Compare commits

..

2 Commits

Author SHA1 Message Date
Trevor Vallender 72f2894b06 Ensure users can’t be spammed with password resets 2024-06-05 14:34:22 +01:00
Trevor Vallender 651813066e Allow deletion of avatars 2024-06-05 13:28:51 +01:00
6 changed files with 41 additions and 1 deletions

View File

@ -20,6 +20,9 @@ class UserMailer < ApplicationMailer
@user = params[:user]
@token = params[:token]
return if @user.password_reset_last_sent_at&.after?(10.minutes.ago)
@user.update(password_reset_last_sent_at: Time.zone.now)
mail(to: @user.email, subject: t(".password_reset.subject"))
end
end

View File

@ -0,0 +1,7 @@
# frozen_string_literal: true
class AddPasswordResetLastSentAtToUser < ActiveRecord::Migration[7.1]
def change
add_column :users, :password_reset_last_sent_at, :datetime
end
end

3
db/schema.rb generated
View File

@ -10,7 +10,7 @@
#
# It's strongly recommended that you check this file into your version control system.
ActiveRecord::Schema[7.1].define(version: 2024_05_30_073852) do
ActiveRecord::Schema[7.1].define(version: 2024_06_05_132327) do
# These are extensions that must be enabled in order to support this database
enable_extension "plpgsql"
@ -221,6 +221,7 @@ ActiveRecord::Schema[7.1].define(version: 2024_05_30_073852) do
t.datetime "created_at", null: false
t.datetime "updated_at", null: false
t.boolean "verified", default: false, null: false
t.datetime "password_reset_last_sent_at"
t.index ["email"], name: "index_users_on_email", unique: true
t.index ["username"], name: "index_users_on_username", unique: true
t.index ["verified"], name: "index_users_on_verified"

View File

@ -0,0 +1,17 @@
# frozen_string_literal: true
class UserMailerTest < ActionMailer::TestCase
test "password resets cant be resent within 10 minutes" do
user = users(:trevor)
assert_emails(+1) do
UserMailer.with(user: user, token: user.generate_token_for(:password_reset)).password_reset.deliver_now
end
assert_emails(0) do
UserMailer.with(user: user, token: user.generate_token_for(:password_reset)).password_reset.deliver_now
end
travel 11.minutes
assert_emails(+1) do
UserMailer.with(user: user, token: user.generate_token_for(:password_reset)).password_reset.deliver_now
end
end
end

View File

@ -55,4 +55,15 @@ class UserTest < ActiveSupport::TestCase
user.update(password: "new_password")
assert_nil User.find_by_token_for(:password_reset, token)
end
test "avatar is automatically deleted when flag set" do
user = users(:trevor)
assert user.avatar.attached?
user.first_name = "Newname"
user.save
assert user.avatar.attached?
user.delete_avatar = true
user.save
assert_not user.avatar.attached?
end
end

View File

@ -1,3 +1,4 @@
- ensure password reset emails can't send too often
- default avatars
- shared/private notes
- Add characters to users/tables