2016-05-10 22:40:06 +03:00
|
|
|
<?php
|
2016-05-14 02:47:17 +03:00
|
|
|
namespace api\models\authentication;
|
2016-05-10 22:40:06 +03:00
|
|
|
|
2017-04-18 19:08:11 +03:00
|
|
|
use api\components\ReCaptcha\Validator as ReCaptchaValidator;
|
2016-05-10 22:40:06 +03:00
|
|
|
use api\models\base\ApiForm;
|
2017-01-23 23:50:13 +03:00
|
|
|
use api\validators\TotpValidator;
|
2017-04-25 21:00:01 +03:00
|
|
|
use common\emails\EmailHelper;
|
2016-06-16 23:32:23 +03:00
|
|
|
use common\helpers\Error as E;
|
2016-05-10 22:40:06 +03:00
|
|
|
use api\traits\AccountFinder;
|
|
|
|
use common\components\UserFriendlyRandomKey;
|
|
|
|
use common\models\Account;
|
2016-05-10 23:28:04 +03:00
|
|
|
use common\models\confirmations\ForgotPassword;
|
2016-05-10 22:40:06 +03:00
|
|
|
use common\models\EmailActivation;
|
|
|
|
use yii\base\ErrorException;
|
|
|
|
|
|
|
|
class ForgotPasswordForm extends ApiForm {
|
|
|
|
use AccountFinder;
|
|
|
|
|
2017-04-18 19:08:11 +03:00
|
|
|
public $captcha;
|
|
|
|
|
2016-05-10 22:40:06 +03:00
|
|
|
public $login;
|
2017-04-18 19:08:11 +03:00
|
|
|
|
2017-09-06 20:17:52 +03:00
|
|
|
public $totp;
|
2016-05-10 22:40:06 +03:00
|
|
|
|
|
|
|
public function rules() {
|
|
|
|
return [
|
2017-04-18 19:08:11 +03:00
|
|
|
['captcha', ReCaptchaValidator::class],
|
2016-06-16 23:32:23 +03:00
|
|
|
['login', 'required', 'message' => E::LOGIN_REQUIRED],
|
2016-05-10 22:40:06 +03:00
|
|
|
['login', 'validateLogin'],
|
2017-09-06 20:17:52 +03:00
|
|
|
['totp', 'required', 'when' => function(self $model) {
|
2017-01-23 23:50:13 +03:00
|
|
|
return !$this->hasErrors() && $model->getAccount()->is_otp_enabled;
|
2017-09-06 20:17:52 +03:00
|
|
|
}, 'message' => E::TOTP_REQUIRED],
|
|
|
|
['totp', 'validateTotp'],
|
2016-05-10 22:40:06 +03:00
|
|
|
['login', 'validateActivity'],
|
|
|
|
['login', 'validateFrequency'],
|
|
|
|
];
|
|
|
|
}
|
|
|
|
|
|
|
|
public function validateLogin($attribute) {
|
|
|
|
if (!$this->hasErrors()) {
|
|
|
|
if ($this->getAccount() === null) {
|
2016-06-16 23:32:23 +03:00
|
|
|
$this->addError($attribute, E::LOGIN_NOT_EXIST);
|
2016-05-10 22:40:06 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-09-06 20:17:52 +03:00
|
|
|
public function validateTotp($attribute) {
|
2017-01-23 23:50:13 +03:00
|
|
|
if ($this->hasErrors()) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
$account = $this->getAccount();
|
|
|
|
if (!$account->is_otp_enabled) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
$validator = new TotpValidator(['account' => $account]);
|
2017-02-22 01:20:43 +03:00
|
|
|
$validator->window = 1;
|
2017-01-23 23:50:13 +03:00
|
|
|
$validator->validateAttribute($this, $attribute);
|
|
|
|
}
|
|
|
|
|
2016-05-10 22:40:06 +03:00
|
|
|
public function validateActivity($attribute) {
|
|
|
|
if (!$this->hasErrors()) {
|
|
|
|
$account = $this->getAccount();
|
|
|
|
if ($account->status !== Account::STATUS_ACTIVE) {
|
2016-06-16 23:32:23 +03:00
|
|
|
$this->addError($attribute, E::ACCOUNT_NOT_ACTIVATED);
|
2016-05-10 22:40:06 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public function validateFrequency($attribute) {
|
|
|
|
if (!$this->hasErrors()) {
|
|
|
|
$emailConfirmation = $this->getEmailActivation();
|
|
|
|
if ($emailConfirmation !== null && !$emailConfirmation->canRepeat()) {
|
2016-06-16 23:32:23 +03:00
|
|
|
$this->addError($attribute, E::RECENTLY_SENT_MESSAGE);
|
2016-05-10 22:40:06 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public function forgotPassword() {
|
|
|
|
if (!$this->validate()) {
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
$account = $this->getAccount();
|
|
|
|
$emailActivation = $this->getEmailActivation();
|
|
|
|
if ($emailActivation === null) {
|
2016-05-10 23:28:04 +03:00
|
|
|
$emailActivation = new ForgotPassword();
|
2016-05-10 22:40:06 +03:00
|
|
|
$emailActivation->account_id = $account->id;
|
|
|
|
} else {
|
|
|
|
$emailActivation->created_at = time();
|
|
|
|
}
|
|
|
|
|
|
|
|
$emailActivation->key = UserFriendlyRandomKey::make();
|
|
|
|
if (!$emailActivation->save()) {
|
|
|
|
throw new ErrorException('Cannot create email activation for forgot password form');
|
|
|
|
}
|
|
|
|
|
2017-04-21 01:41:43 +03:00
|
|
|
EmailHelper::forgotPassword($emailActivation);
|
2016-05-10 22:40:06 +03:00
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2017-09-19 20:06:16 +03:00
|
|
|
public function getLogin(): string {
|
2016-05-10 22:40:06 +03:00
|
|
|
return $this->login;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @return EmailActivation|null
|
|
|
|
* @throws ErrorException
|
|
|
|
*/
|
|
|
|
public function getEmailActivation() {
|
|
|
|
$account = $this->getAccount();
|
|
|
|
if ($account === null) {
|
|
|
|
throw new ErrorException('Account not founded');
|
|
|
|
}
|
|
|
|
|
|
|
|
return $account->getEmailActivations()
|
|
|
|
->andWhere(['type' => EmailActivation::TYPE_FORGOT_PASSWORD_KEY])
|
|
|
|
->one();
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|