Use captcha for reset password.
Signed-off-by: Euan Torano <euantorano@gmail.com>
This commit is contained in:
parent
c1bd44b997
commit
b780b970f4
2 changed files with 22 additions and 30 deletions
|
|
@ -423,10 +423,12 @@
|
||||||
<td>${fieldValid(c, "nick", "Your nickname:")}</td>
|
<td>${fieldValid(c, "nick", "Your nickname:")}</td>
|
||||||
<td><input type="text" name="nick" maxlength="20" /></td>
|
<td><input type="text" name="nick" maxlength="20" /></td>
|
||||||
</tr>
|
</tr>
|
||||||
|
#if useCaptcha:
|
||||||
<tr>
|
<tr>
|
||||||
<td>${fieldValid(c, "antibot", "What is " & antibot(c) & "?")}</td>
|
<td>${fieldValid(c, "g-recaptcha-response", "Captcha:")}</td>
|
||||||
<td>${textWidget(c, "antibot", "", maxlength=4)}</td>
|
<td>${captcha.render(includeNoScript=true)}</td>
|
||||||
</tr>
|
</tr>
|
||||||
|
#end if
|
||||||
</table>
|
</table>
|
||||||
#if c.errorMsg != "":
|
#if c.errorMsg != "":
|
||||||
<div style="float: left; width: 100%;">
|
<div style="float: left; width: 100%;">
|
||||||
|
|
|
||||||
46
forum.nim
46
forum.nim
|
|
@ -276,19 +276,6 @@ proc validThreadId(c: TForumData): bool =
|
||||||
result = getValue(db, sql"select id from thread where id = ?",
|
result = getValue(db, sql"select id from thread where id = ?",
|
||||||
$c.threadId).len > 0
|
$c.threadId).len > 0
|
||||||
|
|
||||||
proc antibot(c: var TForumData): string =
|
|
||||||
let a = random(10)+1
|
|
||||||
let b = random(1000)+1
|
|
||||||
let answer = $(a+b)
|
|
||||||
|
|
||||||
exec(db, sql"delete from antibot where ip = ?", c.req.ip)
|
|
||||||
let captchaId = tryInsertID(db,
|
|
||||||
sql"insert into antibot(ip, answer) values (?, ?)", c.req.ip,
|
|
||||||
answer).int mod 10_000
|
|
||||||
let captchaFile = getCaptchaFilename(captchaId)
|
|
||||||
createCaptcha(captchaFile, $a & "+" & $b)
|
|
||||||
result = """<img src="$1" />""" % c.req.getCaptchaUrl(captchaId)
|
|
||||||
|
|
||||||
const
|
const
|
||||||
SecureChars = {'A'..'Z', 'a'..'z', '0'..'9', '_', '\128'..'\255'}
|
SecureChars = {'A'..'Z', 'a'..'z', '0'..'9', '_', '\128'..'\255'}
|
||||||
|
|
||||||
|
|
@ -297,13 +284,7 @@ proc setError(c: var TForumData, field, msg: string): bool {.inline.} =
|
||||||
c.errorMsg = "Error: " & msg
|
c.errorMsg = "Error: " & msg
|
||||||
return false
|
return false
|
||||||
|
|
||||||
proc isCaptchaCorrect(c: var TForumData, antibot: string): bool =
|
proc register(c: var TForumData, name, pass, antibot, userIp,
|
||||||
## Determines whether the user typed in the captcha correctly.
|
|
||||||
let correctRes = getValue(db,
|
|
||||||
sql"select answer from antibot where ip = ?", c.req.ip)
|
|
||||||
return antibot == correctRes
|
|
||||||
|
|
||||||
proc register(c: var TForumData, name, pass, antibot,
|
|
||||||
email: string): bool =
|
email: string): bool =
|
||||||
# Username validation:
|
# Username validation:
|
||||||
if name.len == 0 or not allCharsInSet(name, SecureChars):
|
if name.len == 0 or not allCharsInSet(name, SecureChars):
|
||||||
|
|
@ -319,13 +300,13 @@ proc register(c: var TForumData, name, pass, antibot,
|
||||||
if useCaptcha:
|
if useCaptcha:
|
||||||
var captchaValid: bool = false
|
var captchaValid: bool = false
|
||||||
try:
|
try:
|
||||||
captchaValid = waitFor captcha.verify(antibot)
|
captchaValid = waitFor captcha.verify(antibot, userIp)
|
||||||
except:
|
except:
|
||||||
echo("[ERROR] Error checking captcha: " & getCurrentExceptionMsg())
|
echo("[ERROR] Error checking captcha: " & getCurrentExceptionMsg())
|
||||||
captchaValid = false
|
captchaValid = false
|
||||||
|
|
||||||
if not captchaValid:
|
if not captchaValid:
|
||||||
return setError(c, "antibot", "Answer to captcha incorrect!")
|
return setError(c, "g-recaptcha-response", "Answer to captcha incorrect!")
|
||||||
|
|
||||||
# email validation
|
# email validation
|
||||||
if not ('@' in email and '.' in email):
|
if not ('@' in email and '.' in email):
|
||||||
|
|
@ -360,10 +341,19 @@ proc register(c: var TForumData, name, pass, antibot,
|
||||||
|
|
||||||
return true
|
return true
|
||||||
|
|
||||||
proc resetPassword(c: var TForumData, nick, antibot: string): bool =
|
proc resetPassword(c: var TForumData, nick, antibot, userIp: string): bool =
|
||||||
# Validate captcha
|
# captcha validation:
|
||||||
if not isCaptchaCorrect(c, antibot):
|
if useCaptcha:
|
||||||
return setError(c, "antibot", "Answer to captcha incorrect!")
|
var captchaValid: bool = false
|
||||||
|
try:
|
||||||
|
captchaValid = waitFor captcha.verify(antibot, userIp)
|
||||||
|
except:
|
||||||
|
echo("[ERROR] Error checking captcha: " & getCurrentExceptionMsg())
|
||||||
|
captchaValid = false
|
||||||
|
|
||||||
|
if not captchaValid:
|
||||||
|
return setError(c, "g-recaptcha-response", "Answer to captcha incorrect!")
|
||||||
|
|
||||||
# Gather some extra information to determine ident hash.
|
# Gather some extra information to determine ident hash.
|
||||||
let epoch = $int(epochTime())
|
let epoch = $int(epochTime())
|
||||||
let row = db.getRow(
|
let row = db.getRow(
|
||||||
|
|
@ -1133,7 +1123,7 @@ routes:
|
||||||
|
|
||||||
post "/doregister":
|
post "/doregister":
|
||||||
createTFD()
|
createTFD()
|
||||||
if c.register(@"name", @"new_password", @"g-recaptcha-response", @"email"):
|
if c.register(@"name", @"new_password", @"g-recaptcha-response", request.host, @"email"):
|
||||||
resp genMain(c, "You are now registered. You must now confirm your" &
|
resp genMain(c, "You are now registered. You must now confirm your" &
|
||||||
" email address by clicking the link sent to " & @"email",
|
" email address by clicking the link sent to " & @"email",
|
||||||
"Registration successful - Nim Forum")
|
"Registration successful - Nim Forum")
|
||||||
|
|
@ -1302,7 +1292,7 @@ routes:
|
||||||
echo(request.params)
|
echo(request.params)
|
||||||
cond(@"nick" != "")
|
cond(@"nick" != "")
|
||||||
|
|
||||||
if resetPassword(c, @"nick", @"antibot"):
|
if resetPassword(c, @"nick", @"g-recaptcha-response", request.host):
|
||||||
resp genMain(c, "Email sent!", "Reset Password - Nim Forum")
|
resp genMain(c, "Email sent!", "Reset Password - Nim Forum")
|
||||||
else:
|
else:
|
||||||
resp genMain(c, genFormResetPassword(c), "Reset Password - Nim Forum")
|
resp genMain(c, genFormResetPassword(c), "Reset Password - Nim Forum")
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue