RenewPasswordController.php 5.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180
  1. <?php
  2. /**
  3. * @copyright Copyright (c) 2017 Roger Szabo <roger.szabo@web.de>
  4. *
  5. * @author Christoph Wurst <christoph@winzerhof-wurst.at>
  6. * @author Roger Szabo <roger.szabo@web.de>
  7. *
  8. * @license GNU AGPL version 3 or any later version
  9. *
  10. * This program is free software: you can redistribute it and/or modify
  11. * it under the terms of the GNU Affero General Public License as
  12. * published by the Free Software Foundation, either version 3 of the
  13. * License, or (at your option) any later version.
  14. *
  15. * This program is distributed in the hope that it will be useful,
  16. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  17. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  18. * GNU Affero General Public License for more details.
  19. *
  20. * You should have received a copy of the GNU Affero General Public License
  21. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  22. *
  23. */
  24. namespace OCA\User_LDAP\Controller;
  25. use OCP\AppFramework\Controller;
  26. use OCP\AppFramework\Http\Attribute\OpenAPI;
  27. use OCP\AppFramework\Http\RedirectResponse;
  28. use OCP\AppFramework\Http\TemplateResponse;
  29. use OCP\HintException;
  30. use OCP\IConfig;
  31. use OCP\IL10N;
  32. use OCP\IRequest;
  33. use OCP\ISession;
  34. use OCP\IURLGenerator;
  35. use OCP\IUser;
  36. use OCP\IUserManager;
  37. #[OpenAPI(scope: OpenAPI::SCOPE_IGNORE)]
  38. class RenewPasswordController extends Controller {
  39. /** @var IUserManager */
  40. private $userManager;
  41. /** @var IConfig */
  42. private $config;
  43. /** @var IL10N */
  44. protected $l10n;
  45. /** @var ISession */
  46. private $session;
  47. /** @var IURLGenerator */
  48. private $urlGenerator;
  49. /**
  50. * @param string $appName
  51. * @param IRequest $request
  52. * @param IUserManager $userManager
  53. * @param IConfig $config
  54. * @param IURLGenerator $urlGenerator
  55. */
  56. public function __construct($appName, IRequest $request, IUserManager $userManager,
  57. IConfig $config, IL10N $l10n, ISession $session, IURLGenerator $urlGenerator) {
  58. parent::__construct($appName, $request);
  59. $this->userManager = $userManager;
  60. $this->config = $config;
  61. $this->l10n = $l10n;
  62. $this->session = $session;
  63. $this->urlGenerator = $urlGenerator;
  64. }
  65. /**
  66. * @PublicPage
  67. * @NoCSRFRequired
  68. *
  69. * @return RedirectResponse
  70. */
  71. public function cancel() {
  72. return new RedirectResponse($this->urlGenerator->linkToRouteAbsolute('core.login.showLoginForm'));
  73. }
  74. /**
  75. * @PublicPage
  76. * @NoCSRFRequired
  77. * @UseSession
  78. *
  79. * @param string $user
  80. *
  81. * @return TemplateResponse|RedirectResponse
  82. */
  83. public function showRenewPasswordForm($user) {
  84. if ($this->config->getUserValue($user, 'user_ldap', 'needsPasswordReset') !== 'true') {
  85. return new RedirectResponse($this->urlGenerator->linkToRouteAbsolute('core.login.showLoginForm'));
  86. }
  87. $parameters = [];
  88. $renewPasswordMessages = $this->session->get('renewPasswordMessages');
  89. $errors = [];
  90. $messages = [];
  91. if (is_array($renewPasswordMessages)) {
  92. [$errors, $messages] = $renewPasswordMessages;
  93. }
  94. $this->session->remove('renewPasswordMessages');
  95. foreach ($errors as $value) {
  96. $parameters[$value] = true;
  97. }
  98. $parameters['messages'] = $messages;
  99. $parameters['user'] = $user;
  100. $parameters['canResetPassword'] = true;
  101. $parameters['resetPasswordLink'] = $this->config->getSystemValue('lost_password_link', '');
  102. if (!$parameters['resetPasswordLink']) {
  103. $userObj = $this->userManager->get($user);
  104. if ($userObj instanceof IUser) {
  105. $parameters['canResetPassword'] = $userObj->canChangePassword();
  106. }
  107. }
  108. $parameters['cancelLink'] = $this->urlGenerator->linkToRouteAbsolute('core.login.showLoginForm');
  109. return new TemplateResponse(
  110. $this->appName, 'renewpassword', $parameters, 'guest'
  111. );
  112. }
  113. /**
  114. * @PublicPage
  115. * @UseSession
  116. *
  117. * @param string $user
  118. * @param string $oldPassword
  119. * @param string $newPassword
  120. *
  121. * @return RedirectResponse
  122. */
  123. public function tryRenewPassword($user, $oldPassword, $newPassword) {
  124. if ($this->config->getUserValue($user, 'user_ldap', 'needsPasswordReset') !== 'true') {
  125. return new RedirectResponse($this->urlGenerator->linkToRouteAbsolute('core.login.showLoginForm'));
  126. }
  127. $args = !is_null($user) ? ['user' => $user] : [];
  128. $loginResult = $this->userManager->checkPassword($user, $oldPassword);
  129. if ($loginResult === false) {
  130. $this->session->set('renewPasswordMessages', [
  131. ['invalidpassword'], []
  132. ]);
  133. return new RedirectResponse($this->urlGenerator->linkToRoute('user_ldap.renewPassword.showRenewPasswordForm', $args));
  134. }
  135. try {
  136. if (!is_null($newPassword) && \OC_User::setPassword($user, $newPassword)) {
  137. $this->session->set('loginMessages', [
  138. [], [$this->l10n->t("Please login with the new password")]
  139. ]);
  140. $this->config->setUserValue($user, 'user_ldap', 'needsPasswordReset', 'false');
  141. return new RedirectResponse($this->urlGenerator->linkToRoute('core.login.showLoginForm', $args));
  142. } else {
  143. $this->session->set('renewPasswordMessages', [
  144. ['internalexception'], []
  145. ]);
  146. }
  147. } catch (HintException $e) {
  148. $this->session->set('renewPasswordMessages', [
  149. [], [$e->getHint()]
  150. ]);
  151. }
  152. return new RedirectResponse($this->urlGenerator->linkToRoute('user_ldap.renewPassword.showRenewPasswordForm', $args));
  153. }
  154. /**
  155. * @PublicPage
  156. * @NoCSRFRequired
  157. * @UseSession
  158. *
  159. * @return RedirectResponse
  160. */
  161. public function showLoginFormInvalidPassword($user) {
  162. $args = !is_null($user) ? ['user' => $user] : [];
  163. $this->session->set('loginMessages', [
  164. ['invalidpassword'], []
  165. ]);
  166. return new RedirectResponse($this->urlGenerator->linkToRoute('core.login.showLoginForm', $args));
  167. }
  168. }