Table of Contents |
---|
Purpose
...
- Add to mithril.users password_expiresset_at = now()+config.password_lifetime
2. Save passwords history
When $.decrypted_hash<>mihril.users.password (the user set up a new password) - add the row to mithril.user_passwords_history
Destination | Source | Description |
---|---|---|
id | Autogenerated | |
user_id | $.user_id | Extract user from token |
password | $.decrypted_hash | |
inserted_at | Timestamp: now() | Get current date-time |
3. Not allow to use recently used passwords
...
Once a day fetch all records from mithril.users where now()>=mithril.users.password_expiresset_at+config.password_lifetime
- set expires_at=now() for all tokens where tokens.user_id=$user.id (--and tokens.name='refresh_token')
Don't send access_token in response on {{host}}/
oauth/tokens until the password will be changed. Show the message Error 401 "The password expired".
...