kaori 4 лет назад
Родитель
Сommit
c524b74874
1 измененных файлов с 3 добавлено и 4 удалено
  1. 3 4
      src/server/routes/apiv3/forgot-password.js

+ 3 - 4
src/server/routes/apiv3/forgot-password.js

@@ -70,12 +70,11 @@ module.exports = (crowi) => {
     }
   });
 
-  router.put('/', csrf, passwordReset, validator.password, apiV3FormValidator, async(req, res) => {
-    const { email } = req.DataFromPasswordResetOrderMiddleware;
+  router.put('/:token', csrf, passwordReset, validator.password, apiV3FormValidator, async(req, res) => {
+    const passwordResetOrder = req.DataFromPasswordResetOrderMiddleware;
     const { newPassword } = req.body;
 
-
-    const user = await User.findOne({ email });
+    const user = await User.findOne({ email: passwordResetOrder.email });
 
     // when the user is not found or active
     if (user == null || user.status !== 2) {