Skip to content

Commit 158958d

Browse files
committed
Password change needs to require user login to reset some cookies
closes pterodactyl#1793
1 parent 5f13531 commit 158958d

File tree

3 files changed

+25
-8
lines changed

3 files changed

+25
-8
lines changed

app/Http/Controllers/Api/Client/AccountController.php

Lines changed: 17 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,8 @@
44

55
use Illuminate\Http\Request;
66
use Illuminate\Http\Response;
7+
use Illuminate\Auth\AuthManager;
8+
use Illuminate\Http\JsonResponse;
79
use Pterodactyl\Services\Users\UserUpdateService;
810
use Pterodactyl\Transformers\Api\Client\AccountTransformer;
911
use Pterodactyl\Http\Requests\Api\Client\Account\UpdateEmailRequest;
@@ -16,16 +18,23 @@ class AccountController extends ClientApiController
1618
*/
1719
private $updateService;
1820

21+
/**
22+
* @var \Illuminate\Auth\SessionGuard
23+
*/
24+
private $sessionGuard;
25+
1926
/**
2027
* AccountController constructor.
2128
*
29+
* @param \Illuminate\Auth\AuthManager $sessionGuard
2230
* @param \Pterodactyl\Services\Users\UserUpdateService $updateService
2331
*/
24-
public function __construct(UserUpdateService $updateService)
32+
public function __construct(AuthManager $sessionGuard, UserUpdateService $updateService)
2533
{
2634
parent::__construct();
2735

2836
$this->updateService = $updateService;
37+
$this->sessionGuard = $sessionGuard;
2938
}
3039

3140
/**
@@ -56,18 +65,21 @@ public function updateEmail(UpdateEmailRequest $request): Response
5665
}
5766

5867
/**
59-
* Update the authenticated user's password.
68+
* Update the authenticated user's password. All existing sessions will be logged
69+
* out immediately.
6070
*
6171
* @param \Pterodactyl\Http\Requests\Api\Client\Account\UpdatePasswordRequest $request
62-
* @return \Illuminate\Http\Response
72+
* @return \Illuminate\Http\JsonResponse
6373
*
6474
* @throws \Pterodactyl\Exceptions\Model\DataValidationException
6575
* @throws \Pterodactyl\Exceptions\Repository\RecordNotFoundException
6676
*/
67-
public function updatePassword(UpdatePasswordRequest $request): Response
77+
public function updatePassword(UpdatePasswordRequest $request): \Illuminate\Http\JsonResponse
6878
{
6979
$this->updateService->handle($request->user(), $request->validated());
7080

71-
return response('', Response::HTTP_CREATED);
81+
$this->sessionGuard->logoutOtherDevices($request->input('current_password'));
82+
83+
return JsonResponse::create([], Response::HTTP_NO_CONTENT);
7284
}
7385
}

resources/scripts/components/dashboard/forms/UpdatePasswordForm.tsx

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,8 +34,8 @@ export default () => {
3434
clearFlashes('account:password');
3535
updateAccountPassword({ ...values })
3636
.then(() => {
37-
resetForm();
38-
addFlash({ key: 'account:password', type: 'success', message: 'Your password has been updated.' });
37+
// @ts-ignore
38+
window.location = '/auth/login';
3939
})
4040
.catch(error => addFlash({
4141
key: 'account:password',

resources/scripts/components/elements/ContentBox.tsx

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,12 @@ type Props = Readonly<React.DetailedHTMLProps<React.HTMLAttributes<HTMLDivElemen
1111
export default ({ title, borderColor, showFlashes, children, ...props }: Props) => (
1212
<div {...props}>
1313
{title && <h2 className={'text-neutral-300 mb-4 px-4'}>{title}</h2>}
14-
{showFlashes && <FlashMessageRender byKey={typeof showFlashes === 'string' ? showFlashes : undefined}/>}
14+
{showFlashes &&
15+
<FlashMessageRender
16+
byKey={typeof showFlashes === 'string' ? showFlashes : undefined}
17+
className={'mb-4'}
18+
/>
19+
}
1520
<div className={classNames('bg-neutral-700 p-4 rounded shadow-lg relative', borderColor, {
1621
'border-t-4': !!borderColor,
1722
})}>

0 commit comments

Comments
 (0)