Files
notifications-admin/app/main/views/new_password.py
T

58 lines
2.0 KiB
Python
Raw Normal View History

2016-03-07 18:18:52 +00:00
import json
2018-02-20 11:22:17 +00:00
from flask import (
current_app,
flash,
redirect,
render_template,
2020-10-09 11:40:28 +01:00
request,
2018-02-20 11:22:17 +00:00
session,
url_for,
)
2016-03-07 18:18:52 +00:00
from itsdangerous import SignatureExpired
from notifications_utils.url_safe_token import check_token
2016-01-05 17:52:09 +00:00
from app.main import main
2016-01-06 17:37:07 +00:00
from app.main.forms import NewPasswordForm
from app.models.user import User
2021-06-14 11:15:57 +01:00
from app.utils.login import log_in_user
2016-01-05 17:52:09 +00:00
2016-01-06 17:37:07 +00:00
@main.route('/new-password/<path:token>', methods=['GET', 'POST'])
def new_password(token):
2016-03-07 18:18:52 +00:00
try:
token_data = check_token(token, current_app.config['SECRET_KEY'], current_app.config['DANGEROUS_SALT'],
current_app.config['EMAIL_EXPIRY_SECONDS'])
2016-03-07 18:18:52 +00:00
except SignatureExpired:
2016-01-08 16:47:34 +00:00
flash('The link in the email we sent you has expired. Enter your email address to resend.')
return redirect(url_for('.forgot_password'))
2016-03-07 18:18:52 +00:00
email_address = json.loads(token_data)['email']
user = User.from_email_address(email_address)
if user.password_changed_more_recently_than(json.loads(token_data)['created_at']):
2016-03-07 18:18:52 +00:00
flash('The link in the email has already been used')
return redirect(url_for('main.index'))
if request.method == 'GET':
user.update_email_access_validated_at()
2016-01-06 17:37:07 +00:00
form = NewPasswordForm()
2016-01-06 17:37:07 +00:00
if form.validate_on_submit():
user.reset_failed_login_count()
2016-01-27 16:30:33 +00:00
session['user_details'] = {
'id': user.id,
'email': user.email_address,
'password': form.new_password.data}
2021-05-12 17:24:47 +01:00
if user.email_auth:
# they've just clicked an email link, so have done an email auth journey anyway. Just log them in.
return log_in_user(user.id)
2021-05-12 17:24:47 +01:00
elif user.webauthn_auth:
return redirect(url_for('main.two_factor_webauthn', next=request.args.get('next')))
else:
# send user a 2fa sms code
user.send_verify_code()
2021-05-14 19:15:12 +01:00
return redirect(url_for('main.two_factor_sms', next=request.args.get('next')))
2016-01-06 17:37:07 +00:00
else:
return render_template('views/new-password.html', token=token, form=form, user=user)