2023-09-05 09:33:46 +00:00
|
|
|
use actix_web::web::{Data, Json};
|
2022-04-13 18:12:25 +00:00
|
|
|
use bcrypt::verify;
|
|
|
|
use lemmy_api_common::{
|
2022-11-28 14:29:33 +00:00
|
|
|
context::LemmyContext,
|
2022-04-13 18:12:25 +00:00
|
|
|
person::{ChangePassword, LoginResponse},
|
2023-09-21 10:42:28 +00:00
|
|
|
utils::password_length_check,
|
2022-04-13 18:12:25 +00:00
|
|
|
};
|
|
|
|
use lemmy_db_schema::source::local_user::LocalUser;
|
2023-09-21 10:42:28 +00:00
|
|
|
use lemmy_db_views::structs::LocalUserView;
|
2023-07-10 14:50:07 +00:00
|
|
|
use lemmy_utils::{
|
|
|
|
claims::Claims,
|
|
|
|
error::{LemmyError, LemmyErrorType},
|
|
|
|
};
|
2022-04-13 18:12:25 +00:00
|
|
|
|
2023-09-05 09:33:46 +00:00
|
|
|
#[tracing::instrument(skip(context))]
|
|
|
|
pub async fn change_password(
|
|
|
|
data: Json<ChangePassword>,
|
|
|
|
context: Data<LemmyContext>,
|
2023-09-21 10:42:28 +00:00
|
|
|
local_user_view: LocalUserView,
|
2023-09-05 09:33:46 +00:00
|
|
|
) -> Result<Json<LoginResponse>, LemmyError> {
|
|
|
|
password_length_check(&data.new_password)?;
|
2022-04-13 18:12:25 +00:00
|
|
|
|
2023-09-05 09:33:46 +00:00
|
|
|
// Make sure passwords match
|
|
|
|
if data.new_password != data.new_password_verify {
|
|
|
|
Err(LemmyErrorType::PasswordsDoNotMatch)?
|
|
|
|
}
|
2022-04-13 18:12:25 +00:00
|
|
|
|
2023-09-05 09:33:46 +00:00
|
|
|
// Check the old password
|
|
|
|
let valid: bool = verify(
|
|
|
|
&data.old_password,
|
|
|
|
&local_user_view.local_user.password_encrypted,
|
|
|
|
)
|
|
|
|
.unwrap_or(false);
|
|
|
|
if !valid {
|
|
|
|
Err(LemmyErrorType::IncorrectLogin)?
|
|
|
|
}
|
2022-04-13 18:12:25 +00:00
|
|
|
|
2023-09-05 09:33:46 +00:00
|
|
|
let local_user_id = local_user_view.local_user.id;
|
|
|
|
let new_password = data.new_password.clone();
|
|
|
|
let updated_local_user =
|
|
|
|
LocalUser::update_password(&mut context.pool(), local_user_id, &new_password).await?;
|
2022-04-13 18:12:25 +00:00
|
|
|
|
2023-09-05 09:33:46 +00:00
|
|
|
// Return the jwt
|
|
|
|
Ok(Json(LoginResponse {
|
|
|
|
jwt: Some(
|
|
|
|
Claims::jwt(
|
|
|
|
updated_local_user.id.0,
|
|
|
|
&context.secret().jwt_secret,
|
|
|
|
&context.settings().hostname,
|
|
|
|
)?
|
|
|
|
.into(),
|
|
|
|
),
|
|
|
|
verify_email_sent: false,
|
|
|
|
registration_created: false,
|
|
|
|
}))
|
2022-04-13 18:12:25 +00:00
|
|
|
}
|