Flask+WTForms+Flask-SQLAlchemy环境下密码重置功能失效排查求助
Hey there, let's figure out why your reset_token function isn't getting past the form.validate_on_submit() check. I spotted a couple of critical issues in your code that are almost certainly causing this problem:
1. Missing Form Wrapper & CSRF Token
Looking at your HTML template, all your form fields are floating without being wrapped in a <form> tag. On top of that, you're not including the CSRF token required by Flask-WTF—without this, form validation will silently fail, making form.validate_on_submit() return False every time.
Fix for the Template
Update your resetpass.html to add the form wrapper and CSRF token:
{% include "html/homeheader.html" %} <!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <link rel="stylesheet" href="../static/enterdata.css"> <link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/3.4.1/css/bootstrap.min.css"> <title>Reset Password</title> </head> <body> <div class="enterdata"> <div class="enterdata-logo"> <p>Reset Password</p> </div> <!-- Add form tag and CSRF token here --> <form method="POST"> {{ form.hidden_tag() }} <div class="form-group"> {{ form.password.label(id="left")}} {% if form.password.errors %} {{ form.password(class="form-control form-control-lg is-invalid") }} <div class="invalid-feedback"> {% for error in form.password.errors %} <span>{{ error }}</span> {% endfor %} </div> {% else %} {{ form.password(class="form-control form-control-lg") }} {% endif %} </div> <br> <div class="form-group"> {{ form.confirm_password.label(id="left")}} {% if form.confirm_password.errors %} <!-- Fixed missing form-control-lg class here --> {{ form.confirm_password(class="form-control form-control-lg is-invalid") }} <div class="invalid-feedback"> {% for error in form.confirm_password.errors %} <span>{{ error }}</span> {% endfor %} </div> {% else %} {{ form.confirm_password(class="form-control form-control-lg") }} {% endif %} </div> <br> <div class="form-group"> {{ form.submit(class="enterdata-button")}} </div> <br> </form> <!-- Close the form tag --> </div> </body> </html>
2. Debugging for Further Issues
If the problem persists after fixing the template, add some debug output to your reset_token function to see exactly why validation is failing:
@app.route('/resetpass/<token>', methods=['GET', 'POST']) def reset_token(token): check = check_user() form = ResetPass() if current_user.is_authenticated: if check == 1: return redirect(url_for('index')) user = Users.verify_token(token) if user is None: flash('Invalid token', 'warning') return redirect(url_for('reset_request')) # Debug: Print form errors to console when POST request is made if request.method == 'POST': print("Form errors:", form.errors) if form.validate_on_submit(): hashed_pass = bcrypt.generate_password_hash(form.password.data).decode('utf-8') user.password = hashed_pass db.session.commit() flash('Your password has been reset successfully!', 'success') return redirect(url_for('login')) return render_template('resetpass.html', form=form)
Check your console for output like password mismatch errors or missing fields—this will point you straight to any remaining issues.
The most likely fix here is adding the form wrapper and CSRF token to your template. Give that a try first, and the validation should start working as expected.
内容的提问来源于stack exchange,提问作者cookiecat

