Version 4.2.0
This commit is contained in:
1 parent
0dc2aee5ed
commit
96997ddd8e
2074 files changed
+125454
-55780
No files matched your search
+10
-17
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Internal Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 13 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
@@ -245,18 +244,12 @@ class _Internal extends LoginAbstract
|
||||
*/
|
||||
public function changePassword( \IPS\Member $member, $newPassword )
|
||||
{
|
||||
/* Clear any current sessions for this user. This resolves an issue where a user resets their password in one location, but a malicious
|
||||
user with access to their account can retain access in another location. */
|
||||
\IPS\Db::i()->delete( 'core_sessions', array( 'member_id=?', $member->member_id ) );
|
||||
\IPS\Db::i()->delete( 'core_sys_cp_sessions', array( 'session_member_id=?', $member->member_id ) );
|
||||
|
||||
$member->members_pass_salt = $member->generateSalt();
|
||||
$member->members_pass_hash = $member->encryptedPassword( $newPassword );
|
||||
$member->member_login_key = '';
|
||||
/* When we reset the login key and call checkLoginKey(), it will save for us. Note that we are NOT sending an updated pass_hash cookie
|
||||
here, and that is instead the responsibility of any controllers that result in the password being updated. This is a central class
|
||||
and we may not be updating the current viewing user's password at this point. */
|
||||
$member->checkLoginKey();
|
||||
/* Change the password */
|
||||
$member->members_pass_salt = $member->generateSalt();
|
||||
$member->members_pass_hash = $member->encryptedPassword( $newPassword );
|
||||
$member->save();
|
||||
|
||||
/* Resync */
|
||||
$member->memberSync( 'onPassChange', array( $newPassword ) );
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user