Project

General

Profile

Actions

Feature proposal #8521

closed

Improve password reset redirect to be plugin and ajax aware

Added by krileon almost 3 years ago. Updated almost 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Start date:
19 May 2021
Due date:
% Done:

100%

Estimated time:

Description

Ajax endpoints end up responding with the full frontend output due to the reset password redirect. Change this to force a 403 response and just exit the output. For plugins fire a trigger (onResetPassword) to allow plugins to authorize access even during password reset (similar to verify consent usage).

Actions

Also available in: Atom PDF