fix(auth): send reset email and code in the request body

The verify call now carries the email the code was issued to, which the
API requires, and neither call puts the email or code in the URL.
This commit is contained in:
Alexandre Brandizzi 2026-09-25 12:22:55 -03:00
parent 358ec3e890
commit 297830ed35
2 changed files with 50 additions and 3 deletions

View file

@ -40,12 +40,14 @@ export async function changePassword(data: ChangePasswordPayload): Promise<unkno
return apiPost(API_PATHS.authentication.changePassword, data);
}
// Email and code travel in the JSON body so they stay out of URLs, traces and proxy logs.
export async function forgotPassword(email: string): Promise<unknown> {
return apiPost(`${API_PATHS.authentication.forgetPassword}?Email=${encodeURIComponent(email)}`);
return apiPost(API_PATHS.authentication.forgetPassword, { email });
}
export async function verifyResetCode(code: string): Promise<unknown> {
return apiPost(`${API_PATHS.authentication.verificationCode}?code=${encodeURIComponent(code)}`);
// The server checks a code only against the email it was issued to.
export async function verifyResetCode(email: string, code: string): Promise<unknown> {
return apiPost(API_PATHS.authentication.verificationCode, { email, code });
}
export async function resetPassword(data: ResetPasswordPayload): Promise<unknown> {

View file

@ -0,0 +1,45 @@
import { beforeEach, describe, expect, it, vi } from "vitest";
const apiPost = vi.fn();
vi.mock("@/api/api", () => ({
apiPost: (...args: unknown[]) => apiPost(...args),
}));
import { forgotPassword, resetPassword, verifyResetCode } from "@/domain/auth/api/auth-api";
describe("password reset API", () => {
beforeEach(() => {
apiPost.mockReset();
apiPost.mockResolvedValue({ status: "Success ", message: "ok" });
});
it("sends the email in the request body, never in the URL", async () => {
await forgotPassword("alice@example.com");
expect(apiPost).toHaveBeenCalledWith("Authentication/ForgetPassword", {
email: "alice@example.com",
});
expect(String(apiPost.mock.calls[0][0])).not.toContain("?");
});
it("verifies a code together with the email it was issued to", async () => {
await verifyResetCode("alice@example.com", "123456");
expect(apiPost).toHaveBeenCalledWith("Authentication/VerificationCode", {
email: "alice@example.com",
code: "123456",
});
expect(String(apiPost.mock.calls[0][0])).not.toContain("123456");
});
it("resets with email, code and the new password in the body", async () => {
await resetPassword({ Email: "alice@example.com", Code: "123456", Password: "New@67890" });
expect(apiPost).toHaveBeenCalledWith("Authentication/ResetPassword", {
Email: "alice@example.com",
Code: "123456",
Password: "New@67890",
});
});
});