]> git.mxchange.org Git - friendica.git/blobdiff - mod/lostpass.php
Vier: Fading effects for tags, borders for links
[friendica.git] / mod / lostpass.php
index 30bdc059c3f8925aa8c5c6b607cd4652daa5038d..1751c2a7eacd555c1e4be88c3aaf1d8aa0d1870f 100644 (file)
@@ -1,32 +1,38 @@
 <?php
 
+require_once('include/email.php');
 
 function lostpass_post(&$a) {
 
-       $email = notags(trim($_POST['login-name']));
-       if(! $email)
-               goaway($a->get_baseurl());
+       $loginame = notags(trim($_POST['login-name']));
+       if(! $loginame)
+               goaway(z_root());
 
-       $r = q("SELECT * FROM `user` WHERE ( `email` = '%s' OR `nickname` = '%s' ) LIMIT 1",
-               dbesc($email),
-               dbesc($email)
+       $r = q("SELECT * FROM `user` WHERE ( `email` = '%s' OR `nickname` = '%s' ) AND `verified` = 1 AND `blocked` = 0 LIMIT 1",
+               dbesc($loginame),
+               dbesc($loginame)
        );
-       if(! count($r))
-               goaway($a->get_baseurl());
+
+       if(! count($r)) {
+               notice( t('No valid account found.') . EOL);
+               goaway(z_root());
+       }
+
        $uid = $r[0]['uid'];
        $username = $r[0]['username'];
+       $email = $r[0]['email'];
 
        $new_password = autoname(12) . mt_rand(100,9999);
        $new_password_encoded = hash('whirlpool',$new_password);
 
-       $r = q("UPDATE `user` SET `pwdreset` = '%s' WHERE `uid` = %d LIMIT 1",
+       $r = q("UPDATE `user` SET `pwdreset` = '%s' WHERE `uid` = %d",
                dbesc($new_password_encoded),
                intval($uid)
        );
        if($r)
-               notice("Password reset request issued. Check your email.");
+               info( t('Password reset request issued. Check your email.') . EOL);
 
-       $email_tpl = load_view_file("view/lostpass_eml.tpl");
+       $email_tpl = get_intltext_template("lostpass_eml.tpl");
        $email_tpl = replace_macros($email_tpl, array(
                        '$sitename' => $a->config['sitename'],
                        '$siteurl' =>  $a->get_baseurl(),
@@ -35,10 +41,14 @@ function lostpass_post(&$a) {
                        '$reset_link' => $a->get_baseurl() . '/lostpass?verify=' . $new_password
        ));
 
-       $res = mail($email, t('Password reset requested at ') . $a->config['sitename'],
-                       $email_tpl, 'From: ' . t('Administrator') . '@' . $_SERVER[SERVER_NAME]);
+       $res = mail($email, email_header_encode(sprintf( t('Password reset requested at %s'),$a->config['sitename']),'UTF-8'),
+                       $email_tpl,
+                       'From: ' . 'Administrator' . '@' . $_SERVER['SERVER_NAME'] . "\n"
+                       . 'Content-type: text/plain; charset=UTF-8' . "\n"
+                       . 'Content-transfer-encoding: 8bit' );
+
 
-       goaway($a->get_baseurl());
+       goaway(z_root());
 }
 
 
@@ -53,8 +63,8 @@ function lostpass_content(&$a) {
                        dbesc($hash)
                );
                if(! count($r)) {
-                       notice("Request could not be verified. (You may have previously submitted it.) Password reset failed." . EOL);
-                       goaway($a->get_baseurl());
+                       notice( t("Request could not be verified. \x28You may have previously submitted it.\x29 Password reset failed.") . EOL);
+                       goaway(z_root());
                        return;
                }
                $uid = $r[0]['uid'];
@@ -64,21 +74,28 @@ function lostpass_content(&$a) {
                $new_password = autoname(6) . mt_rand(100,9999);
                $new_password_encoded = hash('whirlpool',$new_password);
 
-               $r = q("UPDATE `user` SET `password` = '%s', `pwdreset` = ''  WHERE `uid` = %d LIMIT 1",
+               $r = q("UPDATE `user` SET `password` = '%s', `pwdreset` = ''  WHERE `uid` = %d",
                        dbesc($new_password_encoded),
                        intval($uid)
                );
                if($r) {
-                       $tpl = load_view_file('view/pwdreset.tpl');
+                       $tpl = get_markup_template('pwdreset.tpl');
                        $o .= replace_macros($tpl,array(
+                               '$lbl1' => t('Password Reset'),
+                               '$lbl2' => t('Your password has been reset as requested.'),
+                               '$lbl3' => t('Your new password is'),
+                               '$lbl4' => t('Save or copy your new password - and then'),
+                               '$lbl5' => '<a href="' . $a->get_baseurl() . '">' . t('click here to login') . '</a>.',
+                               '$lbl6' => t('Your password may be changed from the <em>Settings</em> page after successful login.'),
                                '$newpass' => $new_password,
                                '$baseurl' => $a->get_baseurl()
+
                        ));
-                               notice("Your password has been reset." . EOL);
+                               info("Your password has been reset." . EOL);
 
 
 
-                       $email_tpl = load_view_file("view/passchanged_eml.tpl");
+                       $email_tpl = get_intltext_template("passchanged_eml.tpl");
                        $email_tpl = replace_macros($email_tpl, array(
                        '$sitename' => $a->config['sitename'],
                        '$siteurl' =>  $a->get_baseurl(),
@@ -87,18 +104,28 @@ function lostpass_content(&$a) {
                        '$new_password' => $new_password,
                        '$uid' => $newuid ));
 
-                       $res = mail($email,"Your password has changed at {$a->config['sitename']}",$email_tpl,"From: Administrator@{$_SERVER[SERVER_NAME]}");
+                       $subject = sprintf( t('Your password has been changed at %s'), $a->config['sitename']);
+
+                       $res = mail($email, email_header_encode( $subject, 'UTF-8'), $email_tpl,
+                               'From: ' . 'Administrator' . '@' . $_SERVER['SERVER_NAME'] . "\n"
+                               . 'Content-type: text/plain; charset=UTF-8' . "\n"
+                               . 'Content-transfer-encoding: 8bit' );
 
                        return $o;
                }
        
        }
        else {
-               $tpl = load_view_file('view/lostpass.tpl');
+               $tpl = get_markup_template('lostpass.tpl');
 
-               $o .= $tpl;
+               $o .= replace_macros($tpl,array(
+                       '$title' => t('Forgot your Password?'),
+                       '$desc' => t('Enter your email address and submit to have your password reset. Then check your email for further instructions.'),
+                       '$name' => t('Nickname or Email: '),
+                       '$submit' => t('Reset') 
+               ));
 
                return $o;
        }
 
-}
\ No newline at end of file
+}