LT-236: Add expiration time for password reset link

This commit is contained in:
aysel.afsar committed 2016-04-13 14:56:35 -04:00
1 parent 1891d1fe75
commit 6c798ad4db
3 files changed
+44 -8

No files matched your search

+24 -7
View File
@@ -361,16 +361,33 @@ ActiveEntry.resetPassword = function(passwordValue, confirmPassword) {
return;
}
Accounts.resetPassword(Session.get('_resetPasswordToken'), passwordValue, function(error) {
// Check token is expired
Meteor.call('checkResetTokenIsExpired',Session.get('_resetPasswordToken'), function(error, isTokenExpired) {
if (error) {
ActiveEntry.errorMessages.set("resetPassword", error.message);
console.log(error.message);
return;
}
Session.set('_resetPasswordToken', null);
// Update last login time
Meteor.call("updateLastLoginDate");
var ActiveEntryConfig = Session.get('Photonic.ActiveEntry');
Router.go(ActiveEntryConfig.signIn.destination);
if (isTokenExpired) {
console.log("Your link is expired");
// Go to forgotPassword to create a new reset link
ActiveEntry.errorMessages.set("forgotPassword", 'Your link is expired. Please create a new reset link.');
Router.go('/forgotPassword');
return;
}
Accounts.resetPassword(Session.get('_resetPasswordToken'), passwordValue, function(error) {
if (error) {
ActiveEntry.errorMessages.set("resetPassword", error.message);
return;
}
Session.set('_resetPasswordToken', null);
// Update last login time
Meteor.call("updateLastLoginDate");
var ActiveEntryConfig = Session.get('Photonic.ActiveEntry');
Router.go(ActiveEntryConfig.signIn.destination);
});
});
};