You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit f3920e4
Browse filesBrowse the repository at this point in the historyBrowse files
fix(profile): return sentinel errors for wrong password and duplicate email (#931)
On the profile-update path, wrong current password and duplicate email
both fell through to the generic 500 "Internal server error" because
UpdateUserProfile returned plain fmt.Errorf strings that the handler
did not recognise as client errors.
- Add ErrCurrentPasswordIncorrect sentinel to internal/auth/errors.go.
- Return the sentinel (not a plain string) from UpdateUserProfile when
the current password does not match.
- Return the existing ErrEmailInUse sentinel (not a plain string) from
updateUserEmail when the address is taken.
- Add mapProfileUpdateError in handler_auth.go: wrong password -> 401
with the sentinel message; duplicate email -> 409 with the neutral
privacy-safe message "Unable to update email" (does not confirm
another account's existence, preventing enumeration).
- Add handler tests for both new error paths asserting the correct
status code and message.
- Add service-layer tests asserting errors.Is on both sentinels so the
contract is positively enforced.
Closes#929
0 commit comments