Skip to content

fix: keep the wordpress hash when it already matches the new password - #23

Merged
vitormattos merged 2 commits into
mainfrom
fix/keep-wordpress-hash-of-unchanged-password
Oct 5, 2026
Merged

vitormattos merged 2 commits into
mainfrom
fix/keep-wordpress-hash-of-unchanged-password

Conversation

@YvesCesar

@YvesCesar YvesCesar commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Closes #22

BeforePasswordUpdatedListener now reads the current WordPress hash with the get_wordpress_user query and only writes a new one when that hash does not match the new password. Since that query also matches by email, the hash is taken from the row whose uid is the user, the same row the set_wordpress_password query updates. A password change that started in WordPress reaches Nextcloud with a password WordPress already stores, so the hash, and the auth cookie tied to it, stay untouched. A password changed in Nextcloud is still written to WordPress.

Tests (tests/Unit/Listener/BeforePasswordUpdatedListenerTest.php, against a SQLite database):

  • a new password is written to WordPress;
  • a hash that already matches the new password is kept;
  • the new password is written when another user has the login as email;
  • a user missing from WordPress leaves the other users untouched.

tests/bootstrap.php gains stubs for IUser, Event, IEventListener and BeforePasswordUpdatedEvent, like the existing IConfig one.

Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
@YvesCesar
YvesCesar marked this pull request as draft October 1, 2026 22:10
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
@YvesCesar
YvesCesar marked this pull request as ready for review October 1, 2026 22:17
@YvesCesar
YvesCesar requested a review from vitormattos October 1, 2026 22:17
@vitormattos
vitormattos merged commit 83df7d6 into main Oct 5, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Password change from WordPress logs the customer out

2 participants