Allow updating passwords using the admin api without logging out devices (#12952)

pull/10384/merge
Jan Christian Grünhage 2022-06-06 13:10:13 +02:00 committed by GitHub
parent e3163e2e11
commit fcd8703508
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 11 additions and 2 deletions

View File

@ -0,0 +1 @@
Allow updating a user's password using the admin API without logging out their devices. Contributed by @jcgruenhage.

View File

@ -115,7 +115,9 @@ URL parameters:
Body parameters:
- `password` - string, optional. If provided, the user's password is updated and all
devices are logged out.
devices are logged out, unless `logout_devices` is set to `false`.
- `logout_devices` - bool, optional, defaults to `true`. If set to false, devices aren't
logged out even when `password` is provided.
- `displayname` - string, optional, defaults to the value of `user_id`.
- `threepids` - array, optional, allows setting the third-party IDs (email, msisdn)
- `medium` - string. Kind of third-party ID, either `email` or `msisdn`.

View File

@ -226,6 +226,13 @@ class UserRestServletV2(RestServlet):
if not isinstance(password, str) or len(password) > 512:
raise SynapseError(HTTPStatus.BAD_REQUEST, "Invalid password")
logout_devices = body.get("logout_devices", True)
if not isinstance(logout_devices, bool):
raise SynapseError(
HTTPStatus.BAD_REQUEST,
"'logout_devices' parameter is not of type boolean",
)
deactivate = body.get("deactivated", False)
if not isinstance(deactivate, bool):
raise SynapseError(
@ -305,7 +312,6 @@ class UserRestServletV2(RestServlet):
await self.store.set_server_admin(target_user, set_admin_to)
if password is not None:
logout_devices = True
new_password_hash = await self.auth_handler.hash(password)
await self.set_password_handler.set_password(