Repository navigation
Implement lost password procedure - #3519
Merged
Merged
Conversation
Sekiro-kost
approved these changes
Sep 18, 2026
Salvialf
reviewed
Oct 8, 2026
Contributor
There was a problem hiding this comment.
Nice work on this one, it's a feature that was really missing and the integration fits well into the existing login page.
Pushed my review fixes on the branch, one commit per topic:
- Fixed the lost/reset password forms showing at the bottom of the card, plus markup cleanup (
hiddenclass, notabindex, duplicated id) - Doc links via
jeedom::getDocUrl()(develop merged) and clearer labels - Reset link forces
v=d, phones were redirected to the mobile UI which ignoresrpk - Fixed Enter sending every request twice (native form submission +
keypresshandler), which also fixes Enter in the forced password change - Added missing log translations,
infoentries moved tolog::audit() - Disabled users can no longer request a reset, like
login() - Same response time on every path: the "link sent" path had no delay and answered almost instantly, revealing valid logins
- Throttled requests now return an explicit "too many requests" error instead of the success message: the limit is per IP so it reveals nothing about logins, and the instant response already gave it away
Left to you: the warning logs (log::audit() is always info, default level 400 hides audit entries), and $current_ip = getClientIp() in askPassword (core/ajax/user.ajax.php) to switch to network::getClientIp() in #3532. LDAP and the internal/external link address are deferred as discussed.
Out of scope here: no password change (profile, users page, this reset, jeecli) revokes existing sessions or registered devices, to be handled globally in a later PR.
Salvialf
self-requested a review
October 9, 2026 08:12
Salvialf
approved these changes
Oct 9, 2026
…stent French phrasing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR adds a complete password reset flow from the login page.
Users can now request a password reset link from the “forgot password” screen. When a valid reset link is opened, Jeedom displays a dedicated password reset form, validates the new password confirmation, and submits the reset using the token from the URL.
The backend now generates short-lived reset tokens, validates token lifetime explicitly before changing the password, rejects password reset attempts for system users, and removes consumed or expired tokens. Reset requests are also throttled per IP address to prevent repeated notification attempts while keeping the client response generic.
Suggested changelog entry
Ajout d’une fonctionnalité de réinitialisation de mot de passe par lien sécurisé avec expiration, limitation par IP. L'utilisateur doit avoir configuré une commande de notification dans son profil pour que cela fonctionne.
Related issues/external references
Fixes #3518
Types of changes