0.5.0
Pre-release
Pre-release
This release adds email delivery through the Java Mail Sender module to add the ability for a user to reset their password, let's go into detail:
- Set Up Email Delivery & Configurationn
- Created A RestorationToken Resource
- Added A New /password-resets Endpoint, It Validates the Email, Creates A RestorationToken for the User, And Sends the New Password Link Containing the UUID Of the Token
- Added A New /password-resets/{token} Endpoint, This Will Validate the RestorationToken, And Update the Password If Everything Goes Well
- Removed The /users/setup Endpoint Which Was the Same as Password Reset but Did Not Use Email Verification, Making the User Account More Vulnerable
- Deprecated The enableUserPassword() Method in the UserService, the sendPasswordResetEmail() And resetPasswordWithToken() Methods Are Recommended Instead
Note: The email that's sent in the /password-resets endpoint only contains a link, and clicking on it, by default will send a GET request, but the endpoint only has a POST method, it will require a front-end page that prepares the request through a form.
The next step is authentication, which might take a while, so stay tuned.