use pre_setPassword hook to update the encryption keys if the back-end doesn't support password change; improved output to let the admin know what happened
This commit is contained in:
parent
fdaab7372e
commit
d7a9852f7b
|
@ -141,6 +141,15 @@ class Hooks {
|
||||||
\OC_FileProxy::$enabled = $proxyStatus;
|
\OC_FileProxy::$enabled = $proxyStatus;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @brief If the password can't be changed within ownCloud, than update the key password in advance.
|
||||||
|
*/
|
||||||
|
public static function preSetPassphrase($params) {
|
||||||
|
if ( ! \OC_User::canUserChangePassword($params['uid']) ) {
|
||||||
|
self::setPassphrase($params);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Change a user's encryption passphrase
|
* @brief Change a user's encryption passphrase
|
||||||
* @param array $params keys: uid, password
|
* @param array $params keys: uid, password
|
||||||
|
|
|
@ -48,6 +48,7 @@ class Helper {
|
||||||
|
|
||||||
\OCP\Util::connectHook('OC_User', 'post_login', 'OCA\Encryption\Hooks', 'login');
|
\OCP\Util::connectHook('OC_User', 'post_login', 'OCA\Encryption\Hooks', 'login');
|
||||||
\OCP\Util::connectHook('OC_User', 'post_setPassword', 'OCA\Encryption\Hooks', 'setPassphrase');
|
\OCP\Util::connectHook('OC_User', 'post_setPassword', 'OCA\Encryption\Hooks', 'setPassphrase');
|
||||||
|
\OCP\Util::connectHook('OC_User', 'pre_setPassword', 'OCA\Encryption\Hooks', 'preSetPassphrase');
|
||||||
\OCP\Util::connectHook('OC_User', 'post_createUser', 'OCA\Encryption\Hooks', 'postCreateUser');
|
\OCP\Util::connectHook('OC_User', 'post_createUser', 'OCA\Encryption\Hooks', 'postCreateUser');
|
||||||
\OCP\Util::connectHook('OC_User', 'post_deleteUser', 'OCA\Encryption\Hooks', 'postDeleteUser');
|
\OCP\Util::connectHook('OC_User', 'post_deleteUser', 'OCA\Encryption\Hooks', 'postDeleteUser');
|
||||||
}
|
}
|
||||||
|
|
|
@ -28,17 +28,29 @@ if(is_null($userstatus)) {
|
||||||
exit();
|
exit();
|
||||||
}
|
}
|
||||||
|
|
||||||
$util = new \OCA\Encryption\Util(new \OC_FilesystemView('/'), $username);
|
|
||||||
$recoveryAdminEnabled = OC_Appconfig::getValue( 'files_encryption', 'recoveryAdminEnabled' );
|
$recoveryAdminEnabled = OC_Appconfig::getValue( 'files_encryption', 'recoveryAdminEnabled' );
|
||||||
$recoveryEnabledForUser = $util->recoveryEnabledForUser();
|
|
||||||
|
|
||||||
if ($recoveryAdminEnabled && $recoveryEnabledForUser && $recoveryPassword == '') {
|
|
||||||
|
$validRecoveryPassword = false;
|
||||||
|
$recoveryPasswordSupported = false;
|
||||||
|
|
||||||
|
if ($recoveryAdminEnabled) {
|
||||||
|
$util = new \OCA\Encryption\Util(new \OC_FilesystemView('/'), $username);
|
||||||
|
$validRecoveryPassword = $util->checkRecoveryPassword($recoveryPassword);
|
||||||
|
$recoveryPasswordSupported = $util->recoveryEnabledForUser();
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($recoveryPasswordSupported && $recoveryPassword == '') {
|
||||||
OC_JSON::error(array("data" => array( "message" => "Please provide a admin recovery password, otherwise all user data will be lost" )));
|
OC_JSON::error(array("data" => array( "message" => "Please provide a admin recovery password, otherwise all user data will be lost" )));
|
||||||
}elseif ( $recoveryPassword && ! $util->checkRecoveryPassword($recoveryPassword) ) {
|
} elseif ( $recoveryPasswordSupported && ! $validRecoveryPassword) {
|
||||||
OC_JSON::error(array("data" => array( "message" => "Wrong admin recovery password. Please check the password and try again." )));
|
OC_JSON::error(array("data" => array( "message" => "Wrong admin recovery password. Please check the password and try again." )));
|
||||||
}elseif(!is_null($password) && OC_User::setPassword( $username, $password, $recoveryPassword )) {
|
} else { // now we know that everything is file regarding the recovery password, let's try to change the password
|
||||||
|
$result = OC_User::setPassword($username, $password, $recoveryPassword);
|
||||||
|
if (!$result && $recoveryPasswordSupported) {
|
||||||
|
OC_JSON::error(array("data" => array( "message" => "Back-end doesn't support password change, but the users encryption key was successfully updated." )));
|
||||||
|
} elseif (!$result && !$recoveryPasswordSupported) {
|
||||||
|
OC_JSON::error(array("data" => array( "message" => "Unable to change password" )));
|
||||||
|
} else {
|
||||||
OC_JSON::success(array("data" => array( "username" => $username )));
|
OC_JSON::success(array("data" => array( "username" => $username )));
|
||||||
}
|
}
|
||||||
else{
|
|
||||||
OC_JSON::error(array("data" => array( "message" => "Unable to change password" )));
|
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in New Issue