fix(19): CR-03 return 403 for wrong current password so change-password does not log user out

This commit is contained in:
Lucas Berger
2026-06-17 20:17:32 -04:00
parent 93c47b38aa
commit 6ef8e03f8c
3 changed files with 20 additions and 6 deletions
+4 -2
View File
@@ -330,7 +330,7 @@ describe('POST /api/me/password — self-change password (AUTH-LOCAL-09)', () =>
expect(verifyPassword(updatedHash!, oldPassword)).toBe(false);
});
it('Test 2: wrong currentPassword → 401 and update is NOT called', async () => {
it('Test 2: wrong currentPassword → 403 and update is NOT called', async () => {
const { db } = await import('../../src/db/client.js');
const realPassword = 'real-password-correct-789';
@@ -374,7 +374,9 @@ describe('POST /api/me/password — self-change password (AUTH-LOCAL-09)', () =>
body: JSON.stringify({ currentPassword: 'WRONG-password', newPassword: 'new-pass-12345678' }),
});
expect(res.status).toBe(401);
// CR-03: wrong current password returns 403 (in-app authz failure), NOT 401.
// A 401 would be interpreted by the PWA as session expiry and log the user out.
expect(res.status).toBe(403);
const body = (await res.json()) as { error: string };
expect(body.error).toBe('Current password incorrect');
// Update must NOT have been called