fix(web): keep reset-password wire shape for the default method

resetPassword() unconditionally added `method` and an empty `totp_code` to
every request, which broke the Playwright smoke test that asserts the
recovery-key flow posts exactly {user, recovery_key, new_password}.

Send only the second-factor fields that apply to the selected method, so the
default recovery-key flow stays byte-compatible with existing callers while
the totp / recovery_code methods still carry their inputs.
This commit is contained in:
TyperBody
2026-09-24 01:31:54 +08:00
parent 28e8821365
commit 0bf610037a
+19 -11
View File
@@ -1404,17 +1404,25 @@ export class BackendClient extends BaseHttpClient {
totpCode?: string;
} = {},
): Promise<{ user: string }> {
return this.post(
'/api/v1/user/reset-password',
{
user,
new_password: newPassword,
method: options.method ?? 'recovery_key',
recovery_key: options.recoveryKey,
totp_code: options.totpCode,
},
{ skipWorkspace: true },
);
// Only send the second-factor fields that apply to the selected method, so
// the default recovery-key flow keeps its historical wire shape (no empty
// `method`/`totp_code` keys) and stays byte-compatible with existing callers.
const body: Record<string, unknown> = {
user,
new_password: newPassword,
};
if (options.method && options.method !== 'recovery_key') {
body.method = options.method;
}
if (options.recoveryKey) {
body.recovery_key = options.recoveryKey;
}
if (options.totpCode) {
body.totp_code = options.totpCode;
}
return this.post('/api/v1/user/reset-password', body, {
skipWorkspace: true,
});
}
public changePassword(