overleaf/services/web/app/coffee/Features/PasswordReset/PasswordResetController.coffee

61 lines
2.2 KiB
CoffeeScript
Raw Normal View History

2014-05-15 15:50:38 +00:00
PasswordResetHandler = require("./PasswordResetHandler")
RateLimiter = require("../../infrastructure/RateLimiter")
AuthenticationController = require("../Authentication/AuthenticationController")
UserGetter = require("../User/UserGetter")
2016-07-05 13:19:59 +00:00
UserSessionsManager = require("../User/UserSessionsManager")
logger = require "logger-sharelatex"
2014-05-15 15:20:23 +00:00
module.exports =
2014-05-15 15:50:38 +00:00
renderRequestResetForm: (req, res)->
logger.log "rendering request reset form"
res.render "user/passwordReset",
2014-08-01 12:47:14 +00:00
title:"reset_password"
2014-05-15 15:20:23 +00:00
2014-05-15 15:50:38 +00:00
requestReset: (req, res)->
2014-06-10 16:54:29 +00:00
email = req.body.email.trim().toLowerCase()
opts =
endpointName: "password_reset_rate_limit"
timeInterval: 60
subjectName: req.ip
throttle: 6
2014-10-30 08:33:18 +00:00
RateLimiter.addCount opts, (err, canContinue)->
if !canContinue
return res.send 500, { message: req.i18n.translate("rate_limit_hit_wait")}
PasswordResetHandler.generateAndEmailResetToken email, (err, exists)->
if err?
res.send 500, {message:err?.message}
else if exists
2015-07-08 15:56:38 +00:00
res.sendStatus 200
else
res.send 404, {message: req.i18n.translate("cant_find_email")}
2014-05-15 15:20:23 +00:00
2014-05-15 15:50:38 +00:00
renderSetPasswordForm: (req, res)->
if req.query.passwordResetToken?
req.session.resetToken = req.query.passwordResetToken
return res.redirect('/user/password/set')
if !req.session.resetToken?
return res.redirect('/user/password/reset')
res.render "user/setPassword",
2014-08-01 12:47:14 +00:00
title:"set_password"
passwordResetToken: req.session.resetToken
2014-05-15 15:20:23 +00:00
setNewUserPassword: (req, res, next)->
{passwordResetToken, password} = req.body
if !password? or password.length == 0 or !passwordResetToken? or passwordResetToken.length == 0
2015-07-08 15:56:38 +00:00
return res.sendStatus 400
delete req.session.resetToken
PasswordResetHandler.setNewUserPassword passwordResetToken?.trim(), password?.trim(), (err, found, user_id) ->
return next(err) if err?
if found
2016-07-05 13:19:59 +00:00
UserSessionsManager.revokeAllUserSessions {_id: user_id}, [], (err) ->
return next(err) if err?
if req.body.login_after
UserGetter.getUser user_id, {email: 1}, (err, user) ->
return next(err) if err?
AuthenticationController.doLogin {email:user.email, password: password}, req, res, next
else
res.sendStatus 200
2014-05-15 15:50:38 +00:00
else
res.sendStatus 404