views.py 4.2 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394
  1. from django.template import RequestContext
  2. from django.utils.translation import ugettext as _
  3. from misago.banning.models import check_ban
  4. from misago.banning.decorators import block_banned
  5. from misago.banning.views import error_banned
  6. from misago.bruteforce.decorators import block_jammed
  7. from misago.crawlers.decorators import block_crawlers
  8. from misago.forms.layouts import FormLayout
  9. from misago.messages import Message
  10. from misago.authn.decorators import block_authenticated
  11. from misago.resetpswd.forms import UserResetPasswordForm
  12. from misago.users.models import User
  13. from misago.views import redirect_message, error404
  14. from misago.utils import get_random_string
  15. @block_crawlers
  16. @block_banned
  17. @block_authenticated
  18. @block_jammed
  19. def form(request):
  20. message = None
  21. if request.method == 'POST':
  22. form = UserResetPasswordForm(request.POST, request=request)
  23. if form.is_valid():
  24. user = form.found_user
  25. user_ban = check_ban(username=user.username, email=user.email)
  26. if user_ban:
  27. return error_banned(request, user, user_ban)
  28. elif user.activation != User.ACTIVATION_NONE:
  29. return redirect_message(request, Message(_("%(username)s, your account has to be activated in order for you to be able to request new password.") % {'username': user.username}), 'info')
  30. user.token = get_random_string(12)
  31. user.save(force_update=True)
  32. user.email_user(
  33. request,
  34. 'users/password/confirm',
  35. _("Confirm New Password Request")
  36. )
  37. return redirect_message(request, Message(_("%(username)s, new password request confirmation has been sent to %(email)s.") % {'username': user.username, 'email': user.email}), 'info')
  38. else:
  39. message = Message(form.non_field_errors()[0], 'error')
  40. else:
  41. form = UserResetPasswordForm(request=request)
  42. return request.theme.render_to_response('reset_password.html',
  43. {
  44. 'message': message,
  45. 'form': FormLayout(form),
  46. },
  47. context_instance=RequestContext(request));
  48. @block_banned
  49. @block_authenticated
  50. @block_jammed
  51. def reset(request, username="", user="0", token=""):
  52. user = int(user)
  53. try:
  54. user = User.objects.get(pk=user)
  55. user_ban = check_ban(username=user.username, email=user.email)
  56. if user_ban:
  57. return error_banned(request, user, user_ban)
  58. if user.activation != User.ACTIVATION_NONE:
  59. return redirect_message(request, Message(_("%(username)s, your account has to be activated in order for you to be able to request new password.") % {'username': user.username}), 'info')
  60. if not token or not user.token or user.token != token:
  61. return redirect_message(request, Message(_("%(username)s, request confirmation link is invalid. Please request new confirmation link.") % {'username': user.username}), 'error')
  62. new_password = get_random_string(6)
  63. user.token = None
  64. user.set_password(new_password)
  65. user.save(force_update=True)
  66. # Logout signed in and kill remember me tokens
  67. Session.objects.filter(user=user).update(user=None)
  68. Token.objects.filter(user=user).delete()
  69. # Set flash and mail new password
  70. user.email_user(
  71. request,
  72. 'users/password/new',
  73. _("Your New Password"),
  74. {'password': new_password}
  75. )
  76. return redirect_message(request, Message(_("%(username)s, your password has been changed with new one that was sent to %(email)s.") % {'username': user.username, 'email': user.email}), 'success')
  77. except User.DoesNotExist:
  78. return error404(request)