Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
Y
yii2
Project
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
Wiki
Wiki
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Commits
Issue Boards
Open sidebar
Rotua Panjaitan
yii2
Commits
08b53fb3
Commit
08b53fb3
authored
Sep 30, 2014
by
Alexander Makarov
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Fixes #5088: new password reset token is now generated only if previous one was…
Fixes #5088: new password reset token is now generated only if previous one was already used or expired
parent
220b60f3
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
22 additions
and
6 deletions
+22
-6
User.php
apps/advanced/common/models/User.php
+18
-5
PasswordResetRequestForm.php
apps/advanced/frontend/models/PasswordResetRequestForm.php
+4
-1
No files found.
apps/advanced/common/models/User.php
View file @
08b53fb3
...
...
@@ -95,11 +95,7 @@ class User extends ActiveRecord implements IdentityInterface
*/
public
static
function
findByPasswordResetToken
(
$token
)
{
$expire
=
Yii
::
$app
->
params
[
'user.passwordResetTokenExpire'
];
$parts
=
explode
(
'_'
,
$token
);
$timestamp
=
(
int
)
end
(
$parts
);
if
(
$timestamp
+
$expire
<
time
())
{
// token expired
if
(
!
static
::
isPasswordResetTokenValid
(
$token
))
{
return
null
;
}
...
...
@@ -110,6 +106,23 @@ class User extends ActiveRecord implements IdentityInterface
}
/**
* Finds out if password reset token is valid
*
* @param string $token password reset token
* @return boolean
*/
public
static
function
isPasswordResetTokenValid
(
$token
)
{
if
(
empty
(
$token
))
{
return
false
;
}
$expire
=
Yii
::
$app
->
params
[
'user.passwordResetTokenExpire'
];
$parts
=
explode
(
'_'
,
$token
);
$timestamp
=
(
int
)
end
(
$parts
);
return
$timestamp
+
$expire
>=
time
();
}
/**
* @inheritdoc
*/
public
function
getId
()
...
...
apps/advanced/frontend/models/PasswordResetRequestForm.php
View file @
08b53fb3
...
...
@@ -42,7 +42,10 @@ class PasswordResetRequestForm extends Model
]);
if
(
$user
)
{
$user
->
generatePasswordResetToken
();
if
(
!
User
::
isPasswordResetTokenValid
(
$user
->
password_reset_token
))
{
$user
->
generatePasswordResetToken
();
}
if
(
$user
->
save
())
{
return
\Yii
::
$app
->
mailer
->
compose
(
'passwordResetToken'
,
[
'user'
=>
$user
])
->
setFrom
([
\Yii
::
$app
->
params
[
'supportEmail'
]
=>
\Yii
::
$app
->
name
.
' robot'
])
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment