use pre_setPassword hook to update the encryption keys if the back-end doesn't support password change; improved output to let the admin know what happened

This commit is contained in:
Björn Schießle 2013-06-06 13:32:02 +02:00
parent fdaab7372e
commit d7a9852f7b
3 changed files with 31 additions and 9 deletions

View File

@ -141,6 +141,15 @@ class Hooks {
\OC_FileProxy::$enabled = $proxyStatus;
}
/**
* @brief If the password can't be changed within ownCloud, than update the key password in advance.
*/
public static function preSetPassphrase($params) {
if ( ! \OC_User::canUserChangePassword($params['uid']) ) {
self::setPassphrase($params);
}
}
/**
* @brief Change a user's encryption passphrase
* @param array $params keys: uid, password

View File

@ -48,6 +48,7 @@ class Helper {
\OCP\Util::connectHook('OC_User', 'post_login', 'OCA\Encryption\Hooks', 'login');
\OCP\Util::connectHook('OC_User', 'post_setPassword', 'OCA\Encryption\Hooks', 'setPassphrase');
\OCP\Util::connectHook('OC_User', 'pre_setPassword', 'OCA\Encryption\Hooks', 'preSetPassphrase');
\OCP\Util::connectHook('OC_User', 'post_createUser', 'OCA\Encryption\Hooks', 'postCreateUser');
\OCP\Util::connectHook('OC_User', 'post_deleteUser', 'OCA\Encryption\Hooks', 'postDeleteUser');
}

View File

@ -28,17 +28,29 @@ if(is_null($userstatus)) {
exit();
}
$util = new \OCA\Encryption\Util(new \OC_FilesystemView('/'), $username);
$recoveryAdminEnabled = OC_Appconfig::getValue( 'files_encryption', 'recoveryAdminEnabled' );
$recoveryEnabledForUser = $util->recoveryEnabledForUser();
if ($recoveryAdminEnabled && $recoveryEnabledForUser && $recoveryPassword == '') {
$validRecoveryPassword = false;
$recoveryPasswordSupported = false;
if ($recoveryAdminEnabled) {
$util = new \OCA\Encryption\Util(new \OC_FilesystemView('/'), $username);
$validRecoveryPassword = $util->checkRecoveryPassword($recoveryPassword);
$recoveryPasswordSupported = $util->recoveryEnabledForUser();
}
if ($recoveryPasswordSupported && $recoveryPassword == '') {
OC_JSON::error(array("data" => array( "message" => "Please provide a admin recovery password, otherwise all user data will be lost" )));
}elseif ( $recoveryPassword && ! $util->checkRecoveryPassword($recoveryPassword) ) {
} elseif ( $recoveryPasswordSupported && ! $validRecoveryPassword) {
OC_JSON::error(array("data" => array( "message" => "Wrong admin recovery password. Please check the password and try again." )));
}elseif(!is_null($password) && OC_User::setPassword( $username, $password, $recoveryPassword )) {
OC_JSON::success(array("data" => array( "username" => $username )));
}
else{
OC_JSON::error(array("data" => array( "message" => "Unable to change password" )));
} else { // now we know that everything is file regarding the recovery password, let's try to change the password
$result = OC_User::setPassword($username, $password, $recoveryPassword);
if (!$result && $recoveryPasswordSupported) {
OC_JSON::error(array("data" => array( "message" => "Back-end doesn't support password change, but the users encryption key was successfully updated." )));
} elseif (!$result && !$recoveryPasswordSupported) {
OC_JSON::error(array("data" => array( "message" => "Unable to change password" )));
} else {
OC_JSON::success(array("data" => array( "username" => $username )));
}
}