Bug 21993: Display a user-friendly message when the CSRF token is wrong
[koha.git] / members / member-password.pl
index 0290b8d..013e7e5 100755 (executable)
@@ -4,24 +4,23 @@
 #by chris@katipo.co.nz
 #converted to using templates 3/16/03 by mwhansen@hmc.edu
 
-use strict;
-use warnings;
+use Modern::Perl;
 
 use C4::Auth;
 use Koha::AuthUtils;
 use C4::Output;
 use C4::Context;
 use C4::Members;
-use C4::Branch;
 use C4::Circulation;
 use CGI qw ( -utf8 );
 use C4::Members::Attributes qw(GetBorrowerAttributes);
-use Koha::Patron::Images;
+use Koha::AuthUtils;
 use Koha::Token;
 
+use Koha::Patrons;
 use Koha::Patron::Categories;
 
-use Digest::MD5 qw(md5_base64);
+use Try::Tiny;
 
 my $input = new CGI;
 
@@ -35,25 +34,26 @@ my ( $template, $loggedinuser, $cookie, $staffflags ) = get_template_and_user(
         query           => $input,
         type            => "intranet",
         authnotrequired => 0,
-        flagsrequired   => { borrowers => 1 },
+        flagsrequired   => { borrowers => 'edit_borrowers' },
         debug           => 1,
     }
 );
 
-my $flagsrequired;
-$flagsrequired->{borrowers} = 1;
-
-my $member      = $input->param('member');
-my $cardnumber  = $input->param('cardnumber');
-my $destination = $input->param('destination');
+my $patron_id    = $input->param('member');
+my $destination  = $input->param('destination');
 my $newpassword  = $input->param('newpassword');
 my $newpassword2 = $input->param('newpassword2');
+my $new_user_id  = $input->param('newuserid');
 
 my @errors;
 
-my ($bor) = GetMember( 'borrowernumber' => $member );
+my $logged_in_user = Koha::Patrons->find( $loggedinuser ) or die "Not logged in";
+my $patron = Koha::Patrons->find( $patron_id );
+output_and_exit_if_error( $input, $cookie, $template, { module => 'members', logged_in_user => $logged_in_user, current_patron => $patron } );
+
+my $category_type = $patron->category->category_type;
 
-if ( ( $member ne $loggedinuser ) && ( $bor->{'category_type'} eq 'S' ) ) {
+if ( ( $patron_id ne $loggedinuser ) && ( $category_type eq 'S' ) ) {
     push( @errors, 'NOPERMISSION' )
       unless ( $staffflags->{'superlibrarian'} || $staffflags->{'staffaccess'} );
 
@@ -62,60 +62,44 @@ if ( ( $member ne $loggedinuser ) && ( $bor->{'category_type'} eq 'S' ) ) {
 
 push( @errors, 'NOMATCH' ) if ( ( $newpassword && $newpassword2 ) && ( $newpassword ne $newpassword2 ) );
 
-my $minpw = C4::Context->preference('minPasswordLength');
-push( @errors, 'SHORTPASSWORD' ) if ( $newpassword && $minpw && ( length($newpassword) < $minpw ) );
+if ( $newpassword and not @errors) {
 
-if ( $newpassword && !scalar(@errors) ) {
-
-    die "Wrong CSRF token"
+    output_and_exit( $input, $cookie, $template,  'wrong_csrf_token' )
         unless Koha::Token->new->check_csrf({
-            id     => C4::Context->userenv->{id},
-            secret => md5_base64( C4::Context->config('pass') ),
+            session_id => scalar $input->cookie('CGISESSID'),
             token  => scalar $input->param('csrf_token'),
         });
 
-    my $digest = Koha::AuthUtils::hash_password( $input->param('newpassword') );
-    my $uid    = $input->param('newuserid') || $bor->{userid};
-    my $dbh    = C4::Context->dbh;
-    if ( Koha::Patrons->find( $member )->update_password($uid, $digest) ) {
+    try {
+        $patron->set_password({ password => $newpassword });
+        $patron->userid($new_user_id)->store
+            if $new_user_id and $new_user_id ne $patron->userid;
         $template->param( newpassword => $newpassword );
         if ( $destination eq 'circ' ) {
-            print $input->redirect("/cgi-bin/koha/circ/circulation.pl?findborrower=$cardnumber");
+            print $input->redirect("/cgi-bin/koha/circ/circulation.pl?findborrower=" . $patron->cardnumber);
         }
         else {
-            print $input->redirect("/cgi-bin/koha/members/moremember.pl?borrowernumber=$member");
+            print $input->redirect("/cgi-bin/koha/members/moremember.pl?borrowernumber=$patron_id");
         }
     }
-    else {
-        push( @errors, 'BADUSERID' );
-    }
-}
-else {
-    my $userid = $bor->{'userid'};
-
-    my $chars              = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789';
-    my $length             = int( rand(2) ) + C4::Context->preference("minPasswordLength");
-    my $defaultnewpassword = '';
-    for ( my $i = 0 ; $i < $length ; $i++ ) {
-        $defaultnewpassword .= substr( $chars, int( rand( length($chars) ) ), 1 );
-    }
-
-    $template->param( defaultnewpassword => $defaultnewpassword );
-}
-
-if ( $bor->{'category_type'} eq 'C') {
-    my $patron_categories = Koha::Patron::Categories->search_limited({ category_type => 'A' }, {order_by => ['categorycode']});
-    $template->param( 'CATCODE_MULTI' => 1) if $patron_categories->count > 1;
-    $template->param( 'catcode' => $patron_categories->next )  if $patron_categories->count == 1;
+    catch {
+        if ( $_->isa('Koha::Exceptions::Password::TooShort') ) {
+            push @errors, 'ERROR_password_too_short';
+        }
+        elsif ( $_->isa('Koha::Exceptions::Password::WhitespaceCharacters') ) {
+            push @errors, 'ERROR_password_has_whitespaces';
+        }
+        elsif ( $_->isa('Koha::Exceptions::Password::TooWeak') ) {
+            push @errors, 'ERROR_password_too_weak';
+        }
+        else {
+            push( @errors, 'BADUSERID' );
+        }
+    };
 }
 
-$template->param( adultborrower => 1 ) if ( $bor->{'category_type'} eq 'A' );
-
-my $patron_image = Koha::Patron::Images->find($bor->{borrowernumber});
-$template->param( picture => 1 ) if $patron_image;
-
 if ( C4::Context->preference('ExtendedPatronAttributes') ) {
-    my $attributes = GetBorrowerAttributes( $bor->{'borrowernumber'} );
+    my $attributes = GetBorrowerAttributes( $patron_id );
     $template->param(
         ExtendedPatronAttributes => 1,
         extendedattributes       => $attributes
@@ -123,37 +107,9 @@ if ( C4::Context->preference('ExtendedPatronAttributes') ) {
 }
 
 $template->param(
-    othernames                 => $bor->{'othernames'},
-    surname                    => $bor->{'surname'},
-    firstname                  => $bor->{'firstname'},
-    borrowernumber             => $bor->{'borrowernumber'},
-    cardnumber                 => $bor->{'cardnumber'},
-    categorycode               => $bor->{'categorycode'},
-    category_type              => $bor->{'category_type'},
-    categoryname               => $bor->{'description'},
-    address                    => $bor->{address},
-    address2                   => $bor->{'address2'},
-    streettype                 => $bor->{streettype},
-    city                       => $bor->{'city'},
-    state                      => $bor->{'state'},
-    zipcode                    => $bor->{'zipcode'},
-    country                    => $bor->{'country'},
-    phone                      => $bor->{'phone'},
-    phonepro                   => $bor->{'phonepro'},
-    mobile                     => $bor->{'mobile'},
-    email                      => $bor->{'email'},
-    emailpro                   => $bor->{'emailpro'},
-    branchcode                 => $bor->{'branchcode'},
-    userid                     => $bor->{'userid'},
-    destination                => $destination,
-    is_child                   => ( $bor->{'category_type'} eq 'C' ),
-    activeBorrowerRelationship => ( C4::Context->preference('borrowerRelationship') ne '' ),
-    minPasswordLength          => $minpw,
-    RoutingSerials             => C4::Context->preference('RoutingSerials'),
-    csrf_token                 => Koha::Token->new->generate_csrf({
-        id     => C4::Context->userenv->{id},
-        secret => md5_base64( C4::Context->config('pass') ),
-    }),
+    patron      => $patron,
+    destination => $destination,
+    csrf_token  => Koha::Token->new->generate_csrf({ session_id => scalar $input->cookie('CGISESSID'), }),
 );
 
 if ( scalar(@errors) ) {