You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

179 lines
5.3 KiB

  1. <?php
  2. /**
  3. * @copyright Copyright (c) 2017 Roger Szabo <roger.szabo@web.de>
  4. *
  5. * @author Roger Szabo <roger.szabo@web.de>
  6. *
  7. * @license GNU AGPL version 3 or any later version
  8. *
  9. * This program is free software: you can redistribute it and/or modify
  10. * it under the terms of the GNU Affero General Public License as
  11. * published by the Free Software Foundation, either version 3 of the
  12. * License, or (at your option) any later version.
  13. *
  14. * This program is distributed in the hope that it will be useful,
  15. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  16. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  17. * GNU Affero General Public License for more details.
  18. *
  19. * You should have received a copy of the GNU Affero General Public License
  20. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  21. *
  22. */
  23. namespace OCA\User_LDAP\Controller;
  24. use OC\HintException;
  25. use OCP\AppFramework\Controller;
  26. use OCP\AppFramework\Http\RedirectResponse;
  27. use OCP\AppFramework\Http\TemplateResponse;
  28. use OCP\IConfig;
  29. use OCP\IL10N;
  30. use OCP\IRequest;
  31. use OCP\ISession;
  32. use OCP\IURLGenerator;
  33. use OCP\IUser;
  34. use OCP\IUserManager;
  35. class RenewPasswordController extends Controller {
  36. /** @var IUserManager */
  37. private $userManager;
  38. /** @var IConfig */
  39. private $config;
  40. /** @var IL10N */
  41. protected $l10n;
  42. /** @var ISession */
  43. private $session;
  44. /** @var IURLGenerator */
  45. private $urlGenerator;
  46. /**
  47. * @param string $appName
  48. * @param IRequest $request
  49. * @param IUserManager $userManager
  50. * @param IConfig $config
  51. * @param IURLGenerator $urlGenerator
  52. */
  53. function __construct($appName, IRequest $request, IUserManager $userManager,
  54. IConfig $config, IL10N $l10n, ISession $session, IURLGenerator $urlGenerator) {
  55. parent::__construct($appName, $request);
  56. $this->userManager = $userManager;
  57. $this->config = $config;
  58. $this->l10n = $l10n;
  59. $this->session = $session;
  60. $this->urlGenerator = $urlGenerator;
  61. }
  62. /**
  63. * @PublicPage
  64. * @NoCSRFRequired
  65. *
  66. * @return RedirectResponse
  67. */
  68. public function cancel() {
  69. return new RedirectResponse($this->urlGenerator->linkToRouteAbsolute('core.login.showLoginForm'));
  70. }
  71. /**
  72. * @PublicPage
  73. * @NoCSRFRequired
  74. * @UseSession
  75. *
  76. * @param string $user
  77. *
  78. * @return TemplateResponse|RedirectResponse
  79. */
  80. public function showRenewPasswordForm($user) {
  81. if($this->config->getUserValue($user, 'user_ldap', 'needsPasswordReset') !== 'true') {
  82. return new RedirectResponse($this->urlGenerator->linkToRouteAbsolute('core.login.showLoginForm'));
  83. }
  84. $parameters = [];
  85. $renewPasswordMessages = $this->session->get('renewPasswordMessages');
  86. $errors = [];
  87. $messages = [];
  88. if (is_array($renewPasswordMessages)) {
  89. list($errors, $messages) = $renewPasswordMessages;
  90. }
  91. $this->session->remove('renewPasswordMessages');
  92. foreach ($errors as $value) {
  93. $parameters[$value] = true;
  94. }
  95. $parameters['messages'] = $messages;
  96. $parameters['user'] = $user;
  97. $parameters['canResetPassword'] = true;
  98. $parameters['resetPasswordLink'] = $this->config->getSystemValue('lost_password_link', '');
  99. if (!$parameters['resetPasswordLink']) {
  100. $userObj = $this->userManager->get($user);
  101. if ($userObj instanceof IUser) {
  102. $parameters['canResetPassword'] = $userObj->canChangePassword();
  103. }
  104. }
  105. $parameters['cancelLink'] = $this->urlGenerator->linkToRouteAbsolute('core.login.showLoginForm');
  106. return new TemplateResponse(
  107. $this->appName, 'renewpassword', $parameters, 'guest'
  108. );
  109. }
  110. /**
  111. * @PublicPage
  112. * @UseSession
  113. *
  114. * @param string $user
  115. * @param string $oldPassword
  116. * @param string $newPassword
  117. *
  118. * @return RedirectResponse
  119. */
  120. public function tryRenewPassword($user, $oldPassword, $newPassword) {
  121. if($this->config->getUserValue($user, 'user_ldap', 'needsPasswordReset') !== 'true') {
  122. return new RedirectResponse($this->urlGenerator->linkToRouteAbsolute('core.login.showLoginForm'));
  123. }
  124. $args = !is_null($user) ? ['user' => $user] : [];
  125. $loginResult = $this->userManager->checkPassword($user, $oldPassword);
  126. if ($loginResult === false) {
  127. $this->session->set('renewPasswordMessages', [
  128. ['invalidpassword'], []
  129. ]);
  130. return new RedirectResponse($this->urlGenerator->linkToRoute('user_ldap.renewPassword.showRenewPasswordForm', $args));
  131. }
  132. try {
  133. if (!is_null($newPassword) && \OC_User::setPassword($user, $newPassword)) {
  134. $this->session->set('loginMessages', [
  135. [], [$this->l10n->t("Please login with the new password")]
  136. ]);
  137. $this->config->setUserValue($user, 'user_ldap', 'needsPasswordReset', 'false');
  138. return new RedirectResponse($this->urlGenerator->linkToRoute('core.login.showLoginForm', $args));
  139. } else {
  140. $this->session->set('renewPasswordMessages', [
  141. ['internalexception'], []
  142. ]);
  143. }
  144. } catch (HintException $e) {
  145. $this->session->set('renewPasswordMessages', [
  146. [], [$e->getHint()]
  147. ]);
  148. }
  149. return new RedirectResponse($this->urlGenerator->linkToRoute('user_ldap.renewPassword.showRenewPasswordForm', $args));
  150. }
  151. /**
  152. * @PublicPage
  153. * @NoCSRFRequired
  154. * @UseSession
  155. *
  156. * @return RedirectResponse
  157. */
  158. public function showLoginFormInvalidPassword($user) {
  159. $args = !is_null($user) ? ['user' => $user] : [];
  160. $this->session->set('loginMessages', [
  161. ['invalidpassword'], []
  162. ]);
  163. return new RedirectResponse($this->urlGenerator->linkToRoute('core.login.showLoginForm', $args));
  164. }
  165. }