diff --git a/server/src/server/router/api/v1/auth/router.ts b/server/src/server/router/api/v1/auth/router.ts index c2cbc0b54..4eb835809 100644 --- a/server/src/server/router/api/v1/auth/router.ts +++ b/server/src/server/router/api/v1/auth/router.ts @@ -199,6 +199,9 @@ router.post( captcha: string; }; + // force lowercase for emails to avoid case-confusion in lookups... + body.email = body.email.toLowerCase(); + if (body.inviteCode === undefined && ServerConfig.INVITE_CODE_CONFIG) { return res.status(400).json({ success: false, @@ -469,6 +472,8 @@ router.post( email: string; }; + body.email = body.email.toLowerCase(); + logger.debug(`received password reset request for ${body.email}.`); // For timing attack and infosec reasons, we can't do anything but **immediately** return here.