From 6612e6edf0de6c0d84160be0f67d2b2ecc9e9749 Mon Sep 17 00:00:00 2001 From: Damodar Lohani Date: Sun, 18 Dec 2022 06:28:19 +0000 Subject: [PATCH] fix: password verify --- app/controllers/api/users.php | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/app/controllers/api/users.php b/app/controllers/api/users.php index 72e4b594f8..65d31d8d3b 100644 --- a/app/controllers/api/users.php +++ b/app/controllers/api/users.php @@ -809,11 +809,14 @@ App::patch('/v1/users/:userId/password') $history = []; if($historyLimit > 0) { $history = $user->getAttribute('passwordHistory', []); - - if(in_array($newPassword, $history)) { - throw new Exception(Exception::USER_PASSWORD_RECENTLY_USED, 'The password was recently used', 409); + + foreach($history as $hash) { + if(Auth::passwordVerify($password, $hash, $user->getAttribute('hash'), $user->getAttribute('hashOptions'))) + { + throw new Exception(Exception::USER_PASSWORD_RECENTLY_USED, 'The password was recently used', 409); + } } - + $history[] = $newPassword; while(count($history) > $historyLimit) { array_pop($history);