Remove old password check from changepassword and use verifyUser instead

remotes/origin/stable5
Lukas Reschke 12 years ago committed by Daniel Molkentin
parent 6b39b80648
commit e6b8153865
  1. 3
      settings/ajax/changepassword.php
  2. 5
      settings/templates/personal.php

@ -10,7 +10,6 @@ OC_JSON::verifyUser();
$username = isset($_POST["username"]) ? $_POST["username"] : OC_User::getUser();
$password = $_POST["password"];
$oldPassword=isset($_POST["oldpassword"])?$_POST["oldpassword"]:'';
$userstatus = null;
if(OC_Group::inGroup(OC_User::getUser(), 'admin')) {
@ -19,7 +18,7 @@ if(OC_Group::inGroup(OC_User::getUser(), 'admin')) {
if(OC_SubAdmin::isUserAccessible(OC_User::getUser(), $username)) {
$userstatus = 'subadmin';
}
if(OC_User::getUser() == $username && OC_User::checkPassword($username, $oldPassword)) {
if(OC_User::getUser() == $username) {
$userstatus = 'user';
}

@ -18,9 +18,8 @@
<fieldset class="personalblock">
<div id="passwordchanged"><?php echo $l->t('Your password was changed');?></div>
<div id="passworderror"><?php echo $l->t('Unable to change your password');?></div>
<input type="password" id="pass1" name="oldpassword" placeholder="<?php echo $l->t('Current password');?>" />
<input type="password" id="pass2" name="password" placeholder="<?php echo $l->t('New password');?>" data-typetoggle="#show" />
<input type="checkbox" id="show" name="show" /><label for="show"><?php echo $l->t('show');?></label>
<input type="password" id="pass1" name="password" placeholder="<?php echo $l->t('New password');?>" data-typetoggle="#show" />
<input type="password" id="pass2" name="password" placeholder="<?php echo $l->t('Verify password');?>" data-typetoggle="#show" />
<input id="passwordbutton" type="submit" value="<?php echo $l->t('Change password');?>" />
</fieldset>
</form>

Loading…
Cancel
Save