Commit 653690f1 authored by Rob Davies's avatar Rob Davies Committed by Larisse Amorim
Browse files

Issue #2922398 by mangy.fox, larisse, Stefdewa, geophysicist, sean.walker,...

Issue #2922398 by mangy.fox, larisse, Stefdewa, geophysicist, sean.walker, beunerd, robcarr: Unable to reset my password
parent 1899d8de
Loading
Loading
Loading
Loading
+10 −12
Changes for force_password_change.module: 10 added lines, 12 removed lines.
Original line number Diff line number Diff line
@@ -216,6 +216,7 @@ function force_password_change_user_login($account) {
    // Check to see if the user has a pending password change.
    if (\Drupal::service('force_password_change.service')->checkForForce()) {
      $middleware = \Drupal::service('force_password_change.on_only_login');
      if (empty($_REQUEST['form_id']) || $_REQUEST['form_id'] != 'user_pass_reset') {
        \Drupal::messenger()->addStatus(t('An administrator has required that you change your password. Please change your password to proceed.'));
        $response = new RedirectResponse(Url::fromRoute('entity.user.edit_form', ['user' => $account->id()])
          ->toString());
@@ -223,6 +224,7 @@ function force_password_change_user_login($account) {
      }
    }
  }
}

/**
 * Implements hook_user_insert().
@@ -253,23 +255,19 @@ function force_password_change_user_delete($account) {
/**
 * This function is called after a user's account page is updated.
 */
function force_password_change_validate_user(array &$form, FormStateInterface $form_state)
{
function force_password_change_validate_user(array &$form, FormStateInterface $form_state) {
  $account = $form_state->getFormObject()->getEntity();
  $current_user = \Drupal::currentUser();
	// Check to see if the user's account has been flagged to change their password, and if so,
	// have they changed it?
	if($account->id() == $current_user->id() && \Drupal::service('user.data')->get('force_password_change', $account->id(), 'force_password_change'))
	{
		if(!strlen($form_state->getValue('pass')))
		{
  // Check to see if the user's account has been flagged to change
  // their password, and if so, have they changed it?
  if($account->id() == $current_user->id() && \Drupal::service('user.data')->get('force_password_change', $account->id(), 'pending_force')) {
    if (!strlen($form_state->getValue('pass'))) {
      $form_state->setErrorByName('pass', t('You must choose a new password'));
    }
  }

	// Check to see if the new password is different from the old password
	if(\Drupal::service('user.auth')->authenticate($account->getAccountName(), $form_state->getValue('pass')))
	{
  // Check to see if the new password is different from the old password.
  if (\Drupal::service('user.auth')->authenticate($account->getAccountName(), $form_state->getValue('pass'))) {
    $form_state->setErrorByName('pass', t('You cannot use your current password. Please choose a different password.'));
  }
}
@@ -284,7 +282,7 @@ function force_password_change_update_user(array &$form, FormStateInterface $for
  $db = \Drupal::database();

  $current_pass = $form_state->getValue('current_pass');
  if ($current_pass && $current_pass != $form_state->getValue('pass')) {
  if ((!$current_pass) || ($current_pass && $current_pass != $form_state->getValue('pass'))) {
    // If a user's password has changed their password, the time of their
    // password change is saved to the database.
    \Drupal::service('force_password_change.service')->setChangedTimeForUser($uid);
+7 −2
Changes for src/EventSubscriber/ForcePasswordChangeEventSubscriber.php: 7 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -132,9 +132,14 @@ class ForcePasswordChangeEventSubscriber implements EventSubscriberInterface {
            \Drupal::messenger()->addMessage(t('This site requires that you change your password every @time_period. Please change your password to proceed.', ['@time_period' => $time_period]));
          }

          // Redirect the user to the change password page.
          $url = Url::fromRoute('entity.user.edit_form', ['user' => $this->currentUser->id()], ['query' => $this->getDestinationArray()]);
          $query = $this->getDestinationArray();
          $pass_key = 'pass_reset_' . $this->currentUser->id();
          if (isset($_SESSION[$pass_key])) {
            $query['pass-reset-token'] = $_SESSION[$pass_key];
          }

          // Redirect the user to the change password page.
          $url = Url::fromRoute('entity.user.edit_form', ['user' => $this->currentUser->id()], ['query' => $query]);
          $event->setResponse(new RedirectResponse($url->toString()));
        }
      }