fix: unable to change password when using magic link (#484)
* fix: fixed password not resetting & added password prompt with save guards * fix: migrated to using setPassword
This commit is contained in:
@@ -27,6 +27,8 @@ export const userRouter = createTRPCRouter({
|
||||
name: z.string().nullable(),
|
||||
image: z.string().nullable(),
|
||||
stripeCustomerId: z.string().nullable(),
|
||||
hasPassword: z.boolean(),
|
||||
hasMagicLinkAccount: z.boolean(),
|
||||
apiKey: z
|
||||
.object({
|
||||
id: z.number(),
|
||||
@@ -61,6 +63,8 @@ export const userRouter = createTRPCRouter({
|
||||
return {
|
||||
...result,
|
||||
image: imageUrl,
|
||||
hasPassword: result.hasPassword,
|
||||
hasMagicLinkAccount: result.hasMagicLinkAccount,
|
||||
apiKey: apiKey ? { id: apiKey.id, prefix: apiKey.prefix } : null,
|
||||
};
|
||||
}),
|
||||
@@ -114,4 +118,42 @@ export const userRouter = createTRPCRouter({
|
||||
image: imageUrl,
|
||||
};
|
||||
}),
|
||||
setPassword: protectedProcedure
|
||||
.input(
|
||||
z.object({
|
||||
newPassword: z
|
||||
.string()
|
||||
.min(8, "Password must be at least 8 characters"),
|
||||
}),
|
||||
)
|
||||
.output(z.object({ success: z.boolean() }))
|
||||
.mutation(async ({ ctx, input }) => {
|
||||
const userId = ctx.user?.id;
|
||||
|
||||
if (!userId)
|
||||
throw new TRPCError({
|
||||
message: `User not authenticated`,
|
||||
code: "UNAUTHORIZED",
|
||||
});
|
||||
|
||||
const existing = await userRepo.getById(ctx.db, userId);
|
||||
|
||||
if (!existing) {
|
||||
throw new TRPCError({
|
||||
message: `User not found`,
|
||||
code: "NOT_FOUND",
|
||||
});
|
||||
}
|
||||
|
||||
if (existing.hasPassword) {
|
||||
throw new TRPCError({
|
||||
message: `Password already set; use change password instead`,
|
||||
code: "BAD_REQUEST",
|
||||
});
|
||||
}
|
||||
|
||||
await ctx.auth.api.setPassword({ newPassword: input.newPassword });
|
||||
|
||||
return { success: true };
|
||||
}),
|
||||
});
|
||||
|
||||
@@ -63,6 +63,11 @@ const createAuthWithHeaders = (
|
||||
headers,
|
||||
query: { referenceId: input.workspacePublicId },
|
||||
}),
|
||||
setPassword: (input: { newPassword: string }) =>
|
||||
auth.api.setPassword({
|
||||
headers,
|
||||
body: { newPassword: input.newPassword },
|
||||
}),
|
||||
},
|
||||
};
|
||||
};
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
import { count, desc, eq } from "drizzle-orm";
|
||||
import { and, count, desc, eq, isNotNull } from "drizzle-orm";
|
||||
import { v4 as uuidv4 } from "uuid";
|
||||
|
||||
import type { dbClient } from "@kan/db/client";
|
||||
import { apikey, users } from "@kan/db/schema";
|
||||
import { account, apikey, users } from "@kan/db/schema";
|
||||
|
||||
export const getCount = async (db: dbClient) => {
|
||||
const result = await db.select({ count: count() }).from(users);
|
||||
@@ -11,27 +11,58 @@ export const getCount = async (db: dbClient) => {
|
||||
};
|
||||
|
||||
export const getById = async (db: dbClient, userId: string) => {
|
||||
return await db.query.users.findFirst({
|
||||
columns: {
|
||||
id: true,
|
||||
name: true,
|
||||
email: true,
|
||||
image: true,
|
||||
stripeCustomerId: true,
|
||||
},
|
||||
with: {
|
||||
apiKeys: {
|
||||
columns: {
|
||||
id: true,
|
||||
prefix: true,
|
||||
key: true,
|
||||
},
|
||||
orderBy: desc(apikey.createdAt),
|
||||
limit: 1,
|
||||
const [user, credentialAccount, magicLinkAccount] = await Promise.all([
|
||||
db.query.users.findFirst({
|
||||
columns: {
|
||||
id: true,
|
||||
name: true,
|
||||
email: true,
|
||||
image: true,
|
||||
stripeCustomerId: true,
|
||||
},
|
||||
},
|
||||
where: eq(users.id, userId),
|
||||
});
|
||||
with: {
|
||||
apiKeys: {
|
||||
columns: {
|
||||
id: true,
|
||||
prefix: true,
|
||||
key: true,
|
||||
},
|
||||
orderBy: desc(apikey.createdAt),
|
||||
limit: 1,
|
||||
},
|
||||
},
|
||||
where: eq(users.id, userId),
|
||||
}),
|
||||
db
|
||||
.select({ id: account.id })
|
||||
.from(account)
|
||||
.where(
|
||||
and(
|
||||
eq(account.userId, userId),
|
||||
eq(account.providerId, "credential"),
|
||||
isNotNull(account.password),
|
||||
),
|
||||
)
|
||||
.limit(1),
|
||||
db
|
||||
.select({ id: account.id })
|
||||
.from(account)
|
||||
.where(
|
||||
and(
|
||||
eq(account.userId, userId),
|
||||
eq(account.providerId, "magic-link"),
|
||||
),
|
||||
)
|
||||
.limit(1),
|
||||
]);
|
||||
|
||||
if (!user) return undefined;
|
||||
|
||||
return {
|
||||
...user,
|
||||
hasPassword: credentialAccount.length > 0,
|
||||
hasMagicLinkAccount: magicLinkAccount.length > 0,
|
||||
};
|
||||
};
|
||||
|
||||
export const getByStripeCustomerId = async (
|
||||
|
||||
Reference in New Issue
Block a user