Version 4.2.0

This commit is contained in:
Neo committed 2025-12-19 05:44:59 -08:00
1 parent 0dc2aee5ed
commit 96997ddd8e
2074 files changed
+125454 -55780

No files matched your search

+10 -17
View File
@@ -1,12 +1,11 @@
<?php
/**
* @brief Internal Login Handler
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Community Suite
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
* @copyright (c) Invision Power Services, Inc.
* @license https://www.invisioncommunity.com/legal/standards/
* @package Invision Community
* @since 13 Mar 2013
* @version SVN_VERSION_NUMBER
*/
namespace IPS\Login;
@@ -245,18 +244,12 @@ class _Internal extends LoginAbstract
*/
public function changePassword( \IPS\Member $member, $newPassword )
{
/* Clear any current sessions for this user. This resolves an issue where a user resets their password in one location, but a malicious
user with access to their account can retain access in another location. */
\IPS\Db::i()->delete( 'core_sessions', array( 'member_id=?', $member->member_id ) );
\IPS\Db::i()->delete( 'core_sys_cp_sessions', array( 'session_member_id=?', $member->member_id ) );
$member->members_pass_salt = $member->generateSalt();
$member->members_pass_hash = $member->encryptedPassword( $newPassword );
$member->member_login_key = '';
/* When we reset the login key and call checkLoginKey(), it will save for us. Note that we are NOT sending an updated pass_hash cookie
here, and that is instead the responsibility of any controllers that result in the password being updated. This is a central class
and we may not be updating the current viewing user's password at this point. */
$member->checkLoginKey();
/* Change the password */
$member->members_pass_salt = $member->generateSalt();
$member->members_pass_hash = $member->encryptedPassword( $newPassword );
$member->save();
/* Resync */
$member->memberSync( 'onPassChange', array( $newPassword ) );
}