2023-06-05 13:05:25 +00:00
|
|
|
import { NextApiRequest, NextApiResponse } from "next";
|
2023-06-05 15:33:27 +00:00
|
|
|
import { sendResetPassword, sendResetPasswordSuccessMail } from "@documenso/lib/mail";
|
2023-06-05 13:05:25 +00:00
|
|
|
import { defaultHandler, defaultResponder } from "@documenso/lib/server";
|
|
|
|
|
import prisma from "@documenso/prisma";
|
|
|
|
|
import crypto from "crypto";
|
|
|
|
|
|
|
|
|
|
async function postHandler(req: NextApiRequest, res: NextApiResponse) {
|
|
|
|
|
const { email } = req.body;
|
|
|
|
|
const cleanEmail = email.toLowerCase();
|
|
|
|
|
|
|
|
|
|
if (!cleanEmail || !cleanEmail.includes("@")) {
|
|
|
|
|
res.status(422).json({ message: "Invalid email" });
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
const user = await prisma.user.findFirst({
|
|
|
|
|
where: {
|
|
|
|
|
email: cleanEmail,
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
if (!user) {
|
2023-06-05 15:52:00 +00:00
|
|
|
return res.status(404).json({ message: "No user found with this email." });
|
2023-06-05 13:05:25 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
const token = crypto.randomBytes(64).toString("hex");
|
2023-06-05 15:52:00 +00:00
|
|
|
|
|
|
|
|
let passwordResetToken;
|
|
|
|
|
|
|
|
|
|
try {
|
|
|
|
|
passwordResetToken = await prisma.passwordResetToken.create({
|
|
|
|
|
data: {
|
|
|
|
|
token,
|
|
|
|
|
userId: user.id,
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
} catch (error) {
|
|
|
|
|
return res.status(500).json({ message: "Error saving token." });
|
|
|
|
|
}
|
2023-06-05 13:05:25 +00:00
|
|
|
|
2023-06-05 13:44:22 +00:00
|
|
|
await sendResetPassword(user, passwordResetToken.token);
|
2023-06-05 13:05:25 +00:00
|
|
|
|
2023-06-05 14:36:20 +00:00
|
|
|
res.status(200).json({ message: "Password reset email sent." });
|
2023-06-05 13:05:25 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
export default defaultHandler({
|
|
|
|
|
POST: Promise.resolve({ default: defaultResponder(postHandler) }),
|
|
|
|
|
});
|