changepassword.php

main 77 lines · 2.2 KB Raw
Alex Alex Commit Initial commit 01/10/2026 09:20
1<?php require_once 'engine/init.php';
2protect_page();
3
4if (empty($_POST) === false) {
5 /* Token used for cross site scripting security */
6 if (!Token::isValid($_POST['token'] ?? null)) {
7 $errors[] = t('login.token_invalid');
8 }
9
10 $required_fields = array('current_password', 'new_password', 'new_password_again');
11
12 foreach($required_fields as $key) {
13 if (empty($_POST[$key])) {
14 $errors[] = t('reg.fill_all');
15 break 1;
16 }
17 }
18
19 $pass_data = user_data($session_user_id, 'password');
20 if (!is_array($pass_data)) $pass_data = array('password' => '');
21
22 // .3 compatibility
23 $salt = array('salt' => '');
24 if (znote_server_adapter()->normalizedEngine() === 'TFS_03' && $config['salt'] === true) {
25 $salt = user_data($session_user_id, 'salt');
26 if (!is_array($salt)) $salt = array('salt' => '');
27 }
28 $current_password = (string)($_POST['current_password'] ?? '');
29 $new_password = (string)($_POST['new_password'] ?? '');
30 $new_password_again = (string)($_POST['new_password_again'] ?? '');
31 if (user_verify_login_password((int)$session_user_id, $current_password, (string)$pass_data['password'], (string)($salt['salt'] ?? ''))) {
32 if (trim($new_password) !== trim($new_password_again)) {
33 $errors[] = t('changepw.mismatch');
34 } else if (strlen($new_password) < 6) {
35 $errors[] = t('changepw.too_short');
36 } else if (strlen($new_password) > 100) {
37 $errors[] = t('changepw.too_long');
38 }
39 } else {
40 $errors[] = t('changepw.wrong');
41 }
42}
43
44/**
45 * What the view has to render: 'success', 'errors' or 'form'.
46 * The password write itself stays here - a theme must never carry it.
47 */
48$formState = 'form';
49
50if (isset($_GET['success']) && empty($_GET['success'])) {
51 $formState = 'success';
52
53 // The password changed, so this session is no longer valid.
54 znote_session_destroy();
55 header('refresh:2;url=index.php');
56
57} elseif (empty($_POST) === false && empty($errors) === true) {
58
59 if (znote_server_adapter()->normalizedEngine() === 'TFS_03') {
60 user_change_password03($session_user_id, $_POST['new_password']);
61 } else {
62 user_change_password($session_user_id, $_POST['new_password']);
63 }
64
65 header('Location: changepassword.php?success');
66 exit;
67
68} elseif (empty($errors) === false) {
69 $formState = 'errors';
70}
71
72theme_open();
73
74view('changepassword');
75
76theme_close();
77
Top