diff --git a/core/controllers/AuthController.php b/core/controllers/AuthController.php index d9494b32..81d1017e 100644 --- a/core/controllers/AuthController.php +++ b/core/controllers/AuthController.php @@ -211,7 +211,18 @@ public function resetAction() (string) $request->getPost('confirm') ); if ($res['ok']) { - $this->_json(['result' => 1, 'redirect' => '/auth/login/reset/1']); + // Better UX: sign the user straight in and send them to their dashboard — no bounce back + // to the login page. `pwreset=1` on the destination drives a dismissable "password set, + // you're logged in" toast; `username` lets the form offer the browser's save-password. + $uid = (string) ($res['user_id'] ?? ''); + if ($uid !== '' && (new Tiger_Service_Authentication())->establishSession($uid)) { + $home = $this->_roleHome(Zend_Auth::getInstance()->getIdentity()); + $home .= (strpos($home, '?') === false ? '?' : '&') . 'pwreset=1'; + $this->_json(['result' => 1, 'redirect' => $home, 'logged_in' => true, + 'username' => (string) ($res['username'] ?? '')]); + } else { + $this->_json(['result' => 1, 'redirect' => '/auth/login/reset/1']); // fallback: old behaviour + } } else { $this->_json(['result' => 0, 'message' => $res['error']], 400); } diff --git a/core/views/scripts/auth/reset.phtml b/core/views/scripts/auth/reset.phtml index 2a0181fd..0a723c98 100644 --- a/core/views/scripts/auth/reset.phtml +++ b/core/views/scripts/auth/reset.phtml @@ -20,6 +20,8 @@ $code = $this->escape($this->code ?? '');