Skip to content

Commit

Permalink
[members] secure password reset token generation
Browse files Browse the repository at this point in the history
  • Loading branch information
ar2rsawseen committed May 5, 2022
1 parent bc5e4b0 commit 2bfa1ee
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion frontend/express/libs/members.js
Original file line number Diff line number Diff line change
Expand Up @@ -809,7 +809,7 @@ membersUtility.forgot = function(req, callback) {
membersUtility.db.collection('members').findOne({"email": email}, function(err, member) {
if (member) {
var timestamp = Math.round(new Date().getTime() / 1000),
prid = sha512Hash(member.username + member.full_name, timestamp);
prid = crypto.randomBytes(32).toString('hex');
member.lang = member.lang || req.body.lang || "en";
membersUtility.db.collection('password_reset').insert({"prid": prid, "user_id": member._id, "timestamp": timestamp}, {safe: true}, function() {
countlyMail.sendPasswordResetInfo(member, prid);
Expand Down

0 comments on commit 2bfa1ee

Please sign in to comment.