Removed user _id from reset route. Use only token value. It's random enough that you don't need to include user id as well.

This commit is contained in:
Sahat Yalkabov
2014-02-17 20:46:21 -05:00
parent 0777294c98
commit bde061debf

4
app.js
View File

@ -102,8 +102,8 @@ app.post('/login', userController.postLogin);
app.get('/logout', userController.logout);
app.get('/forgot', forgotController.getForgot);
app.post('/forgot', forgotController.postForgot);
app.get('/reset/:id/:token', resetController.getReset);
app.post('/reset/:id/:token', resetController.postReset);
app.get('/reset/:token', resetController.getReset);
app.post('/reset/:token', resetController.postReset);
app.get('/signup', userController.getSignup);
app.post('/signup', userController.postSignup);
app.get('/contact', contactController.getContact);