2016-07-20 23:38:20 +02:00
|
|
|
<?php
|
2016-07-21 01:39:36 +02:00
|
|
|
use Respect\Validation\Validator as DataValidator;
|
2016-08-04 21:01:24 +02:00
|
|
|
DataValidator::with('CustomValidations', true);
|
2016-07-20 23:38:20 +02:00
|
|
|
|
2017-04-16 07:35:04 +02:00
|
|
|
/**
|
2017-05-12 06:58:40 +02:00
|
|
|
* @api {post} /user/send-recover-password Send password recovery
|
2021-10-19 03:06:20 +02:00
|
|
|
* @apiVersion 4.10.0
|
2017-04-16 07:35:04 +02:00
|
|
|
*
|
2017-05-12 06:58:40 +02:00
|
|
|
* @apiName Send password recovery
|
2017-04-16 07:35:04 +02:00
|
|
|
*
|
|
|
|
* @apiGroup User
|
|
|
|
*
|
2018-07-20 23:21:18 +02:00
|
|
|
* @apiDescription This path sends a token to the email of the user/staff to change his password.
|
2017-04-16 07:35:04 +02:00
|
|
|
*
|
2017-05-12 06:58:40 +02:00
|
|
|
* @apiPermission any
|
2017-04-16 07:35:04 +02:00
|
|
|
*
|
2018-07-20 23:21:18 +02:00
|
|
|
* @apiParam {String} email The email of the user/staff who forgot the password.
|
|
|
|
* @apiParam {Boolean} staff Indicates if the user is a staff member.
|
2017-04-16 07:35:04 +02:00
|
|
|
*
|
2017-04-21 08:09:24 +02:00
|
|
|
* @apiUse INVALID_EMAIL
|
2017-04-16 07:35:04 +02:00
|
|
|
*
|
2017-04-21 08:09:24 +02:00
|
|
|
* @apiSuccess {Object} data Empty object.
|
2017-04-16 07:35:04 +02:00
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
2016-07-20 23:38:20 +02:00
|
|
|
class SendRecoverPasswordController extends Controller {
|
2016-07-22 09:44:55 +02:00
|
|
|
const PATH = '/send-recover-password';
|
2017-02-08 19:09:15 +01:00
|
|
|
const METHOD = 'POST';
|
2016-07-20 23:38:20 +02:00
|
|
|
|
2016-08-16 01:15:09 +02:00
|
|
|
private $token;
|
|
|
|
private $user;
|
2018-07-20 23:21:18 +02:00
|
|
|
private $staff;
|
2016-08-16 01:15:09 +02:00
|
|
|
|
2016-07-20 23:38:20 +02:00
|
|
|
public function validations() {
|
|
|
|
return [
|
|
|
|
'permission' => 'any',
|
2016-07-21 01:39:36 +02:00
|
|
|
'requestData' => [
|
|
|
|
'email' => [
|
2018-08-14 20:21:36 +02:00
|
|
|
'validation' => DataValidator::oneOf(
|
|
|
|
DataValidator::email()->userEmail(),
|
|
|
|
DataValidator::email()->staffEmail()
|
|
|
|
),
|
2016-07-21 01:39:36 +02:00
|
|
|
'error' => ERRORS::INVALID_EMAIL
|
|
|
|
]
|
|
|
|
]
|
2016-07-20 23:38:20 +02:00
|
|
|
];
|
|
|
|
}
|
|
|
|
|
|
|
|
public function handler() {
|
2019-11-08 23:42:02 +01:00
|
|
|
$this->staff = Controller::request('staff');
|
|
|
|
|
2016-07-21 01:39:36 +02:00
|
|
|
$email = Controller::request('email');
|
2018-07-20 23:21:18 +02:00
|
|
|
|
|
|
|
if($this->staff){
|
2019-10-29 22:23:20 +01:00
|
|
|
$this->user = Staff::getUser($email, 'email');
|
|
|
|
} else {
|
|
|
|
$this->user = User::getUser($email, 'email');
|
2018-07-20 23:21:18 +02:00
|
|
|
}
|
|
|
|
|
2016-08-16 01:15:09 +02:00
|
|
|
if(!$this->user->isNull()) {
|
|
|
|
$this->token = Hashing::generateRandomToken();
|
|
|
|
|
|
|
|
$recoverPassword = new RecoverPassword();
|
|
|
|
$recoverPassword->setProperties(array(
|
|
|
|
'email' => $email,
|
2018-07-20 23:21:18 +02:00
|
|
|
'token' => $this->token,
|
2018-08-14 20:21:36 +02:00
|
|
|
'staff' => !!$this->staff
|
2016-08-16 01:15:09 +02:00
|
|
|
));
|
|
|
|
$recoverPassword->store();
|
|
|
|
|
|
|
|
$this->sendEmail();
|
|
|
|
|
|
|
|
Response::respondSuccess();
|
|
|
|
} else {
|
2018-11-20 23:41:00 +01:00
|
|
|
throw new RequestException(ERRORS::INVALID_EMAIL);
|
2016-08-16 01:15:09 +02:00
|
|
|
}
|
|
|
|
}
|
2016-07-20 23:38:20 +02:00
|
|
|
|
2016-08-16 01:15:09 +02:00
|
|
|
public function sendEmail() {
|
2017-06-05 16:41:52 +02:00
|
|
|
$mailSender = MailSender::getInstance();
|
2016-07-20 23:38:20 +02:00
|
|
|
|
2016-08-16 01:15:09 +02:00
|
|
|
$mailSender->setTemplate(MailTemplate::PASSWORD_FORGOT, [
|
|
|
|
'to' => $this->user->email,
|
|
|
|
'name' => $this->user->name,
|
2017-07-11 08:39:17 +02:00
|
|
|
'url' => Setting::getSetting('url')->getValue(),
|
2016-08-16 01:15:09 +02:00
|
|
|
'token' => $this->token
|
|
|
|
]);
|
2016-07-20 23:38:20 +02:00
|
|
|
|
2016-08-16 01:15:09 +02:00
|
|
|
$mailSender->send();
|
2016-07-20 23:38:20 +02:00
|
|
|
}
|
2016-07-21 01:39:36 +02:00
|
|
|
}
|