Version 4.7.23
This commit is contained in:
1 parent
7124a02564
commit
25ddeb65d6
1791 files changed
+76990
-44452
No files matched your search
@@ -10,6 +10,8 @@
|
||||
|
||||
namespace IPS\core\modules\front\system;
|
||||
|
||||
use IPS\Text\Encrypt;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
@@ -152,27 +154,29 @@ class _lostpass extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
else
|
||||
{
|
||||
\IPS\Db::i()->update( 'core_validating', array( 'email_sent' => time() ), array( 'vid=?', $vid ) );
|
||||
$plainSecurityKey = \IPS\Login::generateRandomString();
|
||||
\IPS\Db::i()->update( 'core_validating', [ 'email_sent' => time(), 'security_key' => Encrypt::fromPlaintext( $plainSecurityKey )->tag() ], [ 'vid=?', $vid ] );
|
||||
}
|
||||
}
|
||||
catch ( \UnderflowException $e )
|
||||
{
|
||||
$vid = md5( $member->members_pass_hash . \IPS\Login::generateRandomString() );
|
||||
|
||||
\IPS\Db::i()->insert( 'core_validating', array(
|
||||
'vid' => $vid,
|
||||
'member_id' => $member->member_id,
|
||||
'entry_date' => time(),
|
||||
'lost_pass' => 1,
|
||||
'ip_address' => $member->ip_address,
|
||||
'email_sent' => time(),
|
||||
) );
|
||||
$plainSecurityKey = \IPS\Login::generateRandomString();
|
||||
\IPS\Db::i()->insert( 'core_validating', [
|
||||
'vid' => $vid,
|
||||
'member_id' => $member->member_id,
|
||||
'entry_date' => time(),
|
||||
'lost_pass' => 1,
|
||||
'ip_address' => $member->ip_address,
|
||||
'email_sent' => time(),
|
||||
'security_key' => Encrypt::fromPlaintext( $plainSecurityKey )->tag()
|
||||
] );
|
||||
}
|
||||
|
||||
/* Send email */
|
||||
if ( $sendEmail )
|
||||
{
|
||||
\IPS\Email::buildFromTemplate( 'core', 'lost_password_init', array( $member, $vid ), \IPS\Email::TYPE_TRANSACTIONAL )->send( $member );
|
||||
\IPS\Email::buildFromTemplate( 'core', 'lost_password_init', array( $member, $vid, $plainSecurityKey ), \IPS\Email::TYPE_TRANSACTIONAL )->send( $member );
|
||||
$message = "lost_pass_confirm";
|
||||
}
|
||||
else
|
||||
@@ -205,6 +209,12 @@ class _lostpass extends \IPS\Dispatcher\Controller
|
||||
\IPS\Output::i()->error( 'no_validation_key', '2S151/1', 410, '' );
|
||||
}
|
||||
|
||||
/* Check security key */
|
||||
if( !\IPS\Login::compareHashes( Encrypt::fromTag( $record['security_key'] )->decrypt(), \IPS\Request::i()->security_key ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'lostpass_invalid_security_key', '2S151/5', 403, '' );
|
||||
}
|
||||
|
||||
/* Show a nicer error message if their link has expired */
|
||||
if( $record['entry_date'] < \IPS\DateTime::create()->sub( new \DateInterval( 'PT1H' ) )->getTimestamp() )
|
||||
{
|
||||
@@ -223,7 +233,8 @@ class _lostpass extends \IPS\Dispatcher\Controller
|
||||
$member = \IPS\Member::load( $record['member_id'] );
|
||||
|
||||
/* Reset the failed logins storage - we don't need to save because the login handler will do that for us later */
|
||||
$member->failed_logins = array();
|
||||
\IPS\Db::i()->delete( 'core_login_failures', [ 'login_member_id=?', $member->member_id ] );
|
||||
$member->failed_login_count = 0;
|
||||
|
||||
/* Now reset the member's password. If no handlers accept the change, create a local password */
|
||||
if ( !$member->changePassword( $values['password'], 'lost' ) )
|
||||
|
||||
Reference in new issue
Block a user