From 14e7a5533d9424b1610b05ff332d8b28da2d5716 Mon Sep 17 00:00:00 2001 From: amandazhu Date: Mon, 14 Sep 2026 10:46:18 +1000 Subject: [PATCH] docs: clarify finish_migrate_password is called on confirmed reset The old docstring described the endpoint as firing when a user starts a password change - which matched the buggy behaviour where Auth0's password-reset-post-challenge action called it as soon as the reset link was opened, before any password was actually changed. That trigger is being removed (see aai-infrastructure), in favour of calling this endpoint from the post-login action once last_password_reset confirms the reset really happened. Co-Authored-By: Claude Sonnet 5 --- routers/user.py | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/routers/user.py b/routers/user.py index 04851fc3..fd09f8dd 100644 --- a/routers/user.py +++ b/routers/user.py @@ -1047,8 +1047,12 @@ def finish_migrate_password(state: str, auth0_client: Annotated[Auth0Client, Depends(get_auth0_client)], db_session: Annotated[Session, Depends(get_db_session)],): """ - Complete the migration process. This should be called by Auth0 when a user - starts the actual password change, and clears their user_needs_migration flag. + Complete the migration process: clears the user_needs_migration flag and + sends the welcome email. Called by the Migrate User post-login Auth0 + action, once a login shows the user's password has actually been reset + (event.user.last_password_reset is set) - not by the password-reset-post-challenge + flow, which fires as soon as the reset link is opened (e.g. by an email + security scanner), before any password has actually been changed. """ # Will raise if token is invalid payload = verify_action_token(session_token, settings=settings)