这是indexloc提供的服务,不要输入任何密码
Skip to content

Conversation

@rzane
Copy link

@rzane rzane commented Jan 17, 2018

After using a recovery token and updating the user's password, Authority should delete the all recovery tokens for the user. However, Authority is actually deleting all recovery tokens for ALL users.

It's basically running this query:

DELETE tokens AS t0
WHERE ((t0.user_id = 1) AND (t0.id != 32))
OR (t0.purpose = "recovery")

@danielberkompas
Copy link
Contributor

Good bug report! Probably an issue with an or_where call somewhere in the template. Will look into it when I can.

@danielberkompas
Copy link
Contributor

Closing this because Template was moved to authority_ecto. Will address this issue over there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants