Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 12 additions & 1 deletion core/controllers/AuthController.php
Original file line number Diff line number Diff line change
Expand Up @@ -211,7 +211,18 @@ public function resetAction()
(string) $request->getPost('confirm')
);
if ($res['ok']) {
$this->_json(['result' => 1, 'redirect' => '/auth/login/reset/1']);
// Better UX: sign the user straight in and send them to their dashboard — no bounce back
// to the login page. `pwreset=1` on the destination drives a dismissable "password set,
// you're logged in" toast; `username` lets the form offer the browser's save-password.
$uid = (string) ($res['user_id'] ?? '');
if ($uid !== '' && (new Tiger_Service_Authentication())->establishSession($uid)) {
$home = $this->_roleHome(Zend_Auth::getInstance()->getIdentity());
$home .= (strpos($home, '?') === false ? '?' : '&') . 'pwreset=1';
$this->_json(['result' => 1, 'redirect' => $home, 'logged_in' => true,
'username' => (string) ($res['username'] ?? '')]);
} else {
$this->_json(['result' => 1, 'redirect' => '/auth/login/reset/1']); // fallback: old behaviour
}
} else {
$this->_json(['result' => 0, 'message' => $res['error']], 400);
}
Expand Down
10 changes: 9 additions & 1 deletion core/views/scripts/auth/reset.phtml
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@ $code = $this->escape($this->code ?? '');
<form id="reset-form" novalidate>
<input type="hidden" name="cid" value="<?= $cid ?>">
<input type="hidden" name="code" value="<?= $code ?>">
<?php /* Filled from the server response on success so the browser can offer to save the password. */ ?>
<input type="text" name="username" id="reset-username" autocomplete="username" value="" hidden>
<div class="mb-3">
<label class="form-label" for="reset-password"><?= $this->escape($this->t('core.auth.reset.new_password')) ?></label>
<input type="password" class="form-control form-control-lg" id="reset-password" name="password"
Expand Down Expand Up @@ -75,7 +77,13 @@ document.addEventListener('DOMContentLoaded', function () {
.then(function (r) { return r.json().catch(function () { return {}; }); });
})
.then(function (res) {
if (res && res.result === 1) { window.location = res.redirect || '/auth/login/reset/1'; return; }
if (res && res.result === 1) {
// Populate the username so the browser offers to save the new password, then go straight
// to the dashboard (we're already signed in — no bounce to the login page).
if (res.username) { var uf = document.getElementById('reset-username'); if (uf) { uf.value = res.username; } }
window.location = res.redirect || '/auth/login/reset/1';
return;
}
if (res && res.recaptcha) { rcReset(); fail(Tiger.t('recaptcha')); return; }
fail((res && res.message) ? res.message : Tiger.t('resetFailed'));
})
Expand Down
4 changes: 3 additions & 1 deletion library/Tiger/Service/Authentication.php
Original file line number Diff line number Diff line change
Expand Up @@ -284,7 +284,9 @@ public function resetPassword($challengeId, $code, $newPassword, $confirm)
return ['ok' => false, 'error' => 'We could not set your password. Please try again.'];
}

return ['ok' => true, 'error' => null];
// Return the identity so the caller can sign the user straight in (no bounce to the login page).
$u = (new Tiger_Model_User())->findById($userId);
return ['ok' => true, 'error' => null, 'user_id' => $userId, 'username' => $u ? (string) $u->username : ''];
}

/**
Expand Down
Loading