#190 resetpassword nearly works (has bugs)
This commit is contained in:
parent
6c669d8486
commit
39bf969b90
15
GanjooRazor/Models/ResetPasswordViewModelWithRepPass.cs
Normal file
15
GanjooRazor/Models/ResetPasswordViewModelWithRepPass.cs
Normal file
@ -0,0 +1,15 @@
|
||||
using RSecurityBackend.Models.Auth.ViewModels;
|
||||
|
||||
namespace GanjooRazor.Models
|
||||
{
|
||||
/// <summary>
|
||||
/// ResetPasswordViewModel with PasswordConfirmation field
|
||||
/// </summary>
|
||||
public class ResetPasswordViewModelWithRepPass : ResetPasswordViewModel
|
||||
{
|
||||
/// <summary>
|
||||
/// password confirmation
|
||||
/// </summary>
|
||||
public string PasswordConfirmation { get; set; }
|
||||
}
|
||||
}
|
||||
@ -3,7 +3,7 @@
|
||||
namespace GanjooRazor.Models
|
||||
{
|
||||
/// <summary>
|
||||
/// erifiedSignUpViewModel with PasswordConfirmation
|
||||
/// VerifiedSignUpViewModel with PasswordConfirmation field
|
||||
/// </summary>
|
||||
public class VerifiedSignUpViewModelWithRepPass : VerifiedSignUpViewModel
|
||||
{
|
||||
|
||||
@ -24,8 +24,9 @@
|
||||
</div>
|
||||
}
|
||||
else
|
||||
if (Model.PhaseSendEmail)
|
||||
{
|
||||
<form method="post" action="/resetpassword?Handler=Phase1">
|
||||
<form method="post" action="/resetpassword?Handler=SendEmail">
|
||||
<table>
|
||||
<tr>
|
||||
<td colspan="2">
|
||||
@ -39,7 +40,7 @@
|
||||
<span class="inputlabel">پست الکترونیکی: </span>
|
||||
</td>
|
||||
<td>
|
||||
<input type="email" asp-for="SignUpViewModel.Email" placeholder="پست الکترونیکی" />
|
||||
<input type="email" asp-for="ForgotPasswordViewModel.Email" placeholder="پست الکترونیکی" />
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
@ -48,10 +49,10 @@
|
||||
</td>
|
||||
<td>
|
||||
<img src="@Model.CaptchaImageUrl" />
|
||||
<input type="hidden" asp-for="SignUpViewModel.ClientAppName" />
|
||||
<input type="hidden" asp-for="SignUpViewModel.Language" />
|
||||
<input type="hidden" asp-for="SignUpViewModel.CallbackUrl" />
|
||||
<input type="hidden" asp-for="SignUpViewModel.CaptchaImageId" />
|
||||
<input type="hidden" asp-for="ForgotPasswordViewModel.ClientAppName" />
|
||||
<input type="hidden" asp-for="ForgotPasswordViewModel.Language" />
|
||||
<input type="hidden" asp-for="ForgotPasswordViewModel.CallbackUrl" />
|
||||
<input type="hidden" asp-for="ForgotPasswordViewModel.CaptchaImageId" />
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
@ -66,7 +67,7 @@
|
||||
<span class="inputlabel">عدد تصویر امنیتی: </span>
|
||||
</td>
|
||||
<td>
|
||||
<input type="password" asp-for="SignUpViewModel.CaptchaValue" id="password" placeholder="عدد تصویر امنیتی" />
|
||||
<input type="password" asp-for="ForgotPasswordViewModel.CaptchaValue" id="password" placeholder="عدد تصویر امنیتی" />
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
@ -75,9 +76,71 @@
|
||||
</table>
|
||||
<div><p style="color:red">@Model.LastError</p></div>
|
||||
</form>
|
||||
|
||||
}
|
||||
else
|
||||
if (Model.PhaseVerify)
|
||||
{
|
||||
<form method="post" action="/resetpassword?Handler=Verify">
|
||||
<table>
|
||||
<tr>
|
||||
<td colspan="2">
|
||||
<p>لطفا پست الکترونیکی خود را بررسی کنید. در صورتی که نشانی پست الکترونیکی خود را درست وارد کرده باشید نامهای از گنجور دریافت کردهاید که حاوی یک رمز است. </p>
|
||||
<p>رمز دریافتی را در کادر زیر وارد کرده، روی دکمهٔ «ادامه» کلیک کنید</p>
|
||||
<p style="color:red">تذکر: ممکن است نامه به پوشه اسپم منتقل شده باشد</p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<td>
|
||||
<span class="inputlabel">رمز دریافتی:</span>
|
||||
</td>
|
||||
<td>
|
||||
<input asp-for="Secret" placeholder="رمز دریافتی" />
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><a role="button" style="cursor: pointer; width: 100%; color: white; background-color: red; display: block">برگشت</a></td>
|
||||
<td><input type="submit" name="submit" id="submit" value="ادامه" /></td>
|
||||
</tr>
|
||||
</table>
|
||||
<div><p style="color:red">@Model.LastError</p></div>
|
||||
</form>
|
||||
}
|
||||
else
|
||||
{
|
||||
<form method="post" action="/resetpassword?Handler=Phase3">
|
||||
<table>
|
||||
<tr>
|
||||
<td>
|
||||
<span class="inputlabel">گذرواژه: </span>
|
||||
</td>
|
||||
<td>
|
||||
<input type="password" asp-for="ResetPasswordViewModel.Password" id="password" placeholder="گذرواژه" />
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
<span class="inputlabel">تکرار گذرواژه: </span>
|
||||
</td>
|
||||
<td>
|
||||
<input type="password" asp-for="ResetPasswordViewModel.PasswordConfirmation" placeholder="تکرار گذرواژه" />
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td colspan="2">
|
||||
<input type="hidden" asp-for="ResetPasswordViewModel.Email" />
|
||||
<input type="hidden" asp-for="ResetPasswordViewModel.Secret" />
|
||||
<p>گذرواژه باید دست کم شامل ۶ حرف باشد و از ترکیبی از اعداد و حروف انگلیسی تشکیل شده باشد.</p>
|
||||
<p>حروف و اعداد نباید تکراری باشند و وجود حداقل یک عدد و یک حرف کوچک انگلیسی در گذرواژه الزامی است</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td colspan="2"><input type="submit" name="submit" id="submit" value="ادامه" /></td>
|
||||
</tr>
|
||||
</table>
|
||||
<div><p style="color:red">@Model.LastError</p></div>
|
||||
</form>
|
||||
}
|
||||
</div>
|
||||
</div>
|
||||
</body>
|
||||
|
||||
@ -1,20 +1,229 @@
|
||||
|
||||
|
||||
using GanjooRazor.Models;
|
||||
using Microsoft.AspNetCore.Http;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
using Microsoft.AspNetCore.Mvc.RazorPages;
|
||||
using Microsoft.Extensions.Configuration;
|
||||
using Newtonsoft.Json;
|
||||
using RMuseum.Models.Auth.Memory;
|
||||
using RSecurityBackend.Models.Auth.Memory;
|
||||
using RSecurityBackend.Models.Auth.ViewModels;
|
||||
using System;
|
||||
using System.Linq;
|
||||
using System.Net.Http;
|
||||
using System.Text;
|
||||
using System.Threading.Tasks;
|
||||
|
||||
namespace GanjooRazor.Pages
|
||||
{
|
||||
[IgnoreAntiforgeryToken(Order = 1001)]
|
||||
public class ResetPasswordModel : PageModel
|
||||
{
|
||||
/// <summary>
|
||||
/// HttpClient instance
|
||||
/// </summary>
|
||||
private readonly HttpClient _httpClient;
|
||||
|
||||
/// <summary>
|
||||
/// configuration
|
||||
/// </summary>
|
||||
private readonly IConfiguration _configuration;
|
||||
|
||||
public ResetPasswordModel(HttpClient httpClient, IConfiguration configuration)
|
||||
{
|
||||
_httpClient = httpClient;
|
||||
_configuration = configuration;
|
||||
}
|
||||
|
||||
|
||||
public bool LoggedIn { get; set; }
|
||||
|
||||
public string LastError { get; set; }
|
||||
|
||||
public UnverifiedSignUpViewModel SignUpViewModel { get; set; }
|
||||
[BindProperty]
|
||||
public UnverifiedSignUpViewModel ForgotPasswordViewModel { get; set; }
|
||||
|
||||
[BindProperty]
|
||||
public string Secret { get; set; }
|
||||
|
||||
|
||||
[BindProperty]
|
||||
public ResetPasswordViewModelWithRepPass ResetPasswordViewModel { get; set; }
|
||||
|
||||
public string CaptchaImageUrl { get; set; }
|
||||
public void OnGet()
|
||||
|
||||
public bool PhaseSendEmail { get; set; }
|
||||
|
||||
public bool PhaseVerify { get; set; }
|
||||
|
||||
public async Task<IActionResult> OnGetAsync()
|
||||
{
|
||||
if (!string.IsNullOrEmpty(Request.Query["secret"]))
|
||||
return await OnPostVerifyAsync(Request.Query["secret"]);
|
||||
LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]);
|
||||
LastError = "";
|
||||
PhaseSendEmail = true;
|
||||
PhaseVerify = false;
|
||||
|
||||
ForgotPasswordViewModel = new UnverifiedSignUpViewModel()
|
||||
{
|
||||
ClientAppName = "وبگاه گنجور",
|
||||
Language = "fa-IR",
|
||||
CallbackUrl = $"{_configuration["SiteUrl"]}/resetpassword"
|
||||
};
|
||||
|
||||
var response = await _httpClient.GetAsync($"{APIRoot.Url}/api/users/captchaimage");
|
||||
response.EnsureSuccessStatusCode();
|
||||
|
||||
ForgotPasswordViewModel.CaptchaImageId = JsonConvert.DeserializeObject<Guid>(await response.Content.ReadAsStringAsync());
|
||||
|
||||
CaptchaImageUrl = $"{APIRoot.InternetUrl}/api/rimages/{ForgotPasswordViewModel.CaptchaImageId}.jpg";
|
||||
|
||||
return Page();
|
||||
}
|
||||
|
||||
public async Task<IActionResult> OnPostSendEmailAsync(UnverifiedSignUpViewModel signUpViewModel)
|
||||
{
|
||||
LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]);
|
||||
LastError = "";
|
||||
PhaseSendEmail = true;
|
||||
PhaseVerify = false;
|
||||
|
||||
var response = await _httpClient.PostAsync($"{APIRoot.Url}/api/users/forgotpassword", new StringContent(JsonConvert.SerializeObject(ForgotPasswordViewModel), Encoding.UTF8, "application/json"));
|
||||
if (!response.IsSuccessStatusCode)
|
||||
{
|
||||
LastError = JsonConvert.DeserializeObject<string>(await response.Content.ReadAsStringAsync());
|
||||
|
||||
response = await _httpClient.GetAsync($"{APIRoot.Url}/api/users/captchaimage");
|
||||
response.EnsureSuccessStatusCode();
|
||||
|
||||
ModelState.Clear();
|
||||
|
||||
ForgotPasswordViewModel = new UnverifiedSignUpViewModel()
|
||||
{
|
||||
ClientAppName = signUpViewModel.ClientAppName,
|
||||
Language = signUpViewModel.Language,
|
||||
CallbackUrl = signUpViewModel.CallbackUrl,
|
||||
Email = signUpViewModel.Email
|
||||
};
|
||||
|
||||
ForgotPasswordViewModel.CaptchaImageId = JsonConvert.DeserializeObject<Guid>(await response.Content.ReadAsStringAsync());
|
||||
CaptchaImageUrl = $"{APIRoot.InternetUrl}/api/rimages/{ForgotPasswordViewModel.CaptchaImageId}.jpg";
|
||||
|
||||
|
||||
return Page();
|
||||
}
|
||||
PhaseSendEmail = false;
|
||||
PhaseVerify = true;
|
||||
|
||||
|
||||
return Page();
|
||||
}
|
||||
|
||||
public async Task<IActionResult> OnPostVerifyAsync(string Secret)
|
||||
{
|
||||
LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]);
|
||||
LastError = "";
|
||||
PhaseSendEmail = false;
|
||||
PhaseVerify = true;
|
||||
|
||||
var response = await _httpClient.GetAsync($"{APIRoot.Url}/api/users/verify?type=1&secret={Secret}");
|
||||
if (!response.IsSuccessStatusCode)
|
||||
{
|
||||
LastError = JsonConvert.DeserializeObject<string>(await response.Content.ReadAsStringAsync());
|
||||
return Page();
|
||||
}
|
||||
|
||||
ResetPasswordViewModel = new ResetPasswordViewModelWithRepPass()
|
||||
{
|
||||
Secret = Secret,
|
||||
Email = JsonConvert.DeserializeObject<string>(await response.Content.ReadAsStringAsync()),
|
||||
Password = "",
|
||||
PasswordConfirmation = ""
|
||||
};
|
||||
|
||||
PhaseVerify = false;
|
||||
|
||||
|
||||
return Page();
|
||||
}
|
||||
|
||||
public async Task<IActionResult> OnPostPhase3Async()
|
||||
{
|
||||
LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]);
|
||||
LastError = "";
|
||||
PhaseSendEmail = false;
|
||||
PhaseVerify = false;
|
||||
|
||||
if (ResetPasswordViewModel.Password != ResetPasswordViewModel.PasswordConfirmation)
|
||||
{
|
||||
LastError = "گذرواژه و تکرار آن یکی نیستند.";
|
||||
return Page();
|
||||
}
|
||||
|
||||
ResetPasswordViewModel postViewModel = new ResetPasswordViewModel()
|
||||
{
|
||||
Email = ResetPasswordViewModel.Email,
|
||||
Secret = ResetPasswordViewModel.Secret,
|
||||
Password = ResetPasswordViewModel.Password
|
||||
};
|
||||
|
||||
var response = await _httpClient.PostAsync($"{APIRoot.Url}/api/users/resetpassword", new StringContent(JsonConvert.SerializeObject(postViewModel), Encoding.UTF8, "application/json"));
|
||||
if (!response.IsSuccessStatusCode)
|
||||
{
|
||||
LastError = JsonConvert.DeserializeObject<string>(await response.Content.ReadAsStringAsync());
|
||||
return Page();
|
||||
}
|
||||
|
||||
|
||||
LoginViewModel loginViewModel = new LoginViewModel()
|
||||
{
|
||||
ClientAppName = "وبگاه گنجور",
|
||||
Language = "fa-IR",
|
||||
Username = postViewModel.Email,
|
||||
Password = postViewModel.Password
|
||||
};
|
||||
|
||||
var stringContent = new StringContent(JsonConvert.SerializeObject(loginViewModel), Encoding.UTF8, "application/json");
|
||||
var loginUrl = $"{APIRoot.Url}/api/users/login";
|
||||
response = await _httpClient.PostAsync(loginUrl, stringContent);
|
||||
|
||||
if (!response.IsSuccessStatusCode)
|
||||
{
|
||||
LastError = JsonConvert.DeserializeObject<string>(await response.Content.ReadAsStringAsync());
|
||||
return Page();
|
||||
}
|
||||
|
||||
LoggedOnUserModel loggedOnUser = JsonConvert.DeserializeObject<LoggedOnUserModel>(await response.Content.ReadAsStringAsync());
|
||||
|
||||
var cookieOption = new CookieOptions()
|
||||
{
|
||||
Expires = DateTime.Now.AddDays(365),
|
||||
};
|
||||
|
||||
Response.Cookies.Append("UserId", loggedOnUser.User.Id.ToString(), cookieOption);
|
||||
Response.Cookies.Append("SessionId", loggedOnUser.SessionId.ToString(), cookieOption);
|
||||
Response.Cookies.Append("Token", loggedOnUser.Token, cookieOption);
|
||||
Response.Cookies.Append("Username", loggedOnUser.User.Username, cookieOption);
|
||||
Response.Cookies.Append("Name", $"{loggedOnUser.User.FirstName} {loggedOnUser.User.SureName}", cookieOption);
|
||||
Response.Cookies.Append("NickName", $"{loggedOnUser.User.NickName}", cookieOption);
|
||||
|
||||
bool canEditContent = false;
|
||||
var ganjoorEntity = loggedOnUser.SecurableItem.Where(s => s.ShortName == RMuseumSecurableItem.GanjoorEntityShortName).SingleOrDefault();
|
||||
if (ganjoorEntity != null)
|
||||
{
|
||||
var op = ganjoorEntity.Operations.Where(o => o.ShortName == SecurableItem.ModifyOperationShortName).SingleOrDefault();
|
||||
if (op != null)
|
||||
{
|
||||
canEditContent = op.Status;
|
||||
}
|
||||
}
|
||||
|
||||
Response.Cookies.Append("CanEdit", canEditContent.ToString(), cookieOption);
|
||||
|
||||
|
||||
|
||||
return Redirect($"{_configuration["SiteUrl"]}/User");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Loading…
Reference in New Issue
Block a user