Removed user _id from reset route. Use only token value. It's random enough that you don't need to include user id as well.
This commit is contained in:
4
app.js
4
app.js
@ -102,8 +102,8 @@ app.post('/login', userController.postLogin);
|
|||||||
app.get('/logout', userController.logout);
|
app.get('/logout', userController.logout);
|
||||||
app.get('/forgot', forgotController.getForgot);
|
app.get('/forgot', forgotController.getForgot);
|
||||||
app.post('/forgot', forgotController.postForgot);
|
app.post('/forgot', forgotController.postForgot);
|
||||||
app.get('/reset/:id/:token', resetController.getReset);
|
app.get('/reset/:token', resetController.getReset);
|
||||||
app.post('/reset/:id/:token', resetController.postReset);
|
app.post('/reset/:token', resetController.postReset);
|
||||||
app.get('/signup', userController.getSignup);
|
app.get('/signup', userController.getSignup);
|
||||||
app.post('/signup', userController.postSignup);
|
app.post('/signup', userController.postSignup);
|
||||||
app.get('/contact', contactController.getContact);
|
app.get('/contact', contactController.getContact);
|
||||||
|
Reference in New Issue
Block a user