From 9d086c78e434ceb4ff3ca84c12bd7c64fe306e9a Mon Sep 17 00:00:00 2001 From: Eldad Fux Date: Mon, 10 Feb 2020 07:15:45 +0200 Subject: [PATCH] Updated docs --- .env | 4 ---- docs/references/account/create-recovery.md | 2 +- docs/references/account/update-recovery.md | 2 +- 3 files changed, 2 insertions(+), 6 deletions(-) delete mode 100644 .env diff --git a/.env b/.env deleted file mode 100644 index 5bb845ae57..0000000000 --- a/.env +++ /dev/null @@ -1,4 +0,0 @@ -TESTS_FACEBOOK_APP_ID=dbase -TESTS_FACEBOOK_APP_KEY=SDASDHAJSHDAJSHDJHSD -DB_PW=dbpassword -DB_ROOT_PW=dbrootpw \ No newline at end of file diff --git a/docs/references/account/create-recovery.md b/docs/references/account/create-recovery.md index 45ff5f83f2..5953e13ebe 100644 --- a/docs/references/account/create-recovery.md +++ b/docs/references/account/create-recovery.md @@ -1 +1 @@ -Sends the user an email with a temporary secret key for password reset. When the user clicks the confirmation link he is redirected back to your app password reset URL with the secret key and email address values attached to the URL query string. Use the query string params to submit a request to the /auth/password/reset endpoint to complete the process. \ No newline at end of file +Sends the user an email with a temporary secret key for password reset. When the user clicks the confirmation link he is redirected back to your app password reset URL with the secret key and email address values attached to the URL query string. Use the query string params to submit a request to the [PUT /account/recovery](/docs/account#updateRecovery) endpoint to complete the process. \ No newline at end of file diff --git a/docs/references/account/update-recovery.md b/docs/references/account/update-recovery.md index 4a58ef92f8..6bd5f5abec 100644 --- a/docs/references/account/update-recovery.md +++ b/docs/references/account/update-recovery.md @@ -1,3 +1,3 @@ -Use this endpoint to complete the user account password reset. Both the **userId** and **secret** arguments will be passed as query parameters to the redirect URL you have provided when sending your request to the /auth/recovery endpoint. +Use this endpoint to complete the user account password reset. Both the **userId** and **secret** arguments will be passed as query parameters to the redirect URL you have provided when sending your request to the [POST /account/recovery](/docs/account#createRecovery) endpoint. Please note that in order to avoid a [Redirect Attack](https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.md) the only valid redirect URLs are the ones from domains you have set when adding your platforms in the console interface. \ No newline at end of file