From bde061debf276dcf0d2c06457b753d5643924d49 Mon Sep 17 00:00:00 2001 From: Sahat Yalkabov Date: Mon, 17 Feb 2014 20:46:21 -0500 Subject: [PATCH] Removed user _id from reset route. Use only token value. It's random enough that you don't need to include user id as well. --- app.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app.js b/app.js index cb25e76d0f..cf07fc02c7 100755 --- a/app.js +++ b/app.js @@ -102,8 +102,8 @@ app.post('/login', userController.postLogin); app.get('/logout', userController.logout); app.get('/forgot', forgotController.getForgot); app.post('/forgot', forgotController.postForgot); -app.get('/reset/:id/:token', resetController.getReset); -app.post('/reset/:id/:token', resetController.postReset); +app.get('/reset/:token', resetController.getReset); +app.post('/reset/:token', resetController.postReset); app.get('/signup', userController.getSignup); app.post('/signup', userController.postSignup); app.get('/contact', contactController.getContact);