feat: Self-service password resets #1484

Merged
ginger merged 30 commits from ginger/password-reset into main 2026-03-18 18:42:51 +00:00
Owner

This pull request adds support for self-service password resets using links issued by an admin command. Support for password reset emails will be added in a future PR.

Pull request checklist:

  • This pull request targets the main branch, and the branch is named something other than
    main.
  • I have written an appropriate pull request title and my description is clear.
  • I understand I am responsible for the contents of this pull request.
  • I have followed the contributing guidelines:
<!-- In order to help reviewers know what your pull request does at a glance, you should ensure that 1. Your PR title is a short, single sentence describing what you changed 2. You have described in more detail what you have changed, why you have changed it, what the intended effect is, and why you think this will be beneficial to the project. If you have made any potentially strange/questionable design choices, but didn't feel they'd benefit from code comments, please don't mention them here - after opening your pull request, go to "files changed", and click on the "+" symbol in the line number gutter, and attach comments to the lines that you think would benefit from some clarification. --> This pull request adds support for self-service password resets using links issued by an admin command. Support for password reset emails will be added in a future PR. <!-- Example: This pull request allows us to warp through time and space ten times faster than before by double-inverting the warp drive with hyperheated jump fluid, both making the drive faster and more efficient. This resolves the common issue where we have to wait more than 10 milliseconds to engage, use, and disengage the warp drive when travelling between galaxies. --> <!-- Closes: #... --> <!-- Fixes: #... --> <!-- Uncomment the above line(s) if your pull request fixes an issue or closes another pull request by superseding it. Replace `#...` with the issue/pr number, such as `#123`. --> **Pull request checklist:** <!-- You need to complete these before your PR can be considered. If you aren't sure about some, feel free to ask for clarification in #dev:continuwuity.org. --> - [x] This pull request targets the `main` branch, and the branch is named something other than `main`. - [x] I have written an appropriate pull request title and my description is clear. - [x] I understand I am responsible for the contents of this pull request. - I have followed the [contributing guidelines][c1]: - [x] My contribution follows the [code style][c2], if applicable. - [x] I ran [pre-commit checks][c1pc] before opening/drafting this pull request. - [x] I have [tested my contribution][c1t] (or proof-read it for documentation-only changes) myself, if applicable. This includes ensuring code compiles. - [x] My commit messages follow the [commit message format][c1cm] and are descriptive. - [x] I have written a [news fragment][n1] for this PR, if applicable<!--(can be done after hitting open!)-->. <!-- Notes on these requirements: - While not required, we encourage you to sign your commits with GPG or SSH to attest the authenticity of your changes. - While we allow LLM-assisted contributions, we do not appreciate contributions that are low quality, which is typical of machine-generated contributions that have not had a lot of love and care from a human. Please do not open a PR if all you have done is asked ChatGPT to tidy up the codebase with a +-100,000 diff. - In the case of code style violations, reviewers may leave review comments/change requests indicating what the ideal change would look like. For example, a reviewer may suggest you lower a log level, or use `match` instead of `if/else` etc. - In the case of code style violations, pre-commit check failures, minor things like typos/spelling errors, and in some cases commit format violations, reviewers may modify your branch directly, typically by making changes and adding a commit. Particularly in the latter case, a reviewer may rebase your commits to squash "spammy" ones (like "fix", "fix", "actually fix"), and reword commit messages that don't satisfy the format. - Pull requests MUST pass the `Checks` CI workflows to be capable of being merged. This can only be bypassed in exceptional circumstances. If your CI flakes, let us know in matrix:r/dev:continuwuity.org. - Pull requests have to be based on the latest `main` commit before being merged. If the main branch changes while you're making your changes, you should make sure you rebase on main before opening a PR. Your branch will be rebased on main before it is merged if it has fallen behind. - We typically only do fast-forward merges, so your entire commit log will be included. Once in main, it's difficult to get out cleanly, so put on your best dress, smile for the cameras! --> [c1]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md [c2]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/docs/development/code_style.mdx [c1pc]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#pre-commit-checks [c1t]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#running-tests-locally [c1cm]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#commit-messages [n1]: https://towncrier.readthedocs.io/en/stable/tutorial.html#creating-news-fragments
chore: News fragment
Some checks failed
Checks / Prek / Pre-commit & Formatting (pull_request) Waiting to run
Checks / Prek / Clippy and Cargo Tests (pull_request) Waiting to run
Update flake hashes / update-flake-hashes (pull_request) Waiting to run
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
6b1db1081e
ginger changed title from ginger/password-reset to feat: Self-service password resets 2026-03-03 18:37:31 +00:00
fix: Disallow issuing password reset tokens for deactivated users
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m42s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m19s
Update flake hashes / update-flake-hashes (pull_request) Successful in 2m49s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
750b689ded
@ -0,0 +87,4 @@
State(services): State<crate::State>,
Query(query): Query<PasswordResetQuery>,
axum::Form(form): axum::Form<PasswordResetForm>,
) -> Result<Response, WebError> {
Owner

To prevent CSRF, this needs to assert that the Sec-Fetch-Site and Origin headers are from the same domain (or use a CSRF token)

To prevent CSRF, this needs to assert that the Sec-Fetch-Site and Origin headers are from the same domain (or use a CSRF token)
Owner
https://www.alexedwards.net/blog/preventing-csrf-in-go
Author
Owner

Addressed.

Addressed.
ginger marked this conversation as resolved
fix: Add CSRF protection
Some checks are pending
Documentation / Build and Deploy Documentation (pull_request) Waiting to run
Checks / Prek / Pre-commit & Formatting (pull_request) Waiting to run
Checks / Prek / Clippy and Cargo Tests (pull_request) Waiting to run
Update flake hashes / update-flake-hashes (pull_request) Waiting to run
58e0716391
@ -0,0 +16,4 @@
#[derive(Debug, Template)]
#[template(path = "index.html.j2")]
struct Index<'a> {
client_domain: &'a str,
Owner

Using client_domain seems incorrect here, clients can resolve well-known themselves.

Using client_domain seems incorrect here, clients can resolve well-known themselves.
Author
Owner

oh yeah that is true

oh yeah that is true
ginger marked this conversation as resolved
fix: Use server name in index again
Some checks are pending
Checks / Prek / Pre-commit & Formatting (pull_request) Has started running
Checks / Prek / Clippy and Cargo Tests (pull_request) Has started running
Update flake hashes / update-flake-hashes (pull_request) Successful in 53s
Documentation / Build and Deploy Documentation (pull_request) Successful in 3m13s
8b8c4aadff
Jade approved these changes 2026-03-03 19:54:06 +00:00
Dismissed
ginger force-pushed ginger/password-reset from 8b8c4aadff
Some checks are pending
Checks / Prek / Pre-commit & Formatting (pull_request) Has started running
Checks / Prek / Clippy and Cargo Tests (pull_request) Has started running
Update flake hashes / update-flake-hashes (pull_request) Successful in 53s
Documentation / Build and Deploy Documentation (pull_request) Successful in 3m13s
to e74974661d
Some checks are pending
Documentation / Build and Deploy Documentation (pull_request) Waiting to run
Checks / Prek / Pre-commit & Formatting (pull_request) Waiting to run
Checks / Prek / Clippy and Cargo Tests (pull_request) Waiting to run
Update flake hashes / update-flake-hashes (pull_request) Waiting to run
2026-03-04 15:26:49 +00:00
Compare
chore: Remove unnecessary database map left over from refactor
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 2m9s
Update flake hashes / update-flake-hashes (pull_request) Successful in 28s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m45s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
d1c4e994ab
feat: Implement dedicated 404 page for routes under /_continuwuity/
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 9m41s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 5m58s
Update flake hashes / update-flake-hashes (pull_request) Successful in 3m59s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 1h0m0s
cfedde4e33
ginger force-pushed ginger/password-reset from cfedde4e33
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 9m41s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 5m58s
Update flake hashes / update-flake-hashes (pull_request) Successful in 3m59s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 1h0m0s
to 8443d2d813
Some checks failed
Update flake hashes / update-flake-hashes (pull_request) Successful in 41s
Documentation / Build and Deploy Documentation (pull_request) Successful in 2m8s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m5s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
2026-03-04 19:39:19 +00:00
Compare
fix: Evil CSS hackery
Some checks failed
Update flake hashes / update-flake-hashes (pull_request) Successful in 30s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m41s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m16s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 16m15s
0c035f1328
fix: Fix M_NOT_FOUND for users with no origin set
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m17s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m29s
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m54s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 12m10s
bc1443dc16
ginger force-pushed ginger/password-reset from bc1443dc16
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m17s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m29s
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m54s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 12m10s
to 34e3c030e9
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m21s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m18s
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m0s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 11m28s
2026-03-07 18:44:52 +00:00
Compare
fix: Fix password reset page appearance in light mode
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m15s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m3s
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m52s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 7m33s
4a4cf5f8f3
@ -12,2 +16,3 @@
let router = conduwuit_api::router::build(router, &services.server)
.merge(conduwuit_web::build())
.nest("/_continuwuity/", conduwuit_web::build())
.route("/", get(async || Redirect::permanent("/_continuwuity/")))
Owner

A redirect is unnecessary here, and a permanent redirect is a bad idea because someone could put this on their root domain

A redirect is unnecessary here, and a permanent redirect is a bad idea because someone could put this on their root domain
ginger marked this conversation as resolved
ginger force-pushed ginger/password-reset from 4a4cf5f8f3
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m15s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m3s
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m52s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 7m33s
to 75f6edb65a
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m19s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m55s
Update flake hashes / update-flake-hashes (pull_request) Successful in 54s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 12m44s
2026-03-09 16:13:57 +00:00
Compare
ginger force-pushed ginger/password-reset from 75f6edb65a
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m19s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m55s
Update flake hashes / update-flake-hashes (pull_request) Successful in 54s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 12m44s
to 2987bed990
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m14s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m13s
Update flake hashes / update-flake-hashes (pull_request) Successful in 59s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 34m57s
2026-03-18 15:01:23 +00:00
Compare
fix: Fix password reset page appearance in light mode
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m19s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m55s
Update flake hashes / update-flake-hashes (pull_request) Successful in 54s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 12m44s
75f6edb65a
Adds a new config option `index_page_allow_indexing` which defaults to false.

Fixes: !1527
chore: Add news fragment for !1527
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
ded23b56ac
fix: Fix logic error
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m12s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 19m20s
86699add33
feat: Use a context struct to store global template context
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
9a65e558e3
chore: Update news fragment
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m48s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 13m32s
6134917e65
chore: Merge branch 'ginger/password-reset' into 1527-prevent-search-engine-indexing
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m16s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
30199f9d33
chore: Rename option index_page_allow_indexing to allow_web_indexing
Some checks are pending
Documentation / Build and Deploy Documentation (pull_request) Waiting to run
Checks / Prek / Pre-commit & Formatting (pull_request) Waiting to run
Checks / Prek / Clippy and Cargo Tests (pull_request) Waiting to run
cbdcd4a774
fix: Update doc comment
Some checks failed
Update flake hashes / update-flake-hashes (pull_request) Waiting to run
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m42s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 24m33s
82ad7515ce
fix: Remove redirect on index
Some checks failed
Update flake hashes / update-flake-hashes (pull_request) Waiting to run
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m25s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m5s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
2013b246fe
ginger force-pushed ginger/password-reset from 2013b246fe
Some checks failed
Update flake hashes / update-flake-hashes (pull_request) Waiting to run
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m25s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m5s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to 0cc188f62c
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m17s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m53s
Update flake hashes / update-flake-hashes (pull_request) Successful in 51s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 22m0s
2026-03-18 16:43:11 +00:00
Compare
Jade approved these changes 2026-03-18 16:45:19 +00:00
Dismissed
Owner

:continuwuity:

:continuwuity:
feat: Add a panic handler and clean up error page
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m16s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m59s
Update flake hashes / update-flake-hashes (pull_request) Successful in 54s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
728c5828ba
Jade approved these changes 2026-03-18 17:46:56 +00:00
ginger scheduled this pull request to auto merge when all checks succeed 2026-03-18 17:48:33 +00:00
chore: Whitelist cognitive_complexity lint
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m24s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m0s
Update flake hashes / update-flake-hashes (pull_request) Successful in 58s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 41m26s
Documentation / Build and Deploy Documentation (push) Successful in 1m16s
Checks / Prek / Pre-commit & Formatting (push) Successful in 3m10s
Release Docker Image / Build linux-amd64 (release) (push) Successful in 14m17s
Release Docker Image / Build linux-arm64 (release) (push) Successful in 13m9s
Checks / Prek / Clippy and Cargo Tests (push) Successful in 44m46s
Release Docker Image / Create Multi-arch Release Manifest (push) Successful in 21s
Release Docker Image / Build linux-amd64 (max-perf) (push) Successful in 32m59s
Release Docker Image / Build linux-arm64 (max-perf) (push) Successful in 29m58s
Release Docker Image / Create Max-Perf Manifest (push) Successful in 21s
05a49ceb60
ginger merged commit 05a49ceb60 into main 2026-03-18 18:42:51 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
continuwuation/continuwuity!1484
No description provided.