7 "github.com/dchest/passwordreset"
8 "immae.eu/Immae/Projets/Cryptomonnaies/Cryptoportfolio/Front/db"
11 var PASSWORD_RESET_SECRET []byte
13 type PasswordResetQuery struct {
19 func (q PasswordResetQuery) ValidateParams() *Error {
21 return &Error{InvalidEmail, "invalid email", fmt.Errorf("invalid email")}
27 func (q PasswordResetQuery) Run() (interface{}, *Error) {
28 user, err := db.GetUserByEmail(q.In.Email)
30 return nil, NewInternalError(err)
34 return nil, &Error{NotFound, "account not found", fmt.Errorf("'%v' is not registered", q.In.Email)}
37 token := passwordreset.NewToken(q.In.Email, time.Hour*24*1, []byte(user.PasswordHash), PASSWORD_RESET_SECRET)
38 if CONFIG.FreeSMSUser != "" {
39 err := SendSMS(CONFIG.FreeSMSUser, CONFIG.FreeSMSPass, fmt.Sprintf("'%v' request a password reset. Token '/change-password?token=%v'", q.In.Email, token))
41 return nil, NewInternalError(err)
48 type ChangePasswordQuery struct {
55 func (q ChangePasswordQuery) ValidateParams() *Error {
56 if q.In.Password == "" {
57 return &Error{InvalidPassword, "invalid password", fmt.Errorf("invalid password")}
61 return &Error{BadRequest, "invalid token", fmt.Errorf("invalid token")}
67 func (q ChangePasswordQuery) Run() (interface{}, *Error) {
70 email, err := passwordreset.VerifyToken(q.In.Token, func(email string) ([]byte, error) {
72 user, err = db.GetUserByEmail(email)
78 return nil, fmt.Errorf("'%v' is not registered", email)
81 return []byte(user.PasswordHash), nil
83 }, PASSWORD_RESET_SECRET)
85 if err != nil && (err == passwordreset.ErrExpiredToken) {
86 return nil, &Error{BadRequest, "expired token", fmt.Errorf("expired token")}
87 } else if err != nil && (err == passwordreset.ErrMalformedToken || err == passwordreset.ErrWrongSignature) {
88 return nil, &Error{BadRequest, "wrong token", fmt.Errorf("wrong token")}
89 } else if err != nil {
90 return nil, NewInternalError(err)
94 return nil, &Error{BadRequest, "bad request", fmt.Errorf("no user found for email '%v'", email)}
97 err = db.SetPassword(user, q.In.Password)
99 return nil, NewInternalError(err)