• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

strongloop / loopback / 5720
90%
master: 90%

Build:
Build:
LAST BUILD BRANCH: chore/update-lts
DEFAULT BRANCH: master
Ran 20 Apr 2017 08:29AM UTC
Jobs 3
Files 35
Run time 38s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

pending completion
5720

push

travis-ci

bajtos
Implement more secure password flow

Improve the flow for setting/changing/resetting User password to make
it more secure.

 1. Modify `User.resetPassword` to create a token scoped to allow
    invocation of a single remote method: `User.setPassword`.

 2. Scope the method `User.setPassword` so that regular tokens created
    by `User.login` are not allowed to execute it.

For backwards compatibility, this new mode (flow) is enabled only
when User model setting `restrictResetPasswordTokenScope` is set to
`true`.

 3. Changing the password via `User.prototype.patchAttributes`
    (and similar DAO methods) is no longer allowed. Applications
    must call `User.changePassword` and ask the user to provide
    the current (old) password.

For backwards compatibility, this new mode (flow) is enabled only
when User model setting `rejectPasswordChangesViaPatchOrReplace` is set
to `true`.

1753 of 2204 branches covered (79.54%)

33 of 33 new or added lines in 1 file covered. (100.0%)

3208 of 3579 relevant lines covered (89.63%)

6271.05 hits per line

New Missed Lines in Diff

Lines Coverage ∆ File
1
100.0
common/models/user.js

Uncovered Existing Lines

Lines Coverage ∆ File
22
100.0
common/models/user.js
Jobs
ID Job ID Ran Files Coverage
1 5720.1 20 Apr 2017 08:29AM UTC 0
89.63
Travis Job 5720.1
2 5720.2 20 Apr 2017 08:29AM UTC 0
89.63
Travis Job 5720.2
3 5720.3 20 Apr 2017 08:29AM UTC 0
89.63
Travis Job 5720.3
Source Files on build 5720
Detailed source file information is not available for this build.
  • Back to Repo
  • Travis Build #5720
  • c5ca2e1c on github
  • Prev Build on feature/set-password-with-token (#5718)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc