Skip to content

TIGER-269: sign the user in after a password reset (no login bounce) - #322

Open
WebTigers wants to merge 1 commit into
mainfrom
fix/reset-autologin
Open

WebTigers wants to merge 1 commit into
mainfrom
fix/reset-autologin

Conversation

@WebTigers

Copy link
Copy Markdown
Owner

What

After setting a new password via the emailed reset link, log the user straight into their dashboard instead of bouncing them to /auth/login/reset/1 to re-type the credentials they just set.

Changes

  • Tiger_Service_Authentication::resetPassword() returns user_id + username on success.
  • AuthController::resetAction() establishes the session and redirects to the role home with pwreset=1; falls back to the old login bounce only if the session can't be established.
  • The reset form carries a username field (autocomplete=username), filled from the response before navigation, so the browser can offer to save the new password.

Follow-ups (UI, need a browser)

  • Dismissable "password set — you're now logged in" toast on the destination (pwreset=1 is already passed; needs a small global handler).
  • Verify the browser save-password modal fires.

Part of the TigerHosting account-setup batch (TIGER-266/267/268/269).

🤖 Generated with Claude Code

https://claude.ai/code/session_01ASauLLscjqdsNqBNsx2Typ

…login page)

Setting a new password via the emailed reset link used to redirect to /auth/login/reset/1,
forcing the user to type the credentials they just set. Now:
- Tiger_Service_Authentication::resetPassword() returns the user_id + username on success.
- AuthController::resetAction() establishes the session and redirects to the role home with
  pwreset=1 (for a "password set — you're now logged in" toast); falls back to the old login
  bounce only if the session can't be established.
- The reset form carries a username field (autocomplete=username), filled from the response
  before navigation, so the browser offers to save the new password.

NOTE: the dismissable toast on the destination (pwreset=1) still needs a small global handler,
and the browser save-password modal behaviour wants a real-browser check — both are UI follow-ups
on top of this core behavioural fix.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ASauLLscjqdsNqBNsx2Typ
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant