forked from CakeDC/users
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathPasswordBehavior.php
More file actions
127 lines (117 loc) · 4.19 KB
/
Copy pathPasswordBehavior.php
File metadata and controls
127 lines (117 loc) · 4.19 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
<?php
/**
* Copyright 2010 - 2015, Cake Development Corporation (http://cakedc.com)
*
* Licensed under The MIT License
* Redistributions of files must retain the above copyright notice.
*
* @copyright Copyright 2010 - 2015, Cake Development Corporation (http://cakedc.com)
* @license MIT License (http://www.opensource.org/licenses/mit-license.php)
*/
namespace CakeDC\Users\Model\Behavior;
use CakeDC\Users\Exception\UserAlreadyActiveException;
use CakeDC\Users\Exception\UserNotFoundException;
use CakeDC\Users\Exception\WrongPasswordException;
use CakeDC\Users\Model\Behavior\Behavior;
use Cake\Datasource\EntityInterface;
use Cake\Mailer\Email;
use Cake\Utility\Hash;
use InvalidArgumentException;
/**
* Covers the password management features
*/
class PasswordBehavior extends Behavior
{
/**
* Resets user token
*
* @param string $reference User username or email
* @param array $options checkActive, sendEmail, expiration
*
* @return string
* @throws InvalidArgumentException
* @throws UserNotFoundException
* @throws UserAlreadyActiveException
*/
public function resetToken($reference, array $options = [])
{
if (empty($reference)) {
throw new InvalidArgumentException(__d('Users', "Reference cannot be null"));
}
$expiration = Hash::get($options, 'expiration');
if (empty($expiration)) {
throw new InvalidArgumentException(__d('Users', "Token expiration cannot be empty"));
}
$user = $this->_getUser($reference);
if (empty($user)) {
throw new UserNotFoundException(__d('Users', "User not found"));
}
if (Hash::get($options, 'checkActive')) {
if ($user->active) {
throw new UserAlreadyActiveException("User account already validated");
}
$user->active = false;
$user->activation_date = null;
}
$user->updateToken($expiration);
$saveResult = $this->_table->save($user);
$template = !empty($options['emailTemplate']) ? $options['emailTemplate'] : 'CakeDC/Users.reset_password';
if (Hash::get($options, 'sendEmail')) {
$this->sendResetPasswordEmail($saveResult, null, $template);
}
return $saveResult;
}
/**
* Get the user by email or username
*
* @param string $reference reference could be either an email or username
* @return mixed user entity if found
*/
protected function _getUser($reference)
{
return $this->_table->findAllByUsernameOrEmail($reference, $reference)->first();
}
/**
* Send the reset password email
*
* @param EntityInterface $user User entity
* @param Email $email instance, if null the default email configuration with the
* @param string $template email template
* Users.validation template will be used, so set a ->template() if you pass an Email
* instance
* @return array email send result
*/
public function sendResetPasswordEmail(EntityInterface $user, Email $email = null, $template = 'CakeDC/Users.reset_password')
{
$firstName = isset($user['first_name'])? $user['first_name'] . ', ' : '';
$subject = __d('Users', '{0}Your reset password link', $firstName);
return $this->_getEmailInstance($email)
->template($template)
->to($user['email'])
->subject($subject)
->viewVars($user->toArray())
->send();
}
/**
* Change password method
*
* @param EntityInterface $user user data.
* @return mixed
*/
public function changePassword(EntityInterface $user)
{
$currentUser = $this->_table->get($user->id, [
'contain' => []
]);
if (!empty($user->current_password)) {
if (!$user->checkPassword($user->current_password, $currentUser->password)) {
throw new WrongPasswordException(__d('Users', 'The old password does not match'));
}
}
$user = $this->_table->save($user);
if (!empty($user)) {
$user = $this->_removeValidationToken($user);
}
return $user;
}
}