Skip to content

Commit

Permalink
Fixed #27840 -- Fixed KeyError in PasswordResetConfirmView.form_valid().
Browse files Browse the repository at this point in the history
When a user is already logged in when submitting the password and
password confirmation to reset a password, a KeyError occurred while
removing the reset session token from the session.

Refs #17209

Thanks Quentin Marlats for the report and Florian Apolloner and Tim
Graham for the review.
  • Loading branch information
MarkusH committed Feb 14, 2017
1 parent 103e6cf commit b9b35f9
Show file tree
Hide file tree
Showing 2 changed files with 9 additions and 1 deletion.
2 changes: 1 addition & 1 deletion django/contrib/auth/views.py
Expand Up @@ -460,9 +460,9 @@ def get_form_kwargs(self):


def form_valid(self, form): def form_valid(self, form):
user = form.save() user = form.save()
del self.request.session[INTERNAL_RESET_SESSION_TOKEN]
if self.post_reset_login: if self.post_reset_login:
auth_login(self.request, user) auth_login(self.request, user)
del self.request.session[INTERNAL_RESET_SESSION_TOKEN]
return super().form_valid(form) return super().form_valid(form)


def get_context_data(self, **kwargs): def get_context_data(self, **kwargs):
Expand Down
8 changes: 8 additions & 0 deletions tests/auth_tests/test_views.py
Expand Up @@ -327,6 +327,14 @@ def test_confirm_login_post_reset(self):
self.assertRedirects(response, '/reset/done/', fetch_redirect_response=False) self.assertRedirects(response, '/reset/done/', fetch_redirect_response=False)
self.assertIn(SESSION_KEY, self.client.session) self.assertIn(SESSION_KEY, self.client.session)


def test_confirm_login_post_reset_already_logged_in(self):
url, path = self._test_confirm_start()
path = path.replace('/reset/', '/reset/post_reset_login/')
self.login()
response = self.client.post(path, {'new_password1': 'anewpassword', 'new_password2': 'anewpassword'})
self.assertRedirects(response, '/reset/done/', fetch_redirect_response=False)
self.assertIn(SESSION_KEY, self.client.session)

def test_confirm_display_user_from_form(self): def test_confirm_display_user_from_form(self):
url, path = self._test_confirm_start() url, path = self._test_confirm_start()
response = self.client.get(path) response = self.client.get(path)
Expand Down

0 comments on commit b9b35f9

Please sign in to comment.