Implements /activateEmail and changes how expiry is determined.
This commit is contained in:
parent
2f5a6d888b
commit
84a80ded03
3 changed files with 31 additions and 8 deletions
|
|
@ -49,8 +49,8 @@ proc makeIdentHash*(user, password: string, epoch: int64, secret: string,
|
||||||
comparingTo = ""): string =
|
comparingTo = ""): string =
|
||||||
## Creates a hash verifying the identity of a user. Used for password reset
|
## Creates a hash verifying the identity of a user. Used for password reset
|
||||||
## links and email activation links.
|
## links and email activation links.
|
||||||
## If ``epoch`` is smaller than the epoch of the user's last login then
|
## The ``epoch`` determines the creation time of this hash, it will be checked
|
||||||
## the link is invalid.
|
## during verification to ensure the hash hasn't expired.
|
||||||
## The ``secret`` is the 'salt' field in the ``person`` table.
|
## The ``secret`` is the 'salt' field in the ``person`` table.
|
||||||
when defined(windows):
|
when defined(windows):
|
||||||
result = getMD5(user & password & $epoch & secret)
|
result = getMD5(user & password & $epoch & secret)
|
||||||
|
|
|
||||||
|
|
@ -240,9 +240,9 @@ proc verifyIdentHash(
|
||||||
if row[0] == "":
|
if row[0] == "":
|
||||||
raise newForumError("User doesn't exist.", @["nick"])
|
raise newForumError("User doesn't exist.", @["nick"])
|
||||||
let newIdent = makeIdentHash(name, row[0], epoch, row[1], ident)
|
let newIdent = makeIdentHash(name, row[0], epoch, row[1], ident)
|
||||||
# Check that the user has not been logged in since this ident hash has been
|
# Check that it hasn't expired.
|
||||||
# created. Give the timestamp a certain range to prevent false negatives.
|
let diff = getTime() - epoch.fromUnix()
|
||||||
if row[2].parseInt > (epoch + 60*3):
|
if diff.hours > 2:
|
||||||
raise newForumError("Link expired")
|
raise newForumError("Link expired")
|
||||||
if newIdent != ident:
|
if newIdent != ident:
|
||||||
raise newForumError("Invalid ident hash")
|
raise newForumError("Invalid ident hash")
|
||||||
|
|
@ -576,6 +576,8 @@ proc executeRegister(c: TForumData, name, pass, antibot, userIp,
|
||||||
## Registers a new user and returns a new session key for that user's
|
## Registers a new user and returns a new session key for that user's
|
||||||
## session if registration was successful. Exceptions are raised otherwise.
|
## session if registration was successful. Exceptions are raised otherwise.
|
||||||
|
|
||||||
|
# TODO: Ignore deleted accounts in duplicate checks.
|
||||||
|
|
||||||
# email validation
|
# email validation
|
||||||
validateEmail(email, checkDuplicated=true)
|
validateEmail(email, checkDuplicated=true)
|
||||||
|
|
||||||
|
|
@ -1279,6 +1281,27 @@ routes:
|
||||||
except ForumError as exc:
|
except ForumError as exc:
|
||||||
resp Http400, $(%exc.data),"application/json"
|
resp Http400, $(%exc.data),"application/json"
|
||||||
|
|
||||||
|
get "/activateEmail":
|
||||||
|
createTFD()
|
||||||
|
cond(@"nick" != "")
|
||||||
|
cond(@"epoch" != "")
|
||||||
|
cond(@"ident" != "")
|
||||||
|
let epoch = getInt64(@"epoch", -1)
|
||||||
|
try:
|
||||||
|
verifyIdentHash(c, @"nick", epoch, @"ident")
|
||||||
|
|
||||||
|
exec(
|
||||||
|
db,
|
||||||
|
sql"""
|
||||||
|
update person set status = ?, lastOnline = DATETIME('now')
|
||||||
|
where name = ?;
|
||||||
|
""",
|
||||||
|
$Rank.Moderated, @"nick"
|
||||||
|
)
|
||||||
|
redirect(uri("/activateEmail/success"))
|
||||||
|
except ForumError as exc:
|
||||||
|
redirect(uri("/activateEmail/failure/" & encodeUrl(exc.data.message)))
|
||||||
|
|
||||||
get "/t/@id":
|
get "/t/@id":
|
||||||
cond "id" in request.params
|
cond "id" in request.params
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,4 @@
|
||||||
import strformat, times, options, json, tables, sugar, httpcore
|
import strformat, times, options, json, tables, sugar, httpcore, uri
|
||||||
from dom import window, Location
|
from dom import window, Location
|
||||||
|
|
||||||
include karax/prelude
|
include karax/prelude
|
||||||
|
|
@ -104,11 +104,11 @@ proc render(): VNode =
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
),
|
),
|
||||||
r("/activateEmail/failure",
|
r("/activateEmail/failure/@msg",
|
||||||
(params: Params) => (
|
(params: Params) => (
|
||||||
renderMessage(
|
renderMessage(
|
||||||
"Email activation failed",
|
"Email activation failed",
|
||||||
"Couldn't verify the supplied ident",
|
decodeUrl(params["msg"]),
|
||||||
"fa-exclamation"
|
"fa-exclamation"
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue