server: Implement password reset

It's still missing the email.

This also secures the password change method with a JWT token check: you
have to be logged in to change the password.
This commit is contained in:
Valentin Tolmer
2021-11-21 18:09:29 +01:00
committed by nitnelave
parent 7b5ad47ee2
commit a13bfc3575
3 changed files with 124 additions and 11 deletions
+9
View File
@@ -151,4 +151,13 @@ impl TcpBackendHandler for SqlBackendHandler {
let (user_id,) = sqlx::query_as(&query).fetch_one(&self.sql_pool).await?;
Ok(user_id)
}
async fn delete_password_reset_token(&self, token: &str) -> Result<()> {
let query = Query::delete()
.from_table(PasswordResetTokens::Table)
.and_where(Expr::col(PasswordResetTokens::Token).eq(token))
.to_string(DbQueryBuilder {});
sqlx::query(&query).execute(&self.sql_pool).await?;
Ok(())
}
}