ashok

ashok

Custom controller for reset password using Pow

I have used Pow for user authentication and successfully created login & logout feature using custom controller (Custom controllers — Pow v1.0.39 ) Now I want to create Forgot Password feature. Pow provides reset password extension “PowResetPassword”. I have install Pow extension by reading the documentation (PowResetPassword — Pow v1.0.39)

I have created a new controller for reset password “WEB_PATH/controllers/reset_password/reset_password_controller.ex”

The controller code is shown below.

def new(conn, _params) do
changeset = Pow.Plug.change_user(conn)

render(conn, "new.html", changeset: changeset)

end

def create(conn, %{“user” => user_params}) do

conn
|> PowResetPassword.Plug.create_reset_token(user_params)
|> case do
     {:ok, conn} ->
     conn
     |> put_flash(:info, 'Check your email to reset password')
     |> redirect(to: Routes.reset_password_path(conn, :new))

     {:error, conn} ->
        conn
        |> put_flash(:info, "Error resetting")
        |> redirect(to: Routes.reset_password_path(conn, :new))

   end

end

def update(conn, %{“user” => user_params}) do

PowResetPassword.Plug.update_user_password(conn, user_params)
# {:ok, conn} = Pow.Plug.clear_authenticated_user(conn)

redirect(conn, to: Routes.login_path(conn, :new))

end

My reset password view is:

<%= form_for @changeset, Routes.reset_password_path(@conn, :create), [class: “form-wrap login-form w-100”], fn f → %>

Reset password

<%= label f, :email, "" %> <%= text_input f, :email, class: "form-control", id: "email", placeholder: "Email" %>
<%= submit "Continue", class: "btn btn-primary w-100" %>

<% end %>

My routes are

signup_path GET / MyAppWeb.RegistrationController :new
signup_path POST / MyAppWeb.RegistrationController :create
login_path GET /login MyAppWeb.SessionController :new
login_path POST /login MyAppWeb.SessionController :create
reset_password_path GET /reset-password/new MyAppWeb.ResetPasswordController :new
reset_password_path POST /reset-password MyAppWeb.ResetPasswordController :create
reset_password_path PATCH /reset-password/:id MyAppWeb.ResetPasswordController :update
PUT /reset-password/:id MyAppWeb.ResetPasswordController :update
reset_password_path GET /reset-password/:id MyAppWeb.ResetPasswordController :edit
logout_path DELETE /logout MyAppWeb.SessionController :delete
game_path GET /game MyAppWeb.PageController :index
websocket WS /socket/websocket MyAppWeb.UserSocket

When I hit submit ‘continue’ button in reset password page with or without entring any email I am getting error as shown below:

CaseClauseError at POST /reset-password
no case clause matching: {:error, #Ecto.Changeset<action: :update, changes: %{}, errors: [password_hash: {“can’t be blank”, [validation: :required]}, password: {“can’t be blank”, [validation: :required]}], data: #MyApp.Users.User<>, valid?: false>, %Plug

I have taken reference from the Pow module PowResetPassword.Phoenix.ResetPasswordController present in my project “deps” folder but not sure which one to use in “create” , “edit” and “update”. please suggest how can I over come this issue.

Marked As Solved

danschultzer

danschultzer

Pow Core Team

Your case statement is invalid. PowResetPassword.Plug.create_reset_token/2 returns {:ok, %{token: token, user: user}, conn} or {:error, changeset, conn}.

For security you should also respond with success no matter the result:

def create(conn, %{“user” => user_params}) do
  conn
  |> PowResetPassword.Plug.create_reset_token(user_params)
  |> case do
    {:ok, %{token: token, user: user}, conn} ->
      # Send e-mail

      conn
      |> put_flash(:info, 'Check your email to reset password')
      |> redirect(to: Routes.reset_password_path(conn, :new))

    {:error, conn} ->
      conn
      |> put_flash(:info, 'Check your email to reset password')
      |> redirect(to: Routes.reset_password_path(conn, :new))
  end
end

Take a look at the controller for more.

Also Liked

danschultzer

danschultzer

Pow Core Team

Just for anyone who’s reading, the question was answered on Github: Custom controller for reset password using pow · Issue #354 · pow-auth/pow · GitHub

sveredyuk

sveredyuk

@danschultzer I see. Thank you a lot for your amazing work.

Last Post!

Hossman333

Hossman333

Ahhhhhh. I figured it out. Haha. Whoops. I was using my own changeset instead of what I should have been doing. Inside the changeset is where the magic happens.

I now call these methods inside my changeset:

      |> Pow.Ecto.Schema.Changeset.confirm_password_changeset(attrs, @pow_config)
      |> Pow.Ecto.Schema.Changeset.new_password_changeset(attrs, @pow_config)

Thanks!

Where Next?

Popular in Questions Top

electic
Hi, I am new to Elixir. I am trying to use the DateTime component to insert a date into MySQL however the there seems to be no way to fo...
New
joeerl
Hello again - after a longish gap I’ve decided I really must dig into Elixir and see what’s been happening here - so I have a few questio...
New
gshaw
What is the idiomatic way of matching for not nil in Elixir? E.g., First way: defp halt_if_not_signed_in(conn, signed_in_account) when...
New
belgoros
I’m not a pro in using Regex and can’t figure out why the following behaviour happens, especially if we take into account the difference ...
New
freewebwithme
Using vs code and installed ElixirLS: support and debugger. And I got an error popped up on start up says Failed to run ‘elixir’ comma...
New
SoCreat
i’m a new one to elixir which editor can i use vs code? or atom? Thanks! :smiley:
New
fayddelight
I tried installing elixir 1.11.2 erlang 23.3.4 via asdf in my zsh shell. Enabled the versions locally and globally. When I list them ...
New

Other popular topics Top

grych
Hi folks, Few months ago I have announced the proof-of-concept of the library to manipulate the browsers DOM objects directly from Elixi...
639 54092 488
New
New
chrismccord
Phoenix 1.4.0 released Phoenix 1.4 is out! This release ships with exciting new features, most notably with HTTP2 support, improved deve...
688 31525 112
New
AstonJ
Seen any cool LiveView demos, sample apps or examples? Please post them here! :003:
New
bsollish-terakeet
Credo is smart enough to check for (something like) this: assert length(the_list) == 0 with this response: Checking if an enum is empt...
New
senggen
Erlang/OTP 25 [erts-13.2.2] [source] [64-bit] [smp:8:8] [ds:8:8:10] [async-threads:1] 15:22:35.803 [error] gen_event {lager_file_backend...
New

We're in Beta

About us Mission Statement