Skip to content

Commit 2db912e

Browse files
author
Nick Harper
committed
Add change password settings panel
Summary: In password-based auth environments, there is now a user settings panel to allow them to change their password. Test Plan: Click settings, choose password from the left: * enter current password, new password (twice), log out, and log in with new password * enter current password, non-matching passwords, and get error * enter invalid old password, and get error * use firebug to change csrf token and verify that it does not save with and invalid token Changed config to disable password auth, loaded settings panel and saw that password was no longer visible. Tried loading the panel anyway and got redirected. Reviewers: epriestley Reviewed By: epriestley CC: aran, epriestley Differential Revision: 890
1 parent 3ecd11a commit 2db912e

File tree

5 files changed

+149
-2
lines changed

5 files changed

+149
-2
lines changed

src/__phutil_library_map__.php

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -642,6 +642,7 @@
642642
'PhabricatorUserLog' => 'applications/people/storage/log',
643643
'PhabricatorUserOAuthInfo' => 'applications/people/storage/useroauthinfo',
644644
'PhabricatorUserOAuthSettingsPanelController' => 'applications/people/controller/settings/panels/oauth',
645+
'PhabricatorUserPasswordSettingsPanelController' => 'applications/people/controller/settings/panels/password',
645646
'PhabricatorUserPreferenceSettingsPanelController' => 'applications/people/controller/settings/panels/preferences',
646647
'PhabricatorUserPreferences' => 'applications/people/storage/preferences',
647648
'PhabricatorUserProfile' => 'applications/people/storage/profile',
@@ -1222,6 +1223,7 @@
12221223
'PhabricatorUserLog' => 'PhabricatorUserDAO',
12231224
'PhabricatorUserOAuthInfo' => 'PhabricatorUserDAO',
12241225
'PhabricatorUserOAuthSettingsPanelController' => 'PhabricatorUserSettingsPanelController',
1226+
'PhabricatorUserPasswordSettingsPanelController' => 'PhabricatorUserSettingsPanelController',
12251227
'PhabricatorUserPreferenceSettingsPanelController' => 'PhabricatorUserSettingsPanelController',
12261228
'PhabricatorUserPreferences' => 'PhabricatorUserDAO',
12271229
'PhabricatorUserProfile' => 'PhabricatorUserDAO',

src/applications/people/controller/settings/PhabricatorUserSettingsController.php

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,16 +29,20 @@ public function processRequest() {
2929

3030
$request = $this->getRequest();
3131

32-
// TODO: Implement a password panel.
33-
3432
$this->pages = array(
3533
'account' => 'Account',
3634
'profile' => 'Profile',
3735
'email' => 'Email',
36+
'password' => 'Password',
3837
'preferences' => 'Preferences',
3938
'conduit' => 'Conduit Certificate',
4039
);
4140

41+
if (!PhabricatorEnv::getEnvConfig('account.editable') ||
42+
!PhabricatorEnv::getEnvConfig('auth.password-auth-enabled')) {
43+
unset($this->pages['password']);
44+
}
45+
4246
if (PhabricatorUserSSHKeysSettingsPanelController::isEnabled()) {
4347
$this->pages['sshkeys'] = 'SSH Public Keys';
4448
}
@@ -67,6 +71,10 @@ public function processRequest() {
6771
case 'email':
6872
$delegate = new PhabricatorUserEmailSettingsPanelController($request);
6973
break;
74+
case 'password':
75+
$delegate = new PhabricatorUserPasswordSettingsPanelController(
76+
$request);
77+
break;
7078
case 'conduit':
7179
$delegate = new PhabricatorUserConduitSettingsPanelController($request);
7280
break;

src/applications/people/controller/settings/__init__.php

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,9 +13,11 @@
1313
phutil_require_module('phabricator', 'applications/people/controller/settings/panels/conduit');
1414
phutil_require_module('phabricator', 'applications/people/controller/settings/panels/email');
1515
phutil_require_module('phabricator', 'applications/people/controller/settings/panels/oauth');
16+
phutil_require_module('phabricator', 'applications/people/controller/settings/panels/password');
1617
phutil_require_module('phabricator', 'applications/people/controller/settings/panels/preferences');
1718
phutil_require_module('phabricator', 'applications/people/controller/settings/panels/profile');
1819
phutil_require_module('phabricator', 'applications/people/controller/settings/panels/sshkeys');
20+
phutil_require_module('phabricator', 'infrastructure/env');
1921
phutil_require_module('phabricator', 'view/layout/sidenav');
2022

2123
phutil_require_module('phutil', 'markup');
Lines changed: 111 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,111 @@
1+
<?php
2+
3+
/*
4+
* Copyright 2011 Facebook, Inc.
5+
*
6+
* Licensed under the Apache License, Version 2.0 (the "License");
7+
* you may not use this file except in compliance with the License.
8+
* You may obtain a copy of the License at
9+
*
10+
* http://www.apache.org/licenses/LICENSE-2.0
11+
*
12+
* Unless required by applicable law or agreed to in writing, software
13+
* distributed under the License is distributed on an "AS IS" BASIS,
14+
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15+
* See the License for the specific language governing permissions and
16+
* limitations under the License.
17+
*/
18+
19+
class PhabricatorUserPasswordSettingsPanelController
20+
extends PhabricatorUserSettingsPanelController {
21+
22+
public function processRequest() {
23+
24+
$request = $this->getRequest();
25+
$user = $request->getUser();
26+
$editable = $this->getAccountEditable();
27+
28+
// There's no sense in showing a change password panel if the user
29+
// can't change their password
30+
if (!$editable ||
31+
!PhabricatorEnv::getEnvConfig('auth.password-auth-enabled')) {
32+
return new Aphront400Response();
33+
}
34+
35+
$errors = array();
36+
if ($request->isFormPost()) {
37+
if ($user->comparePassword($request->getStr('old_pw'))) {
38+
$pass = $request->getStr('new_pw');
39+
$conf = $request->getStr('conf_pw');
40+
if ($pass === $conf) {
41+
if (strlen($pass)) {
42+
$user->setPassword($pass);
43+
// This write is unguarded because the CSRF token has already
44+
// been checked in the call to $request->isFormPost() and
45+
// the CSRF token depends on the password hash, so when it
46+
// is changed here the CSRF token check will fail.
47+
$unguarded = AphrontWriteGuard::beginScopedUnguardedWrites();
48+
$user->save();
49+
unset($unguarded);
50+
return id(new AphrontRedirectResponse())
51+
->setURI('/settings/page/password/?saved=true');
52+
} else {
53+
$errors[] = 'Your new password is too short.';
54+
}
55+
} else {
56+
$errors[] = 'New password and confirmation do not match.';
57+
}
58+
} else {
59+
$errors[] = 'The old password you entered is incorrect.';
60+
}
61+
}
62+
63+
$notice = null;
64+
if (!$errors) {
65+
if ($request->getStr('saved')) {
66+
$notice = new AphrontErrorView();
67+
$notice->setSeverity(AphrontErrorView::SEVERITY_NOTICE);
68+
$notice->setTitle('Changes Saved');
69+
$notice->appendChild('<p>Your password has been updated.</p>');
70+
}
71+
} else {
72+
$notice = new AphrontErrorView();
73+
$notice->setTitle('Error Changing Password');
74+
$notice->setErrors($errors);
75+
}
76+
77+
$form = new AphrontFormView();
78+
$form
79+
->setUser($user)
80+
->appendChild(
81+
id(new AphrontFormPasswordControl())
82+
->setLabel('Old Password')
83+
->setName('old_pw'));
84+
$form
85+
->appendChild(
86+
id(new AphrontFormPasswordControl())
87+
->setLabel('New Password')
88+
->setName('new_pw'));
89+
$form
90+
->appendChild(
91+
id(new AphrontFormPasswordControl())
92+
->setLabel('Confirm Password')
93+
->setName('conf_pw'));
94+
$form
95+
->appendChild(
96+
id(new AphrontFormSubmitControl())
97+
->setValue('Save'));
98+
99+
$panel = new AphrontPanelView();
100+
$panel->setHeader('Change Password');
101+
$panel->setWidth(AphrontPanelView::WIDTH_FORM);
102+
$panel->appendChild($form);
103+
104+
return id(new AphrontNullView())
105+
->appendChild(
106+
array(
107+
$notice,
108+
$panel,
109+
));
110+
}
111+
}
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
<?php
2+
/**
3+
* This file is automatically generated. Lint this module to rebuild it.
4+
* @generated
5+
*/
6+
7+
8+
9+
phutil_require_module('phabricator', 'aphront/response/400');
10+
phutil_require_module('phabricator', 'aphront/response/redirect');
11+
phutil_require_module('phabricator', 'aphront/writeguard');
12+
phutil_require_module('phabricator', 'applications/people/controller/settings/panels/base');
13+
phutil_require_module('phabricator', 'infrastructure/env');
14+
phutil_require_module('phabricator', 'view/form/base');
15+
phutil_require_module('phabricator', 'view/form/control/password');
16+
phutil_require_module('phabricator', 'view/form/control/submit');
17+
phutil_require_module('phabricator', 'view/form/error');
18+
phutil_require_module('phabricator', 'view/layout/panel');
19+
phutil_require_module('phabricator', 'view/null');
20+
21+
phutil_require_module('phutil', 'utils');
22+
23+
24+
phutil_require_source('PhabricatorUserPasswordSettingsPanelController.php');

0 commit comments

Comments
 (0)