Skip to content

fix(auth): complete changePassword route contract and fix handler error mapping - #1249

Open
Wittig18 wants to merge 1 commit into
RevoraOrg:masterfrom
Wittig18:fix-change-password-route
Open

Wittig18 wants to merge 1 commit into
RevoraOrg:masterfrom
Wittig18:fix-change-password-route

Conversation

@Wittig18

@Wittig18 Wittig18 commented Oct 1, 2026

Copy link
Copy Markdown

Summary

Fixes #963 - completes the changePassword route implementation and fixes a critical handler bug.

Changes

changePasswordRoute.ts - Fixed inaccurate comment claiming auth was Bearer JWT (or x-user-id stub in dev). Auth is actually Bearer JWT via createRequireAuth (session-hardened). Route paths corrected to actual mounted paths (/me/change-password, /me/password). Full success/failure HTTP contract documented.

changePasswordHandler.ts - Critical bug fix: the handler ignored the service ChangePasswordResult, so wrong passwords/user-not-found/weak passwords returned 200 OK. Now maps each reason to the correct error:

  • VALIDATION_ERROR to 400
  • WRONG_PASSWORD to 401
  • USER_NOT_FOUND to 404

types.ts - Path docs aligned; ChangePasswordResponse updated to real { ok: true, message } shape.

changePasswordRoute.test.ts (new) - 12 supertest tests covering:

  • Factory wiring/route registration
  • Success (hash replaced + sessions invalidated)
  • Wrong password to 401 with no side effects
  • Missing fields to 400
  • Weak password to 400
  • User not found to 404
  • PATCH alias parity
  • Unauthenticated to 401

All 26 tests pass (handler, service, route suites), lint clean.

Closes #963

@Wittig18
Wittig18 force-pushed the fix-change-password-route branch from 3c972c7 to 0434033 Compare October 4, 2026 16:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Implement createChangePasswordRouter behavior currently marked as incomplete

2 participants