Skip to content

Make password reset tokens single-use - #687

Merged
MarcelGeo merged 3 commits into
developfrom
fix_token_lifetime
Oct 1, 2026
Merged

MarcelGeo merged 3 commits into
developfrom
fix_token_lifetime

Conversation

@varmar05

Copy link
Copy Markdown
Collaborator

Bind each token to a random nonce stored on the user. Requesting a reset rotates the nonce, revoking older links; any password change clears it, so a link works once and dies on a logged-in password change.

There is also a new config variable PASSWORD_RESET_TOKEN_EXPIRATION.

Bind each token to a random nonce stored on the user. Requesting a reset
rotates the nonce, revoking older links; any password change clears it,
so a link works once and dies on a logged-in password change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@varmar05
varmar05 requested a review from MarcelGeo September 29, 2026 11:27
@varmar05
varmar05 changed the base branch from master to develop September 29, 2026 11:34
@coveralls

coveralls commented Sep 29, 2026 •

Copy link
Copy Markdown

Coverage Report for CI Build 36836952244

Coverage increased (+0.02%) to 92.689%

Details

  • Coverage increased (+0.02%) from the base build.
  • Patch coverage: 82 of 82 lines across 6 files are fully covered (100%).
  • 16 coverage regressions across 2 files.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

16 previously-covered lines in 2 files lost coverage.

File Lines Losing Coverage Coverage
server/mergin/sync/public_api_v2_controller.py 15 88.62%
server/mergin/tests/test_public_api_v2.py 1 99.87%

Coverage Stats

Coverage Status
Relevant Lines: 11216
Covered Lines: 10396
Line Coverage: 92.69%
Coverage Strength: 0.93 hits per line

💛 - Coveralls

@MarcelGeo MarcelGeo left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As I understand old tokens will be revoked, no?

Comment thread server/mergin/auth/app.py Outdated
Comment thread server/mergin/auth/controller.py Outdated
Comment thread server/mergin/auth/controller.py Outdated
Comment thread server/mergin/auth/config.py Outdated
Comment thread server/mergin/auth/app.py
Comment thread deployment/community/.env.template
Comment thread server/mergin/auth/app.py Outdated
@varmar05

varmar05 commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

As I understand old tokens will be revoked, no?

Yes, on purpose. Old link will get invalid token and user can just create a new one. Old links are valid only for 1 hour anyway so the impact is very low.

@MarcelGeo
MarcelGeo merged commit 9070262 into develop Oct 1, 2026
5 checks passed
@MarcelGeo
MarcelGeo deleted the fix_token_lifetime branch October 1, 2026 09:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants