Discussion on: How to Handle Password Reset in ExpressJS

mtrcn profile image
Mete Ercan Pakdil

Hi Kelvin, great article, thanks. I just spotted that you forgot to check whether reset token is valid or not in '/reset-confirm/:token' Post method.

const passwordReset = await PasswordReset.findOne({ token })
passwordReset is not being checked after this line.

kelvinvmwinuka profile image
Kelvin Mwinuka Author

Hi Mete,

Good eye. If we don't check it here, the user update will throw an error. To avoid this we can add a guard clause to check the password reset object:

if (!passwordReset) {
    return res.status(404).send()

// Continue with the reset
