* wip * update layoutHOC * wip * remove app router related code no longer used * remove more * await cookies, headers, params, serachparams * update yarn.lock * await cookies, headers, params, serachparams more * update yarn lock again * downgrade next-auth to 4.22.1 * update yarn lock * fix * update yarn lock * fix type checks * update yarn lock * await headers and cookies * restore pages folder * restore yarn.lock * update yarn.lock * await headers and cookies * remove * await params in API routes * updates * restore next.config.js * remove i18n from next.config.js * Fixed tests * Fixed types * Removed duplicate favicon.ico * Fixing more types * ImageResponse moved to next/og * Fixed prisma import issues * dynamic import for @ewsjs/xhr * remove deasync dep * dynamic import for @tryvital/vital-node * fix type checks * add back turbopack command * Type fix * Removed unneeded file * fix turbopack relative path errors * add comments * remove unneeded code * Fixed build errors * await apis * use Promise<Params> type in defaultResponderForAppDir util * refactor scim api route * fix type checks * separate app-routing.config into client-config and server-config * wip * refactor routing forms components * revert unneeded changes for easier review * fix * fix * use CustomTrans * fix type * fix unit tests * fix type error * fix build error * fix build error * fix build error * fix warnings * fix warnings * upgrade @tremor/react and tailwindcss * numCols -> numItems * fix forgot-password e2e test * fix 1 more e2e test * fix login e2e test * fix e2e tests * fix e2e tests * clean up * remove error * use tremor/react 2.11.0 * fix * rename CustomTrans to ServerTrans * address comment * fix test * fix ServerTrans * fix * fix type * fix ServerTrans usages 1 * fix translations * fix type checks * fix type checks * link styling * fix --------- Co-authored-by: Keith Williams <keithwillcode@gmail.com> Co-authored-by: Anik Dhabal Babu <81948346+anikdhabal@users.noreply.github.com>
53 lines
1.6 KiB
TypeScript
53 lines
1.6 KiB
TypeScript
import type { User } from "@prisma/client";
|
|
|
|
import dayjs from "@calcom/dayjs";
|
|
import { getTranslation } from "@calcom/lib/server/i18n";
|
|
import prisma from "@calcom/prisma";
|
|
|
|
export const PASSWORD_RESET_EXPIRY_HOURS = 6;
|
|
|
|
const RECENT_MAX_ATTEMPTS = 3;
|
|
const RECENT_PERIOD_IN_MINUTES = 5;
|
|
|
|
const createPasswordReset = async (email: string): Promise<string> => {
|
|
const expiry = dayjs().add(PASSWORD_RESET_EXPIRY_HOURS, "hours").toDate();
|
|
const createdResetPasswordRequest = await prisma.resetPasswordRequest.create({
|
|
data: {
|
|
email,
|
|
expires: expiry,
|
|
},
|
|
});
|
|
|
|
return `${process.env.NEXT_PUBLIC_WEBAPP_URL}/auth/forgot-password/${createdResetPasswordRequest.id}`;
|
|
};
|
|
|
|
const guardAgainstTooManyPasswordResets = async (email: string) => {
|
|
const recentPasswordRequestsCount = await prisma.resetPasswordRequest.count({
|
|
where: {
|
|
email,
|
|
createdAt: {
|
|
gt: dayjs().subtract(RECENT_PERIOD_IN_MINUTES, "minutes").toDate(),
|
|
},
|
|
},
|
|
});
|
|
if (recentPasswordRequestsCount >= RECENT_MAX_ATTEMPTS) {
|
|
throw new Error("Too many password reset attempts. Please try again later.");
|
|
}
|
|
};
|
|
const passwordResetRequest = async (user: Pick<User, "email" | "name" | "locale">) => {
|
|
const { email } = user;
|
|
const t = await getTranslation(user.locale ?? "en", "common");
|
|
await guardAgainstTooManyPasswordResets(email);
|
|
const resetLink = await createPasswordReset(email);
|
|
const { sendPasswordResetEmail } = await import("@calcom/emails");
|
|
|
|
// send email in user language
|
|
await sendPasswordResetEmail({
|
|
language: t,
|
|
user,
|
|
resetLink,
|
|
});
|
|
};
|
|
|
|
export { passwordResetRequest };
|