAPIKeysByUserID(dbauthz.AsSystemRestricted(ctx), user.ID)
//nolint:gocritic // Password resets must revoke all keys owned by the
// target user, not just keys addressable by the caller's actor.
err = tx.DeleteAPIKeysByUserID(dbauthz.AsAPIKeyRevoker(ctx, user.ID), user.ID)
if err != nil {
logger.Error(ctx, "unable to delete user's api keys", slog.Error(err))
return xerrors.Errorf("delete api keys for user: %w", err)