Skip to content

parse-server 2.8.1: Cannot login after changing user password #4790

Description

@nebitrams

Issue Description

These is error deployment error (see log showing Kerberos compilation error) when I deploy to Heroku. The application works fine in all expects except that I cannot login after changing user password.

Steps to reproduce

  1. Change user password using iOS ParseUI and also parse dashboard.
  2. Login using App ParseUI Login screen.
  3. Failed to login and this is the server error log.

error: Error generating response. ParseError { code: 101, message: 'Invalid username/password.' } code=101, message=Invalid username/password.
error: Invalid username/password. code=101, message=Invalid username/password.

It works after I rollback to previous version in heroku with parse-server 2.7.4

Expected Results

I should be able to login after changing password.

Actual Outcome

I cannot login.

Environment Setup

  • Server

    • parse-server version (Be specific! Don't say 'latest'.) : 2.8.1
    • Operating System: Heroku stack Cedar-14
    • Hardware: Heroku
    • Localhost or remote server? (AWS, Heroku, Azure, Digital Ocean, etc): Heroku
  • Database

    • MongoDB version: current is 3.2.10 (MMAPv1). Should I switch to mLab latest 3.4.15 (MMAPv1)?
    • Storage engine: mLab
    • Hardware: mLab
    • Localhost or remote server? (AWS, mLab, ObjectRocket, Digital Ocean, etc): mLab

Logs/Trace

This is the heroku deployment error.

-----> Node.js app detected
-----> Creating runtime environment

   NPM_CONFIG_LOGLEVEL=error
   NODE_VERBOSE=false
   NODE_ENV=production
   NODE_MODULES_CACHE=true

-----> Installing binaries
engines.node (package.json): >=4.3
engines.npm (package.json): unspecified (use default)

   Resolving node version >=4.3...
   Downloading and installing node 10.2.0...
   Using default npm version: 5.6.0

-----> Restoring cache
Skipping cache restore (new-signature)
-----> Building dependencies
Installing node modules (package.json)

   > [email protected] preinstall /tmp/build_786e8213e834a7d1022250f222c7b1bb/node_modules/parse-image
   > ./install.sh
   
   Cannot install using brew or sudo apt-get
   Please install manually
   
   > [email protected] install /tmp/build_786e8213e834a7d1022250f222c7b1bb/node_modules/bcrypt
   > node-pre-gyp install --fallback-to-build
   
   [bcrypt] Success: "/tmp/build_786e8213e834a7d1022250f222c7b1bb/node_modules/bcrypt/lib/binding/bcrypt_lib.node" is installed via remote
   
   > [email protected] install /tmp/build_786e8213e834a7d1022250f222c7b1bb/node_modules/uws
   > node-gyp rebuild > build_log.txt 2>&1 || exit 0
   
   
   > [email protected] install /tmp/build_786e8213e834a7d1022250f222c7b1bb/node_modules/kerberos
   > (node-gyp rebuild) || (exit 0)
   
   make: Entering directory `/tmp/build_786e8213e834a7d1022250f222c7b1bb/node_modules/kerberos/build'
   CXX(target) Release/obj.target/kerberos/lib/kerberos.o
   In file included from ../lib/kerberos.h:4:0,
   from ../lib/kerberos.cc:1:
   /app/.node-gyp/10.2.0/include/node/node.h:53:50: fatal error: core.h: No such file or directory
   #include "core.h"  // NOLINT(build/include_order)
   ^
   compilation terminated.
   make: *** [Release/obj.target/kerberos/lib/kerberos.o] Error 1
   make: Leaving directory `/tmp/build_786e8213e834a7d1022250f222c7b1bb/node_modules/kerberos/build'
   gyp ERR! build error
   gyp ERR! stack Error: `make` failed with exit code: 2
   gyp ERR! stack     at ChildProcess.onExit (/tmp/build_786e8213e834a7d1022250f222c7b1bb/.heroku/node/lib/node_modules/npm/node_modules/node-gyp/lib/build.js:258:23)
   gyp ERR! stack     at ChildProcess.emit (events.js:182:13)
   gyp ERR! stack     at Process.ChildProcess._handle.onexit (internal/child_process.js:237:12)
   gyp ERR! System Linux 4.4.0-1019-aws
   gyp ERR! command "/tmp/build_786e8213e834a7d1022250f222c7b1bb/.heroku/node/bin/node" "/tmp/build_786e8213e834a7d1022250f222c7b1bb/.heroku/node/lib/node_modules/npm/node_modules/node-gyp/bin/node-gyp.js" "rebuild"
   gyp ERR! cwd /tmp/build_786e8213e834a7d1022250f222c7b1bb/node_modules/kerberos
   gyp ERR! node -v v10.2.0
   gyp ERR! node-gyp -v v3.6.2
   gyp ERR! not ok
   
   > [email protected] postinstall /tmp/build_786e8213e834a7d1022250f222c7b1bb/node_modules/parse-server

Activity

  1. changed the title [-]Cannot login after changing user password after upgrading to 2.8.1[/-] [+]parse-server 2.8.1: Cannot login after changing user password[/+] on May 26, 2018
  2. flovilmart commented on May 26, 2018

    @flovilmart
    Contributor

    Please provide the logs when running with VERBOSE=1 of the whole process of singing up, logging in, changing password etc...

  3. flovilmart commented on May 26, 2018

    @flovilmart
    Contributor

    Is the old password still valid?

  4. nebitrams commented on May 26, 2018

    @nebitrams
    Author

    I can't try because I could not remember the old password. I test against several other accounts and it seems that this problem affect accounts that are created long ago such as April 2015 (they were migrated from parse.com to ParseServer). The recent accounts is working fine after password reset.

    Is this related to the migration of revokable session token (in 2017) or the User.authData and Session data?

    I am going to sleep now and will be back online in 8 hours time. Thanks Mr Vilmart for checking on this.

  5. flovilmart commented on May 26, 2018

    @flovilmart
    Contributor

    Perhaps those account are still on revocable sessions and you’re hitting a nasty bug. Any chance you can get a look at the object in the DB and check if the sessionToken is still an old one ?

  6. nebitrams commented on May 26, 2018

    @nebitrams
    Author

    I used mLab to query the _Session table. I could not find session for the failed to logon users.

    This is the _user record for the account that I could not login. Does it contain any clue on the sessionToken type?
    {
    "_id": "xxx",
    "_created_at": {
    "$date": "2015-01-26T00:34:23.529Z"
    },
    "_hashed_password": "hashedXXX",
    "_session_token": "xxx",
    "_updated_at": {
    "$date": "2018-05-26T15:51:12.611Z"
    },
    "email": "[email protected]",
    "username": "Nebi",
    "emailVerified": true,
    "_email_verify_token": "yyy"
    }

  7. flovilmart commented on May 26, 2018

    @flovilmart
    Contributor

    Legacy session tokens have the token on he user object; this is what you see there.

  8. nebitrams commented on May 27, 2018

    @nebitrams
    Author

    Thanks Florent. Was there any recent deprecation of logic in this area? What are the ways that I can adopt to solve this problem?

  9. flovilmart commented on May 27, 2018

    @flovilmart
    Contributor

    parse-server never supported old session tokens, further investigation need to be done to reproduce the issue and perhaps find a workaround. I have trouble also understanding why login information would not work after resetting the password.

  10. nebitrams commented on May 27, 2018

    @nebitrams
    Author

    Thanks.

    Apparently, for those old user account, session token is never generated for user login. I can help to test/reproduce if you need, just let me know.

    May I trouble you to delete the log file that I submitted earlier? I deleted the link in this thread but could not delete the file. I can email you the actual link if you need to link to delete it.

  11. flovilmart commented on May 27, 2018

    @flovilmart
    Contributor

    I don’t believe I have access to the log file myself. I can see the comment isn’t there anymore.

    As for the reproduction, that would be very nice to have an edge to edge test that simulates this password exchange / replacement flow. This may help us understand the issue a bit more in depth.

    There are many tests for the ‘reset password’ emails as well as for legacy session tokens. Perhaps there’s something there that’s problematic

  12. lxknvlk commented on May 27, 2018

    @lxknvlk

    I have the same problem, just after updating parse server logging in with my old password returned invalid username/password error. Then i have changed password, logged in. After some time logged out and again i cant login. In all cases the password was the same old password.

  13. nebitrams commented on May 27, 2018

    @nebitrams
    Author

    I work around this problem by manually deleting the old "_User" record and use app GUI to "signup" for new user account.

    The new user account is having different data structure and don't have the password reset problem.
    {
    "_id": "xxx",
    "email": "[email protected]",
    "username": "Nebi",
    "_hashed_password": "hashedXXX",
    "emailVerified": true,
    "_wperm": [
    "xxx"
    ],
    "_rperm": [
    "",
    "xxx"
    ],
    "_acl": {
    "xxx": {
    "w": true,
    "r": true
    },
    "
    ": {
    "r": true
    }
    },
    "_created_at": {
    "$date": "20xx-xx-xxTyy:yy:yy.yyyZ"
    },
    "_updated_at": {
    "$date": "20xx-xx-xxTyy:yy:yy.yyyZ"
    }
    }

  14. flovilmart commented on May 27, 2018

    @flovilmart
    Contributor

    Interesting! I’ll be able to investigate from there with the old user data then!

  15. flovilmart commented on May 27, 2018

    @flovilmart
    Contributor

    The full old user object is the one that was previously posted?

  16. 35 remaining items

  17. flovilmart commented on Jun 1, 2018

    @flovilmart
    Contributor

    @nebitrams ok good to know. But you should not have done that as when you'll deploy to heroku or somewhere else, this won't work anymore.

  18. nebitrams commented on Jun 1, 2018

    @nebitrams
    Author

    Thanks @flovilmart for fixing this issue.
    For production, I will wait for 2.8.2 and not patch it using the parse-server#latest.

  19. lxknvlk commented on Jun 5, 2018

    @lxknvlk

    This issue still persists in 2.8.2

    Logging in causes error invalid username/password for users from previous version.

  20. flovilmart commented on Jun 5, 2018

    @flovilmart
    Contributor

    @lxknvlk can you open a new issue please, with providing verbose logs, as well as any relevant information that would help isolating the issue?

  21. lxknvlk commented on Jun 6, 2018

    @lxknvlk
  22. dulmanr commented on Jun 6, 2018

    @dulmanr

    @flovilmart Why open a new issue if the issue wasn't resolved?
    Personally I'm still having issues in installing the new parse-server 2.8.2.

  23. flovilmart commented on Jun 6, 2018

    @flovilmart
    Contributor

    It’s been resolved according to the person who opened it. So, I’m not sure what to say, open a new issue please, with filling all required informations.

  24. artua commented on Jun 7, 2018

    @artua

    The same problem here.
    Parse 2.8.1 on node 6.11.5 authorization failed.

  25. flovilmart commented on Jun 7, 2018

    @flovilmart
    Contributor

    Can you try with 2.8.2 on node 8+ please?

  26. artua commented on Jun 7, 2018

    @artua

    I will ask my hosting provider (nodechef.com) to get it up and running, because now it crashes then I try to run it on node 8.

  27. flovilmart commented on Jun 7, 2018

    @flovilmart
    Contributor

    @artua so please reach out to nodechef support.

  28. nebitrams commented on Jun 8, 2018

    @nebitrams
    Author

    @flovilmart I tested 2.8.2 in heroku and it works well. I am using these node and npm version.

    remote: Downloading and installing node 10.4.0...
    remote: Using default npm version: 6.1.0

  29. flovilmart commented on Jun 8, 2018

    @flovilmart
    Contributor

    Awesome! Good to hear!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions