diff --git a/src/domain/auth/api/auth-api.ts b/src/domain/auth/api/auth-api.ts index 279baaa7..c8f4f681 100644 --- a/src/domain/auth/api/auth-api.ts +++ b/src/domain/auth/api/auth-api.ts @@ -40,12 +40,14 @@ export async function changePassword(data: ChangePasswordPayload): Promise { - return apiPost(`${API_PATHS.authentication.forgetPassword}?Email=${encodeURIComponent(email)}`); + return apiPost(API_PATHS.authentication.forgetPassword, { email }); } -export async function verifyResetCode(code: string): Promise { - return apiPost(`${API_PATHS.authentication.verificationCode}?code=${encodeURIComponent(code)}`); +// The server checks a code only against the email it was issued to. +export async function verifyResetCode(email: string, code: string): Promise { + return apiPost(API_PATHS.authentication.verificationCode, { email, code }); } export async function resetPassword(data: ResetPasswordPayload): Promise { diff --git a/src/test/domain/auth/api/auth-api.test.ts b/src/test/domain/auth/api/auth-api.test.ts new file mode 100644 index 00000000..498d28be --- /dev/null +++ b/src/test/domain/auth/api/auth-api.test.ts @@ -0,0 +1,45 @@ +import { beforeEach, describe, expect, it, vi } from "vitest"; + +const apiPost = vi.fn(); + +vi.mock("@/api/api", () => ({ + apiPost: (...args: unknown[]) => apiPost(...args), +})); + +import { forgotPassword, resetPassword, verifyResetCode } from "@/domain/auth/api/auth-api"; + +describe("password reset API", () => { + beforeEach(() => { + apiPost.mockReset(); + apiPost.mockResolvedValue({ status: "Success ", message: "ok" }); + }); + + it("sends the email in the request body, never in the URL", async () => { + await forgotPassword("alice@example.com"); + + expect(apiPost).toHaveBeenCalledWith("Authentication/ForgetPassword", { + email: "alice@example.com", + }); + expect(String(apiPost.mock.calls[0][0])).not.toContain("?"); + }); + + it("verifies a code together with the email it was issued to", async () => { + await verifyResetCode("alice@example.com", "123456"); + + expect(apiPost).toHaveBeenCalledWith("Authentication/VerificationCode", { + email: "alice@example.com", + code: "123456", + }); + expect(String(apiPost.mock.calls[0][0])).not.toContain("123456"); + }); + + it("resets with email, code and the new password in the body", async () => { + await resetPassword({ Email: "alice@example.com", Code: "123456", Password: "New@67890" }); + + expect(apiPost).toHaveBeenCalledWith("Authentication/ResetPassword", { + Email: "alice@example.com", + Code: "123456", + Password: "New@67890", + }); + }); +});