From ce4f12b63306fd879b9f14b17bb8901e72dee0f5 Mon Sep 17 00:00:00 2001 From: "Beau Beauchamp, WebTigers" Date: Thu, 1 Oct 2026 08:02:41 -0400 Subject: [PATCH] TIGER-269: sign the user in after a password reset (no bounce to the login page) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Setting a new password via the emailed reset link used to redirect to /auth/login/reset/1, forcing the user to type the credentials they just set. Now: - Tiger_Service_Authentication::resetPassword() returns the user_id + username on success. - AuthController::resetAction() establishes the session and redirects to the role home with pwreset=1 (for a "password set — you're now logged in" toast); falls back to the old login bounce only if the session can't be established. - The reset form carries a username field (autocomplete=username), filled from the response before navigation, so the browser offers to save the new password. NOTE: the dismissable toast on the destination (pwreset=1) still needs a small global handler, and the browser save-password modal behaviour wants a real-browser check — both are UI follow-ups on top of this core behavioural fix. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01ASauLLscjqdsNqBNsx2Typ --- core/controllers/AuthController.php | 13 ++++++++++++- core/views/scripts/auth/reset.phtml | 10 +++++++++- library/Tiger/Service/Authentication.php | 4 +++- 3 files changed, 24 insertions(+), 3 deletions(-) diff --git a/core/controllers/AuthController.php b/core/controllers/AuthController.php index d9494b32..81d1017e 100644 --- a/core/controllers/AuthController.php +++ b/core/controllers/AuthController.php @@ -211,7 +211,18 @@ public function resetAction() (string) $request->getPost('confirm') ); if ($res['ok']) { - $this->_json(['result' => 1, 'redirect' => '/auth/login/reset/1']); + // Better UX: sign the user straight in and send them to their dashboard — no bounce back + // to the login page. `pwreset=1` on the destination drives a dismissable "password set, + // you're logged in" toast; `username` lets the form offer the browser's save-password. + $uid = (string) ($res['user_id'] ?? ''); + if ($uid !== '' && (new Tiger_Service_Authentication())->establishSession($uid)) { + $home = $this->_roleHome(Zend_Auth::getInstance()->getIdentity()); + $home .= (strpos($home, '?') === false ? '?' : '&') . 'pwreset=1'; + $this->_json(['result' => 1, 'redirect' => $home, 'logged_in' => true, + 'username' => (string) ($res['username'] ?? '')]); + } else { + $this->_json(['result' => 1, 'redirect' => '/auth/login/reset/1']); // fallback: old behaviour + } } else { $this->_json(['result' => 0, 'message' => $res['error']], 400); } diff --git a/core/views/scripts/auth/reset.phtml b/core/views/scripts/auth/reset.phtml index 2a0181fd..0a723c98 100644 --- a/core/views/scripts/auth/reset.phtml +++ b/core/views/scripts/auth/reset.phtml @@ -20,6 +20,8 @@ $code = $this->escape($this->code ?? '');
+ +
false, 'error' => 'We could not set your password. Please try again.']; } - return ['ok' => true, 'error' => null]; + // Return the identity so the caller can sign the user straight in (no bounce to the login page). + $u = (new Tiger_Model_User())->findById($userId); + return ['ok' => true, 'error' => null, 'user_id' => $userId, 'username' => $u ? (string) $u->username : '']; } /**