X-Git-Url: https://delta.frontaccounting.com/gitweb/?a=blobdiff_plain;f=admin%2Fchange_current_user_password.php;h=1b69e00ec5f7fdea54e09a49ad0be8494c9a83ec;hb=7e6e0807990447d2977b970c3a0fd28dc9250194;hp=4ed37fb012d1f55c2a13e4e1225179a2263a014b;hpb=78fe8cb8f56510ba3f6a1720b207a33b5828e071;p=fa-stable.git diff --git a/admin/change_current_user_password.php b/admin/change_current_user_password.php index 4ed37fb0..1b69e00e 100644 --- a/admin/change_current_user_password.php +++ b/admin/change_current_user_password.php @@ -23,6 +23,18 @@ include_once($path_to_root . "/admin/db/users_db.inc"); function can_process() { + $Auth_Result = hook_authenticate($_SESSION["wa_current_user"]->username, $_POST['cur_password']); + + if (!isset($Auth_Result)) // if not used external login: standard method + $Auth_Result = get_user_auth($_SESSION["wa_current_user"]->username, md5($_POST['cur_password'])); + + if (!$Auth_Result) + { + display_error( _("Invalid password entered.")); + set_focus('cur_password'); + return false; + } + if (strlen($_POST['password']) < 4) { display_error( _("The password entered must be at least 4 characters long.")); @@ -52,7 +64,7 @@ if (isset($_POST['UPDATE_ITEM']) && check_csrf_token()) if (can_process()) { - if ($allow_demo_mode) { + if ($SysPrefs->allow_demo_mode) { display_warning(_("Password cannot be changed in demo mode.")); } else { update_user_password($_SESSION["wa_current_user"]->user, @@ -72,11 +84,13 @@ $myrow = get_user($_SESSION["wa_current_user"]->user); label_row(_("User login:"), $myrow['user_id']); +$_POST['cur_password'] = ""; $_POST['password'] = ""; $_POST['passwordConfirm'] = ""; -password_row(_("Password:"), 'password', $_POST['password']); -password_row(_("Repeat password:"), 'passwordConfirm', $_POST['passwordConfirm']); +password_row(_("Current Password:"), 'cur_password', $_POST['cur_password']); +password_row(_("New Password:"), 'password', $_POST['password']); +password_row(_("Repeat New Password:"), 'passwordConfirm', $_POST['passwordConfirm']); table_section_title(_("Enter your new password in the fields.")); @@ -85,4 +99,3 @@ end_table(1); submit_center( 'UPDATE_ITEM', _('Change password'), true, '', 'default'); end_form(); end_page(); -?>