X-Git-Url: https://git.mxchange.org/?a=blobdiff_plain;f=mod%2Flostpass.php;h=6505db549723fc540fb89b0257b8400c71eb576e;hb=1fdd0f915250517e254adb5165b394f03721cd87;hp=9cde1c9ff4a637edf2398b99efe62c50c7bffd02;hpb=dbe49a0c1ad0467c2e12e363aac5635a1f11a3ea;p=friendica.git
diff --git a/mod/lostpass.php b/mod/lostpass.php
index 9cde1c9ff4..6505db5497 100644
--- a/mod/lostpass.php
+++ b/mod/lostpass.php
@@ -1,49 +1,61 @@
.
+ *
*/
use Friendica\App;
-use Friendica\Core\Config;
-use Friendica\Core\L10n;
-use Friendica\Core\System;
+use Friendica\Core\Renderer;
use Friendica\Database\DBA;
+use Friendica\DI;
use Friendica\Model\User;
use Friendica\Util\DateTimeFormat;
-
-require_once 'boot.php';
-require_once 'include/enotify.php';
-require_once 'include/text.php';
+use Friendica\Util\Strings;
function lostpass_post(App $a)
{
- $loginame = notags(trim($_POST['login-name']));
+ $loginame = trim($_POST['login-name']);
if (!$loginame) {
- $a->internalRedirect();
+ DI::baseUrl()->redirect();
}
- $condition = ['(`email` = ? OR `nickname` = ?) AND `verified` = 1 AND `blocked` = 0', $loginame, $loginame];
- $user = DBA::selectFirst('user', ['uid', 'username', 'email', 'language'], $condition);
+ $condition = ['(`email` = ? OR `nickname` = ?) AND `verified` = 1 AND `blocked` = 0 AND `account_removed` = 0 AND `account_expired` = 0', $loginame, $loginame];
+ $user = DBA::selectFirst('user', ['uid', 'username', 'nickname', 'email', 'language'], $condition);
if (!DBA::isResult($user)) {
- notice(L10n::t('No valid account found.') . EOL);
- $a->internalRedirect();
+ DI::sysmsg()->addNotice(DI::l10n()->t('No valid account found.'));
+ DI::baseUrl()->redirect();
}
- $pwdreset_token = autoname(12) . mt_rand(1000, 9999);
+ $pwdreset_token = Strings::getRandomHex(32);
$fields = [
- 'pwdreset' => $pwdreset_token,
+ 'pwdreset' => hash('sha256', $pwdreset_token),
'pwdreset_time' => DateTimeFormat::utcNow()
];
$result = DBA::update('user', $fields, ['uid' => $user['uid']]);
if ($result) {
- info(L10n::t('Password reset request issued. Check your email.') . EOL);
+ DI::sysmsg()->addInfo(DI::l10n()->t('Password reset request issued. Check your email.'));
}
- $sitename = Config::get('config', 'sitename');
- $resetlink = System::baseUrl() . '/lostpass/' . $pwdreset_token;
+ $sitename = DI::config()->get('config', 'sitename');
+ $resetlink = DI::baseUrl() . '/lostpass/' . $pwdreset_token;
- $preamble = deindent(L10n::t('
+ $preamble = Strings::deindent(DI::l10n()->t('
Dear %1$s,
A request was recently received at "%2$s" to reset your account
password. In order to confirm this request, please select the verification link
@@ -54,7 +66,7 @@ function lostpass_post(App $a)
Your password will not be changed unless we can verify that you
issued this request.', $user['username'], $sitename));
- $body = deindent(L10n::t('
+ $body = Strings::deindent(DI::l10n()->t('
Follow this link soon to verify your identity:
%1$s
@@ -65,31 +77,27 @@ function lostpass_post(App $a)
The login details are as follows:
Site Location: %2$s
- Login Name: %3$s', $resetlink, System::baseUrl(), $user['email']));
-
- notification([
- 'type' => SYSTEM_EMAIL,
- 'language' => $user['language'],
- 'to_name' => $user['username'],
- 'to_email' => $user['email'],
- 'uid' => $user['uid'],
- 'subject' => L10n::t('Password reset requested at %s', $sitename),
- 'preamble' => $preamble,
- 'body' => $body
- ]);
+ Login Name: %3$s', $resetlink, DI::baseUrl(), $user['nickname']));
+
+ $email = DI::emailer()
+ ->newSystemMail()
+ ->withMessage(DI::l10n()->t('Password reset requested at %s', $sitename), $preamble, $body)
+ ->forUser($user)
+ ->withRecipient($user['email'])
+ ->build();
- $a->internalRedirect();
+ DI::emailer()->send($email);
+ DI::baseUrl()->redirect();
}
function lostpass_content(App $a)
{
- $o = '';
- if ($a->argc > 1) {
- $pwdreset_token = $a->argv[1];
+ if (DI::args()->getArgc() > 1) {
+ $pwdreset_token = DI::args()->getArgv()[1];
- $user = DBA::selectFirst('user', ['uid', 'username', 'email', 'pwdreset_time', 'language'], ['pwdreset' => $pwdreset_token]);
+ $user = DBA::selectFirst('user', ['uid', 'username', 'nickname', 'email', 'pwdreset_time', 'language'], ['pwdreset' => hash('sha256', $pwdreset_token)]);
if (!DBA::isResult($user)) {
- notice(L10n::t("Request could not be verified. \x28You may have previously submitted it.\x29 Password reset failed."));
+ DI::sysmsg()->addNotice(DI::l10n()->t("Request could not be verified. \x28You may have previously submitted it.\x29 Password reset failed."));
return lostpass_form();
}
@@ -102,7 +110,7 @@ function lostpass_content(App $a)
];
DBA::update('user', $fields, ['uid' => $user['uid']]);
- notice(L10n::t('Request has expired, please make a new one.'));
+ DI::sysmsg()->addNotice(DI::l10n()->t('Request has expired, please make a new one.'));
return lostpass_form();
}
@@ -115,12 +123,12 @@ function lostpass_content(App $a)
function lostpass_form()
{
- $tpl = get_markup_template('lostpass.tpl');
- $o = replace_macros($tpl, [
- '$title' => L10n::t('Forgot your Password?'),
- '$desc' => L10n::t('Enter your email address and submit to have your password reset. Then check your email for further instructions.'),
- '$name' => L10n::t('Nickname or Email: '),
- '$submit' => L10n::t('Reset')
+ $tpl = Renderer::getMarkupTemplate('lostpass.tpl');
+ $o = Renderer::replaceMacros($tpl, [
+ '$title' => DI::l10n()->t('Forgot your Password?'),
+ '$desc' => DI::l10n()->t('Enter your email address and submit to have your password reset. Then check your email for further instructions.'),
+ '$name' => DI::l10n()->t('Nickname or Email: '),
+ '$submit' => DI::l10n()->t('Reset')
]);
return $o;
@@ -129,33 +137,31 @@ function lostpass_form()
function lostpass_generate_password($user)
{
$o = '';
- $a = get_app();
$new_password = User::generateNewPassword();
$result = User::updatePassword($user['uid'], $new_password);
if (DBA::isResult($result)) {
- $tpl = get_markup_template('pwdreset.tpl');
- $o .= replace_macros($tpl, [
- '$lbl1' => L10n::t('Password Reset'),
- '$lbl2' => L10n::t('Your password has been reset as requested.'),
- '$lbl3' => L10n::t('Your new password is'),
- '$lbl4' => L10n::t('Save or copy your new password - and then'),
- '$lbl5' => '' . L10n::t('click here to login') . '.',
- '$lbl6' => L10n::t('Your password may be changed from the Settings page after successful login.'),
+ $tpl = Renderer::getMarkupTemplate('pwdreset.tpl');
+ $o .= Renderer::replaceMacros($tpl, [
+ '$lbl1' => DI::l10n()->t('Password Reset'),
+ '$lbl2' => DI::l10n()->t('Your password has been reset as requested.'),
+ '$lbl3' => DI::l10n()->t('Your new password is'),
+ '$lbl4' => DI::l10n()->t('Save or copy your new password - and then'),
+ '$lbl5' => '' . DI::l10n()->t('click here to login') . '.',
+ '$lbl6' => DI::l10n()->t('Your password may be changed from the Settings page after successful login.'),
'$newpass' => $new_password,
- '$baseurl' => System::baseUrl()
]);
- info("Your password has been reset." . EOL);
+ DI::sysmsg()->addInfo(DI::l10n()->t("Your password has been reset."));
- $sitename = Config::get('config', 'sitename');
- $preamble = deindent(L10n::t('
+ $sitename = DI::config()->get('config', 'sitename');
+ $preamble = Strings::deindent(DI::l10n()->t('
Dear %1$s,
Your password has been changed as requested. Please retain this
information for your records ' . "\x28" . 'or change your password immediately to
something that you will remember' . "\x29" . '.
', $user['username']));
- $body = deindent(L10n::t('
+ $body = Strings::deindent(DI::l10n()->t('
Your login details are as follows:
Site Location: %1$s
@@ -163,18 +169,15 @@ function lostpass_generate_password($user)
Password: %3$s
You may change that password from your account settings page after logging in.
- ', System::baseUrl(), $user['email'], $new_password));
-
- notification([
- 'type' => SYSTEM_EMAIL,
- 'language' => $user['language'],
- 'to_name' => $user['username'],
- 'to_email' => $user['email'],
- 'uid' => $user['uid'],
- 'subject' => L10n::t('Your password has been changed at %s', $sitename),
- 'preamble' => $preamble,
- 'body' => $body
- ]);
+ ', DI::baseUrl(), $user['nickname'], $new_password));
+
+ $email = DI::emailer()
+ ->newSystemMail()
+ ->withMessage(DI::l10n()->t('Your password has been changed at %s', $sitename), $preamble, $body)
+ ->forUser($user)
+ ->withRecipient($user['email'])
+ ->build();
+ DI::emailer()->send($email);
}
return $o;