Passwort-Reset per Einmal-Link (kver reset-link)
Ohne E-Mail-System erzeugt der Admin per CLI einen Link (/reset#<token>), gültig 72 h und einmal. Gespeichert wird nur der SHA-256 des Tokens; es steht im Fragment und geht nur im POST-Body an die API. Der Reset meldet alle alten Sessions ab und loggt direkt neu ein. Passwortregeln jetzt gemeinsam in checkNewPassword. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
b6cf8c7fa0
commit
81a74375b7
@@ -15,6 +15,10 @@ KVER_DSN=postgres://kver:passwort@host:5432/kontrollverlust?sslmode=disable
|
||||
# Optional: Pfad zur GeoLite2-ASN-DB im Container (leer = ASN-Auflösung aus).
|
||||
#KVER_GEOIP_ASN=/app/data/GeoLite2-ASN.mmdb
|
||||
|
||||
# Optional: öffentliche Adresse, damit `kver reset-link` einen fertigen Link
|
||||
# ausgibt statt nur des Pfads.
|
||||
#KVER_BASE_URL=https://example.org
|
||||
|
||||
# Selten nötig -- die Container-Defaults passen normalerweise:
|
||||
#KVER_ADDR=:8080
|
||||
|
||||
|
||||
Reference in New Issue
Block a user