forked from CakeDC/users
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathPasswordBehavior.php
More file actions
138 lines (125 loc) · 4.33 KB
/
Copy pathPasswordBehavior.php
File metadata and controls
138 lines (125 loc) · 4.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
<?php
/**
* Copyright 2010 - 2017, Cake Development Corporation (https://www.cakedc.com)
*
* Licensed under The MIT License
* Redistributions of files must retain the above copyright notice.
*
* @copyright Copyright 2010 - 2017, Cake Development Corporation (https://www.cakedc.com)
* @license MIT License (http://www.opensource.org/licenses/mit-license.php)
*/
namespace CakeDC\Users\Model\Behavior;
use CakeDC\Users\Exception\UserAlreadyActiveException;
use CakeDC\Users\Exception\UserNotActiveException;
use CakeDC\Users\Exception\UserNotFoundException;
use CakeDC\Users\Exception\WrongPasswordException;
use Cake\Core\Configure;
use Cake\Datasource\EntityInterface;
use Cake\Datasource\Exception\RecordNotFoundException;
use Cake\Mailer\MailerAwareTrait;
use Cake\Utility\Hash;
/**
* Covers the password management features
*/
class PasswordBehavior extends BaseTokenBehavior
{
use MailerAwareTrait;
/**
* Resets user token
*
* @param string $reference User username or email
* @param array $options checkActive, sendEmail, expiration
*
* @return string
* @throws \InvalidArgumentException
* @throws UserNotFoundException
* @throws UserAlreadyActiveException
*/
public function resetToken($reference, array $options = [])
{
if (empty($reference)) {
throw new \InvalidArgumentException(__d('CakeDC/Users', "Reference cannot be null"));
}
$expiration = Hash::get($options, 'expiration');
if (empty($expiration)) {
throw new \InvalidArgumentException(__d('CakeDC/Users', "Token expiration cannot be empty"));
}
$user = $this->_getUser($reference);
if (empty($user)) {
throw new UserNotFoundException(__d('CakeDC/Users', "User not found"));
}
if (Hash::get($options, 'checkActive')) {
if ($user->active) {
throw new UserAlreadyActiveException(__d('CakeDC/Users', "User account already validated"));
}
$user->active = false;
$user->activation_date = null;
}
if (Hash::get($options, 'ensureActive')) {
if (!$user['active']) {
throw new UserNotActiveException(__d('CakeDC/Users', "User not active"));
}
}
$user->updateToken($expiration);
$saveResult = $this->_table->save($user);
if (Hash::get($options, 'sendEmail')) {
$this->sendResetPasswordEmail($user);
}
return $saveResult;
}
/**
* Send the reset password related email link
*
* @param EntityInterface $user user
* @return void
*/
protected function sendResetPasswordEmail($user)
{
$this
->getMailer(Configure::read('Users.Email.mailerClass') ?: 'CakeDC/Users.Users')
->send('resetPassword', [$user]);
}
/**
* Get the user by email or username
*
* @param string $reference reference could be either an email or username
* @return mixed user entity if found
*/
protected function _getUser($reference)
{
return $this->_table->findByUsernameOrEmail($reference, $reference)->first();
}
/**
* Change password method
*
* @param EntityInterface $user user data.
* @throws WrongPasswordException
* @return mixed
*/
public function changePassword(EntityInterface $user)
{
try {
$currentUser = $this->_table->get($user->id, [
'contain' => []
]);
} catch (RecordNotFoundException $e) {
throw new UserNotFoundException(__d('CakeDC/Users', "User not found"));
}
if (!empty($user->current_password)) {
if (!$user->checkPassword($user->current_password, $currentUser->password)) {
throw new WrongPasswordException(__d('CakeDC/Users', 'The current password does not match'));
}
if ($user->current_password === $user->password_confirm) {
throw new WrongPasswordException(__d(
'CakeDC/Users',
'You cannot use the current password as the new one'
));
}
}
$user = $this->_table->save($user);
if (!empty($user)) {
$user = $this->_removeValidationToken($user);
}
return $user;
}
}