diff --git a/GanjooRazor/Models/ResetPasswordViewModelWithRepPass.cs b/GanjooRazor/Models/ResetPasswordViewModelWithRepPass.cs new file mode 100644 index 00000000..0f41c721 --- /dev/null +++ b/GanjooRazor/Models/ResetPasswordViewModelWithRepPass.cs @@ -0,0 +1,15 @@ +using RSecurityBackend.Models.Auth.ViewModels; + +namespace GanjooRazor.Models +{ + /// + /// ResetPasswordViewModel with PasswordConfirmation field + /// + public class ResetPasswordViewModelWithRepPass : ResetPasswordViewModel + { + /// + /// password confirmation + /// + public string PasswordConfirmation { get; set; } + } +} diff --git a/GanjooRazor/Models/VerifiedSignUpViewModelWithRepPass.cs b/GanjooRazor/Models/VerifiedSignUpViewModelWithRepPass.cs index 415f80d4..0bcd8173 100644 --- a/GanjooRazor/Models/VerifiedSignUpViewModelWithRepPass.cs +++ b/GanjooRazor/Models/VerifiedSignUpViewModelWithRepPass.cs @@ -3,7 +3,7 @@ namespace GanjooRazor.Models { /// - /// erifiedSignUpViewModel with PasswordConfirmation + /// VerifiedSignUpViewModel with PasswordConfirmation field /// public class VerifiedSignUpViewModelWithRepPass : VerifiedSignUpViewModel { diff --git a/GanjooRazor/Pages/ResetPassword.cshtml b/GanjooRazor/Pages/ResetPassword.cshtml index df7a4e00..d0944779 100644 --- a/GanjooRazor/Pages/ResetPassword.cshtml +++ b/GanjooRazor/Pages/ResetPassword.cshtml @@ -24,8 +24,9 @@ } else + if (Model.PhaseSendEmail) { -
+ @@ -48,10 +49,10 @@ @@ -66,7 +67,7 @@ عدد تصویر امنیتی: @@ -75,9 +76,71 @@
@@ -39,7 +40,7 @@ پست الکترونیکی: - +
- - - - + + + +
- +

@Model.LastError

- } + else + if (Model.PhaseVerify) + { +
+ + + + + + + + + + + + +
+

لطفا پست الکترونیکی خود را بررسی کنید. در صورتی که نشانی پست الکترونیکی خود را درست وارد کرده باشید نامه‌ای از گنجور دریافت کرده‌اید که حاوی یک رمز است.

+

رمز دریافتی را در کادر زیر وارد کرده، روی دکمهٔ «ادامه» کلیک کنید

+

تذکر: ممکن است نامه به پوشه اسپم منتقل شده باشد

+
+ رمز دریافتی: + + +
برگشت
+

@Model.LastError

+
+ } + else + { +
+ + + + + + + + + + + + + + + +
+ گذرواژه: + + +
+ تکرار گذرواژه: + + +
+ + +

گذرواژه باید دست کم شامل ۶ حرف باشد و از ترکیبی از اعداد و حروف انگلیسی تشکیل شده باشد.

+

حروف و اعداد نباید تکراری باشند و وجود حداقل یک عدد و یک حرف کوچک انگلیسی در گذرواژه الزامی است

+
+

@Model.LastError

+
+ } diff --git a/GanjooRazor/Pages/ResetPassword.cshtml.cs b/GanjooRazor/Pages/ResetPassword.cshtml.cs index 3bd66aa2..9da1f6d7 100644 --- a/GanjooRazor/Pages/ResetPassword.cshtml.cs +++ b/GanjooRazor/Pages/ResetPassword.cshtml.cs @@ -1,20 +1,229 @@ - + +using GanjooRazor.Models; +using Microsoft.AspNetCore.Http; +using Microsoft.AspNetCore.Mvc; using Microsoft.AspNetCore.Mvc.RazorPages; +using Microsoft.Extensions.Configuration; +using Newtonsoft.Json; +using RMuseum.Models.Auth.Memory; +using RSecurityBackend.Models.Auth.Memory; using RSecurityBackend.Models.Auth.ViewModels; +using System; +using System.Linq; +using System.Net.Http; +using System.Text; +using System.Threading.Tasks; namespace GanjooRazor.Pages { + [IgnoreAntiforgeryToken(Order = 1001)] public class ResetPasswordModel : PageModel { + /// + /// HttpClient instance + /// + private readonly HttpClient _httpClient; + + /// + /// configuration + /// + private readonly IConfiguration _configuration; + + public ResetPasswordModel(HttpClient httpClient, IConfiguration configuration) + { + _httpClient = httpClient; + _configuration = configuration; + } + + public bool LoggedIn { get; set; } public string LastError { get; set; } - public UnverifiedSignUpViewModel SignUpViewModel { get; set; } + [BindProperty] + public UnverifiedSignUpViewModel ForgotPasswordViewModel { get; set; } + + [BindProperty] + public string Secret { get; set; } + + + [BindProperty] + public ResetPasswordViewModelWithRepPass ResetPasswordViewModel { get; set; } public string CaptchaImageUrl { get; set; } - public void OnGet() + + public bool PhaseSendEmail { get; set; } + + public bool PhaseVerify { get; set; } + + public async Task OnGetAsync() { + if (!string.IsNullOrEmpty(Request.Query["secret"])) + return await OnPostVerifyAsync(Request.Query["secret"]); + LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]); + LastError = ""; + PhaseSendEmail = true; + PhaseVerify = false; + + ForgotPasswordViewModel = new UnverifiedSignUpViewModel() + { + ClientAppName = "وبگاه گنجور", + Language = "fa-IR", + CallbackUrl = $"{_configuration["SiteUrl"]}/resetpassword" + }; + + var response = await _httpClient.GetAsync($"{APIRoot.Url}/api/users/captchaimage"); + response.EnsureSuccessStatusCode(); + + ForgotPasswordViewModel.CaptchaImageId = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); + + CaptchaImageUrl = $"{APIRoot.InternetUrl}/api/rimages/{ForgotPasswordViewModel.CaptchaImageId}.jpg"; + + return Page(); + } + + public async Task OnPostSendEmailAsync(UnverifiedSignUpViewModel signUpViewModel) + { + LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]); + LastError = ""; + PhaseSendEmail = true; + PhaseVerify = false; + + var response = await _httpClient.PostAsync($"{APIRoot.Url}/api/users/forgotpassword", new StringContent(JsonConvert.SerializeObject(ForgotPasswordViewModel), Encoding.UTF8, "application/json")); + if (!response.IsSuccessStatusCode) + { + LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); + + response = await _httpClient.GetAsync($"{APIRoot.Url}/api/users/captchaimage"); + response.EnsureSuccessStatusCode(); + + ModelState.Clear(); + + ForgotPasswordViewModel = new UnverifiedSignUpViewModel() + { + ClientAppName = signUpViewModel.ClientAppName, + Language = signUpViewModel.Language, + CallbackUrl = signUpViewModel.CallbackUrl, + Email = signUpViewModel.Email + }; + + ForgotPasswordViewModel.CaptchaImageId = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); + CaptchaImageUrl = $"{APIRoot.InternetUrl}/api/rimages/{ForgotPasswordViewModel.CaptchaImageId}.jpg"; + + + return Page(); + } + PhaseSendEmail = false; + PhaseVerify = true; + + + return Page(); + } + + public async Task OnPostVerifyAsync(string Secret) + { + LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]); + LastError = ""; + PhaseSendEmail = false; + PhaseVerify = true; + + var response = await _httpClient.GetAsync($"{APIRoot.Url}/api/users/verify?type=1&secret={Secret}"); + if (!response.IsSuccessStatusCode) + { + LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); + return Page(); + } + + ResetPasswordViewModel = new ResetPasswordViewModelWithRepPass() + { + Secret = Secret, + Email = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()), + Password = "", + PasswordConfirmation = "" + }; + + PhaseVerify = false; + + + return Page(); + } + + public async Task OnPostPhase3Async() + { + LoggedIn = !string.IsNullOrEmpty(Request.Cookies["Name"]); + LastError = ""; + PhaseSendEmail = false; + PhaseVerify = false; + + if (ResetPasswordViewModel.Password != ResetPasswordViewModel.PasswordConfirmation) + { + LastError = "گذرواژه و تکرار آن یکی نیستند."; + return Page(); + } + + ResetPasswordViewModel postViewModel = new ResetPasswordViewModel() + { + Email = ResetPasswordViewModel.Email, + Secret = ResetPasswordViewModel.Secret, + Password = ResetPasswordViewModel.Password + }; + + var response = await _httpClient.PostAsync($"{APIRoot.Url}/api/users/resetpassword", new StringContent(JsonConvert.SerializeObject(postViewModel), Encoding.UTF8, "application/json")); + if (!response.IsSuccessStatusCode) + { + LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); + return Page(); + } + + + LoginViewModel loginViewModel = new LoginViewModel() + { + ClientAppName = "وبگاه گنجور", + Language = "fa-IR", + Username = postViewModel.Email, + Password = postViewModel.Password + }; + + var stringContent = new StringContent(JsonConvert.SerializeObject(loginViewModel), Encoding.UTF8, "application/json"); + var loginUrl = $"{APIRoot.Url}/api/users/login"; + response = await _httpClient.PostAsync(loginUrl, stringContent); + + if (!response.IsSuccessStatusCode) + { + LastError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); + return Page(); + } + + LoggedOnUserModel loggedOnUser = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); + + var cookieOption = new CookieOptions() + { + Expires = DateTime.Now.AddDays(365), + }; + + Response.Cookies.Append("UserId", loggedOnUser.User.Id.ToString(), cookieOption); + Response.Cookies.Append("SessionId", loggedOnUser.SessionId.ToString(), cookieOption); + Response.Cookies.Append("Token", loggedOnUser.Token, cookieOption); + Response.Cookies.Append("Username", loggedOnUser.User.Username, cookieOption); + Response.Cookies.Append("Name", $"{loggedOnUser.User.FirstName} {loggedOnUser.User.SureName}", cookieOption); + Response.Cookies.Append("NickName", $"{loggedOnUser.User.NickName}", cookieOption); + + bool canEditContent = false; + var ganjoorEntity = loggedOnUser.SecurableItem.Where(s => s.ShortName == RMuseumSecurableItem.GanjoorEntityShortName).SingleOrDefault(); + if (ganjoorEntity != null) + { + var op = ganjoorEntity.Operations.Where(o => o.ShortName == SecurableItem.ModifyOperationShortName).SingleOrDefault(); + if (op != null) + { + canEditContent = op.Status; + } + } + + Response.Cookies.Append("CanEdit", canEditContent.ToString(), cookieOption); + + + + return Redirect($"{_configuration["SiteUrl"]}/User"); } } }