Skip to content

fix(post): send current_password when replacing an issued password - #198

Merged
catinspace-au merged 2 commits into
mainfrom
fix/post-current-password
Oct 4, 2026
Merged

catinspace-au merged 2 commits into
mainfrom
fix/post-current-password

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

make post breaks against every engine from v1.22.11 on. The engine's own-password change has required current_password since engine #667, and post only sent new_password, so its forced-change login got a 422.

post now sends the password it just logged in with. The test fake used to accept the change with no current_password, which is how this got past the suite: it now refuses a missing one with 422 and a wrong one with 403, the same as the engine (accounts.py:682-691).

Proof: make check-tests 768 passed, make check-python clean.

The engine's own-password change has required current_password since v1.22.11 (engine #667) and answers 422 without it, so make post failed its forced-change login against every engine from that release on. post now sends the password it just logged in with. The test fake refuses a change with no current_password, or a wrong one, the way the engine does, so the drift cannot pass silently again.
A request validation error echoes the submitted body, and the body now carries current_password beside new_password. Both are masked before the fault text reaches stderr; a test feeds back the whole body and asserts neither value prints.
@catinspace-au
catinspace-au merged commit 41d1aa3 into main Oct 4, 2026
7 checks passed
@catinspace-au
catinspace-au deleted the fix/post-current-password branch October 4, 2026 06:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant