1 package club.wpia.gigi.pages;
3 import java.io.IOException;
4 import java.io.PrintWriter;
5 import java.net.URLEncoder;
6 import java.util.HashMap;
9 import javax.servlet.http.HttpServletRequest;
10 import javax.servlet.http.HttpServletResponse;
12 import club.wpia.gigi.GigiApiException;
13 import club.wpia.gigi.database.GigiPreparedStatement;
14 import club.wpia.gigi.dbObjects.User;
15 import club.wpia.gigi.localisation.Language;
16 import club.wpia.gigi.output.template.Form;
17 import club.wpia.gigi.output.template.MailTemplate;
18 import club.wpia.gigi.output.template.Template;
19 import club.wpia.gigi.output.template.TranslateCommand;
20 import club.wpia.gigi.util.AuthorizationContext;
21 import club.wpia.gigi.util.RandomToken;
22 import club.wpia.gigi.util.ServerConstants;
23 import club.wpia.gigi.util.ServerConstants.Host;
25 public class PasswordResetPage extends Page {
27 public static final int HOUR_MAX = 96;
29 public static final String PATH = "/passwordReset";
31 public PasswordResetPage() {
32 super("Password Reset");
35 public static class PasswordResetForm extends Form {
37 private static final Template t = new Template(PasswordResetForm.class.getResource("PasswordResetForm.templ"));
43 public PasswordResetForm(HttpServletRequest hsr) throws GigiApiException {
45 String idS = hsr.getParameter("id");
46 String tokS = hsr.getParameter("token");
47 if (idS == null || tokS == null) {
48 throw new GigiApiException("requires id and token");
51 id = Integer.parseInt(idS);
52 } catch (NumberFormatException e) {
53 throw new GigiApiException("requires id to be integer");
55 u = User.getResetWithToken(id, tokS);
57 throw new GigiApiException("User missing or token invalid");
63 public SuccessMessageResult submit(HttpServletRequest req) throws GigiApiException {
64 try (GigiPreparedStatement passwordReset = new GigiPreparedStatement("UPDATE `passwordResetTickets` SET `used` = CURRENT_TIMESTAMP WHERE `used` IS NULL AND `created` < CURRENT_TIMESTAMP - interval '1 hours' * ?::INTEGER;")) {
65 passwordReset.setInt(1, HOUR_MAX);
66 passwordReset.execute();
69 String p1 = req.getParameter("pword1");
70 String p2 = req.getParameter("pword2");
71 String tok = req.getParameter("private_token");
72 if (p1 == null || p2 == null || tok == null) {
73 throw new GigiApiException("Missing form parameter.");
75 if ( !p1.equals(p2)) {
76 throw new GigiApiException("New passwords differ.");
78 u.consumePasswordResetTicket(id, tok, p1);
79 u.writeUserLog(u, "User token based password reset");
80 return new SuccessMessageResult(new TranslateCommand("Password reset successful."));
84 protected void outputContent(PrintWriter out, Language l, Map<String, Object> vars) {
85 t.output(out, l, vars);
91 public boolean beforePost(HttpServletRequest req, HttpServletResponse resp) throws IOException {
92 return Form.getForm(req, PasswordResetForm.class).submitExceptionProtected(req, resp);
96 public void doPost(HttpServletRequest req, HttpServletResponse resp) throws IOException {
97 if (Form.printFormErrors(req, resp.getWriter())) {
98 PasswordResetForm form = Form.getForm(req, PasswordResetForm.class);
99 form.output(resp.getWriter(), getLanguage(req), getDefaultVars(req));
104 public void doGet(HttpServletRequest req, HttpServletResponse resp) throws IOException {
106 new PasswordResetForm(req).output(resp.getWriter(), getLanguage(req), getDefaultVars(req));
107 } catch (GigiApiException e) {
108 e.format(resp.getWriter(), getLanguage(req), getDefaultVars(req));
113 public boolean isPermitted(AuthorizationContext ac) {
117 private static final MailTemplate passwordResetMail = new MailTemplate(PasswordResetPage.class.getResource("PasswordResetMail.templ"));
119 public static void initPasswordResetProcess(User targetUser, HttpServletRequest req, String aword, Language l, String method, String subject) {
120 String ptok = RandomToken.generateToken(32);
121 int id = targetUser.generatePasswordResetTicket(Page.getUser(req), ptok, aword);
123 HashMap<String, Object> vars = new HashMap<>();
124 vars.put("subject", subject);
125 vars.put("method", method);
126 vars.put("link", "https://" + ServerConstants.getHostNamePortSecure(Host.WWW) + PasswordResetPage.PATH //
127 + "?id=" + id + "&token=" + URLEncoder.encode(ptok, "UTF-8"));
128 vars.put("hour_max", HOUR_MAX);
130 passwordResetMail.sendMail(l, vars, targetUser.getEmail());
131 } catch (IOException e) {