Merge remote-tracking branch 'origin/ticket/r16455-exclude_bot'

This commit is contained in:
Michael RICOIS 2018-03-12 10:11:36 +01:00
commit 37b955667f

View File

@ -35,22 +35,28 @@ class PasswordControllerCore extends FrontController
{ {
parent::process(); parent::process();
if (Tools::isSubmit('email')) // Check User Agent - no bot
{ $userAgent = $_SERVER['HTTP_USER_AGENT'];
if (!($email = Tools::getValue('email')) OR !Validate::isEmail($email)) if (strstr(strtolower($userAgent), 'bot')) {
$this->errors[] = Tools::displayError("Who are you ?");
}
if (empty($this->errors)) {
if (Tools::isSubmit('email')) {
if (!($email = Tools::getValue('email')) OR !Validate::isEmail($email)) {
$this->errors[] = Tools::displayError('Invalid e-mail address'); $this->errors[] = Tools::displayError('Invalid e-mail address');
else }
{ else {
$customer = new Customer(); $customer = new Customer();
$customer->getByemail($email); $customer->getByemail($email);
if (!Validate::isLoadedObject($customer)) if (!Validate::isLoadedObject($customer)) {
$this->errors[] = Tools::displayError('There is no account registered to this e-mail address.'); $this->errors[] = Tools::displayError('There is no account registered to this e-mail address.');
else }
{ else {
if ((strtotime($customer->last_passwd_gen.'+'.(int)($min_time = Configuration::get('PS_PASSWD_TIME_FRONT')).' minutes') - time()) > 0) if ((strtotime($customer->last_passwd_gen.'+'.(int)($min_time = Configuration::get('PS_PASSWD_TIME_FRONT')).' minutes') - time()) > 0) {
$this->errors[] = Tools::displayError('You can regenerate your password only every').' '.(int)($min_time).' '.Tools::displayError('minute(s)'); $this->errors[] = Tools::displayError('You can regenerate your password only every').' '.(int)($min_time).' '.Tools::displayError('minute(s)');
else }
{ else {
if (Mail::Send((int)(self::$cookie->id_lang), 'password_query', Mail::l('Password query confirmation'), if (Mail::Send((int)(self::$cookie->id_lang), 'password_query', Mail::l('Password query confirmation'),
array('{email}' => $customer->email, array('{email}' => $customer->email,
'{lastname}' => $customer->lastname, '{lastname}' => $customer->lastname,
@ -65,17 +71,15 @@ class PasswordControllerCore extends FrontController
} }
} }
} }
elseif (($token = Tools::getValue('token')) && ($id_customer = (int)(Tools::getValue('id_customer')))) elseif (($token = Tools::getValue('token')) && ($id_customer = (int)(Tools::getValue('id_customer')))) {
{
$email = Db::getInstance()->getValue('SELECT `email` FROM '._DB_PREFIX_.'customer c WHERE c.`secure_key` = \''.pSQL($token).'\' AND c.id_customer = '.(int)$id_customer); $email = Db::getInstance()->getValue('SELECT `email` FROM '._DB_PREFIX_.'customer c WHERE c.`secure_key` = \''.pSQL($token).'\' AND c.id_customer = '.(int)$id_customer);
if ($email) if ($email) {
{
$customer = new Customer(); $customer = new Customer();
$customer->getByemail($email); $customer->getByemail($email);
if ((strtotime($customer->last_passwd_gen.'+'.(int)($min_time = Configuration::get('PS_PASSWD_TIME_FRONT')).' minutes') - time()) > 0) if ((strtotime($customer->last_passwd_gen.'+'.(int)($min_time = Configuration::get('PS_PASSWD_TIME_FRONT')).' minutes') - time()) > 0) {
Tools::redirect('authentication.php?error_regen_pwd'); Tools::redirect('authentication.php?error_regen_pwd');
else }
{ else {
$customer->passwd = Tools::encrypt($password = Tools::passwdGen((int)MIN_PASSWD_LENGTH,'RANDOM')); $customer->passwd = Tools::encrypt($password = Tools::passwdGen((int)MIN_PASSWD_LENGTH,'RANDOM'));
$customer->last_passwd_gen = date('Y-m-d H:i:s', time()); $customer->last_passwd_gen = date('Y-m-d H:i:s', time());
if ($customer->update()) if ($customer->update())
@ -95,12 +99,15 @@ class PasswordControllerCore extends FrontController
$this->errors[] = Tools::displayError('An error occurred with your account and your new password cannot be sent to your e-mail. Please report your problem using the contact form.'); $this->errors[] = Tools::displayError('An error occurred with your account and your new password cannot be sent to your e-mail. Please report your problem using the contact form.');
} }
} }
else else {
$this->errors[] = Tools::displayError('We cannot regenerate your password with the data you submitted'); $this->errors[] = Tools::displayError('We cannot regenerate your password with the data you submitted');
} }
elseif (($token = Tools::getValue('token')) || ($id_customer = Tools::getValue('id_customer'))) }
elseif (($token = Tools::getValue('token')) || ($id_customer = Tools::getValue('id_customer'))) {
$this->errors[] = Tools::displayError('We cannot regenerate your password with the data you submitted'); $this->errors[] = Tools::displayError('We cannot regenerate your password with the data you submitted');
} }
}
}
public function displayContent() public function displayContent()
{ {