mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix(coderd): allow user-admin password resets to succeed (#26537)
User Admin password resets could update the target user's hashed password but fail while revoking that user's API keys. The transaction then rolled back and returned HTTP 500, so the password was never changed. Add a user-scoped API key revoker actor and use it in both password reset flows so key revocation succeeds without broader system auth. Refs: https://linear.app/codercom/issue/PLAT-316
This commit is contained in:
@@ -2850,11 +2850,27 @@ func TestUserForgotPassword(t *testing.T) {
|
||||
// as we haven't change the password yet.
|
||||
requireCannotLogin(t, ctx, anotherClient, anotherUser.Email, newPassword)
|
||||
|
||||
// Create an API token to confirm the password reset revokes the
|
||||
// user's existing keys.
|
||||
token, tokenErr := anotherClient.CreateToken(ctx, codersdk.Me, codersdk.CreateTokenRequest{})
|
||||
require.NoError(t, tokenErr)
|
||||
|
||||
tokenClient := codersdk.New(client.URL, codersdk.WithSessionToken(token.Key))
|
||||
|
||||
_, tokenErr = tokenClient.User(ctx, codersdk.Me)
|
||||
require.NoError(t, tokenErr, "token should authenticate before the password reset")
|
||||
|
||||
oneTimePasscode := requireRequestOneTimePasscode(t, ctx, anotherClient, notifyEnq, anotherUser.Email, anotherUser.ID)
|
||||
|
||||
requireChangePasswordWithOneTimePasscode(t, ctx, anotherClient, anotherUser.Email, oneTimePasscode, newPassword)
|
||||
requireCanLogin(t, ctx, anotherClient, anotherUser.Email, newPassword)
|
||||
|
||||
// The password reset must revoke every API key owned by the user.
|
||||
_, tokenErr = tokenClient.User(ctx, codersdk.Me)
|
||||
var tokenAPIErr *codersdk.Error
|
||||
require.ErrorAs(t, tokenErr, &tokenAPIErr)
|
||||
require.Equal(t, http.StatusUnauthorized, tokenAPIErr.StatusCode())
|
||||
|
||||
// We now need to check that the one-time passcode isn't valid.
|
||||
err := anotherClient.ChangePasswordWithOneTimePasscode(ctx, codersdk.ChangePasswordWithOneTimePasscodeRequest{
|
||||
Email: anotherUser.Email,
|
||||
|
||||
Reference in New Issue
Block a user