fix(api): reissue JWT with mustChangePassword=false after password change
After a successful password change the old cookie still contained mustChangePassword=true, causing the middleware to redirect back to /change-password. Now changePassword issues a fresh session cookie. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -97,11 +97,13 @@ export class AuthController {
|
||||
async changePassword(
|
||||
@CurrentUser() user: any,
|
||||
@Body() dto: ChangePasswordDto,
|
||||
@Res({ passthrough: true }) res: Response,
|
||||
) {
|
||||
await this.authService.changePassword(
|
||||
user.id,
|
||||
dto.currentPassword,
|
||||
dto.newPassword,
|
||||
res,
|
||||
);
|
||||
return { message: 'Password changed successfully.' };
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user