Enabled :error_handling, :unknown, :unmatched_returns, :extra_return, :missing_return in an earlier commit and landed a 129-warning baseline. Four parallel agents each fixed a directory slice: - Core contexts (29): Radio, Release, Weather, Beacons, Cache, Backtest.Features, Terrain.Srtm, Ionosphere.GiroClient, Propagation.RunTiming, Accounts.Scope, RepoListener. Fixes were (a) prefix side-effect calls (Task.start, Phoenix.PubSub, Logger, :ets.new) with _ = ; (b) tighten/widen specs that didn't match actual returns; (c) add missing @type t declarations; (d) drop dead parse_int(nil) clause. - Propagation + weather subdirs (15): FreshnessMonitor, NotifyListener, ScoreCache, ScoreCacheReconciler, Weather.FrontalAnalysis, Weather.Grib2.Extractor, Weather.Grib2.Wgrib2, GridCache, HrrrPointEnqueuer, NexradCache. Same patterns — mostly _ = on PubSub / :ets / Repo.insert_all; widened two specs (float -> number) where integer returns were reachable. - Workers (35): BackfillEnqueue, CanadianSoundingFetch, ContactImport, ContactWeatherEnqueue, GefsFetch, IemreFetch, NarrFetch, SolarIndex, TerrainProfile, WeatherFetch. Prefixed Repo.update_all / Radio.set_enrichment_status! / Weather.upsert_* side-effect calls. Fixed one :pattern_match in CanadianSoundingFetch.most_recent_sounding_time/1 where a tautological cond guard generated unreachable code. - Web + Mix tasks + lib_ml (46 of 50): controllers, LiveViews, UserAuth, and 11 mix tasks. Same prefix strategy. 4 remaining warnings originate in LiveTable.LiveResource dep macro expansion and can't be fixed without forking the dep — added .dialyzer_ignore.exs to suppress just those specific file:line pairs. Also wired ignore_warnings in mix.exs dialyzer config. mix dialyzer --format short | grep ^lib/ | wc -l -> 0 mix test: 2163 tests, 3 pre-existing flakes, 0 regressions.
64 lines
1.9 KiB
Elixir
64 lines
1.9 KiB
Elixir
defmodule MicrowavepropWeb.UserResetPasswordController do
|
|
use MicrowavepropWeb, :controller
|
|
|
|
alias Microwaveprop.Accounts
|
|
|
|
plug :get_user_by_reset_password_token when action in [:edit, :update]
|
|
|
|
def new(conn, _params) do
|
|
render(conn, :new)
|
|
end
|
|
|
|
def create(conn, %{"user" => %{"email" => email}}) do
|
|
_ =
|
|
if user = Accounts.get_user_by_email(email) do
|
|
{:ok, _email} =
|
|
Accounts.deliver_user_reset_password_instructions(
|
|
user,
|
|
&url(~p"/users/reset-password/#{&1}")
|
|
)
|
|
end
|
|
|
|
# Always respond the same way whether or not the email exists — this is
|
|
# a deliberate anti-enumeration measure. If we redirected differently on
|
|
# a miss, an attacker could iterate emails to discover registered accounts.
|
|
conn
|
|
|> put_flash(
|
|
:info,
|
|
"If your email is in our system, you will receive instructions to reset your password shortly."
|
|
)
|
|
|> redirect(to: ~p"/users/log-in")
|
|
end
|
|
|
|
def edit(conn, _params) do
|
|
render(conn, :edit,
|
|
changeset: Accounts.change_user_password(conn.assigns.user),
|
|
token: conn.assigns.token
|
|
)
|
|
end
|
|
|
|
def update(conn, %{"user" => user_params}) do
|
|
case Accounts.reset_user_password(conn.assigns.user, user_params) do
|
|
{:ok, _} ->
|
|
conn
|
|
|> put_flash(:info, "Password reset successfully.")
|
|
|> redirect(to: ~p"/users/log-in")
|
|
|
|
{:error, changeset} ->
|
|
render(conn, :edit, changeset: changeset, token: conn.assigns.token)
|
|
end
|
|
end
|
|
|
|
defp get_user_by_reset_password_token(conn, _opts) do
|
|
%{"token" => token} = conn.params
|
|
|
|
if user = Accounts.get_user_by_reset_password_token(token) do
|
|
conn |> assign(:user, user) |> assign(:token, token)
|
|
else
|
|
conn
|
|
|> put_flash(:error, "Reset link is invalid or it has expired.")
|
|
|> redirect(to: ~p"/users/reset-password")
|
|
|> halt()
|
|
end
|
|
end
|
|
end
|