PR #357 (closed #356, P0) fixed a bug where the resetPassword API handler forgot to base64-decode new_password, locking out invited users. PR #357 noted that a CI guard against this class of bug (a handler that accepts a password but skips the decode step) was deferred as a follow-up, but no issue was filed.
Scope:
Out of scope when deferred: PR #357 was a targeted P0 fix; the systemic guard is a separate, lower-priority hardening item.
Deferred by: #357
Related: #356 (the original bug, fixed).
PR #357 (closed #356, P0) fixed a bug where the
resetPasswordAPI handler forgot to base64-decodenew_password, locking out invited users. PR #357 noted that a CI guard against this class of bug (a handler that accepts a password but skips the decode step) was deferred as a follow-up, but no issue was filed.Scope:
Out of scope when deferred: PR #357 was a targeted P0 fix; the systemic guard is a separate, lower-priority hardening item.
Deferred by: #357
Related: #356 (the original bug, fixed).