Repository navigation
parse-server 2.8.1: Cannot login after changing user password #4790
Description
Activity
- changed the title
[-]Cannot login after changing user password after upgrading to 2.8.1[/-][+]parse-server 2.8.1: Cannot login after changing user password[/+]on May 26, 2018 Please provide the logs when running with VERBOSE=1 of the whole process of singing up, logging in, changing password etc...
Is the old password still valid?
I can't try because I could not remember the old password. I test against several other accounts and it seems that this problem affect accounts that are created long ago such as April 2015 (they were migrated from parse.com to ParseServer). The recent accounts is working fine after password reset.
Is this related to the migration of revokable session token (in 2017) or the User.authData and Session data?
I am going to sleep now and will be back online in 8 hours time. Thanks Mr Vilmart for checking on this.
Perhaps those account are still on revocable sessions and you’re hitting a nasty bug. Any chance you can get a look at the object in the DB and check if the sessionToken is still an old one ?
I used mLab to query the _Session table. I could not find session for the failed to logon users.
This is the _user record for the account that I could not login. Does it contain any clue on the sessionToken type?
{
"_id": "xxx",
"_created_at": {
"$date": "2015-01-26T00:34:23.529Z"
},
"_hashed_password": "hashedXXX",
"_session_token": "xxx",
"_updated_at": {
"$date": "2018-05-26T15:51:12.611Z"
},
"email": "[email protected]",
"username": "Nebi",
"emailVerified": true,
"_email_verify_token": "yyy"
}Legacy session tokens have the token on he user object; this is what you see there.
Thanks Florent. Was there any recent deprecation of logic in this area? What are the ways that I can adopt to solve this problem?
parse-server never supported old session tokens, further investigation need to be done to reproduce the issue and perhaps find a workaround. I have trouble also understanding why login information would not work after resetting the password.
Thanks.
Apparently, for those old user account, session token is never generated for user login. I can help to test/reproduce if you need, just let me know.
May I trouble you to delete the log file that I submitted earlier? I deleted the link in this thread but could not delete the file. I can email you the actual link if you need to link to delete it.
I don’t believe I have access to the log file myself. I can see the comment isn’t there anymore.
As for the reproduction, that would be very nice to have an edge to edge test that simulates this password exchange / replacement flow. This may help us understand the issue a bit more in depth.
There are many tests for the ‘reset password’ emails as well as for legacy session tokens. Perhaps there’s something there that’s problematic
I have the same problem, just after updating parse server logging in with my old password returned invalid username/password error. Then i have changed password, logged in. After some time logged out and again i cant login. In all cases the password was the same old password.
I work around this problem by manually deleting the old "_User" record and use app GUI to "signup" for new user account.
The new user account is having different data structure and don't have the password reset problem.
{
"_id": "xxx",
"email": "[email protected]",
"username": "Nebi",
"_hashed_password": "hashedXXX",
"emailVerified": true,
"_wperm": [
"xxx"
],
"_rperm": [
"",
"xxx"
],
"_acl": {
"xxx": {
"w": true,
"r": true
},
"": {
"r": true
}
},
"_created_at": {
"$date": "20xx-xx-xxTyy:yy:yy.yyyZ"
},
"_updated_at": {
"$date": "20xx-xx-xxTyy:yy:yy.yyyZ"
}
}Interesting! I’ll be able to investigate from there with the old user data then!
The full old user object is the one that was previously posted?
35 remaining items
@nebitrams ok good to know. But you should not have done that as when you'll deploy to heroku or somewhere else, this won't work anymore.
Thanks @flovilmart for fixing this issue.
For production, I will wait for 2.8.2 and not patch it using the parse-server#latest.This issue still persists in 2.8.2
Logging in causes error invalid username/password for users from previous version.
@lxknvlk can you open a new issue please, with providing verbose logs, as well as any relevant information that would help isolating the issue?
@flovilmart ok
@flovilmart Why open a new issue if the issue wasn't resolved?
Personally I'm still having issues in installing the new parse-server 2.8.2.It’s been resolved according to the person who opened it. So, I’m not sure what to say, open a new issue please, with filling all required informations.
The same problem here.
Parse 2.8.1 on node 6.11.5 authorization failed.Can you try with 2.8.2 on node 8+ please?
I will ask my hosting provider (nodechef.com) to get it up and running, because now it crashes then I try to run it on node 8.
@artua so please reach out to nodechef support.
@flovilmart I tested 2.8.2 in heroku and it works well. I am using these node and npm version.
remote: Downloading and installing node 10.4.0...
remote: Using default npm version: 6.1.0Awesome! Good to hear!
Issue Description
These is error deployment error (see log showing Kerberos compilation error) when I deploy to Heroku. The application works fine in all expects except that I cannot login after changing user password.
Steps to reproduce
error: Error generating response. ParseError { code: 101, message: 'Invalid username/password.' } code=101, message=Invalid username/password.
error: Invalid username/password. code=101, message=Invalid username/password.
It works after I rollback to previous version in heroku with parse-server 2.7.4
Expected Results
I should be able to login after changing password.
Actual Outcome
I cannot login.
Environment Setup
Server
Database
Logs/Trace
This is the heroku deployment error.
-----> Node.js app detected
-----> Creating runtime environment
-----> Installing binaries
engines.node (package.json): >=4.3
engines.npm (package.json): unspecified (use default)
-----> Restoring cache
Skipping cache restore (new-signature)
-----> Building dependencies
Installing node modules (package.json)