dolibarr 21.0.0-alpha
passwordreset.tpl.php
1<?php
2/* Copyright (C) 2022 Laurent Destailleur <eldy@users.sourceforge.net>
3 * Copyright (C) 2024 Frédéric France <frederic.france@free.fr>
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 3 of the License, or
8 * (at your option) any later version.
9 *
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 *
15 * You should have received a copy of the GNU General Public License
16 * along with this program. If not, see <https://www.gnu.org/licenses/>.
17 */
18
19// Page called to validate a password change
20// To show this page, we need parameters: setnewpassword=1&username=...&passworduidhash=...
21
22if (!defined('NOBROWSERNOTIF')) {
23 define('NOBROWSERNOTIF', 1);
24}
25
26// Protection to avoid direct call of template
27if (empty($conf) || !is_object($conf)) {
28 print "Error, template page can't be called as URL";
29 exit(1);
30}
31
32// DDOS protection
33$size = (int) $_SERVER['CONTENT_LENGTH'];
34if ($size > 10000) {
35 $langs->loadLangs(array("errors", "install"));
36 httponly_accessforbidden('<center>'.$langs->trans("ErrorRequestTooLarge").'<br><a href="'.DOL_URL_ROOT.'">'.$langs->trans("ClickHereToGoToApp").'</a></center>', 413, 1);
37}
38
39require_once DOL_DOCUMENT_ROOT.'/core/lib/functions2.lib.php';
40
41header('Cache-Control: Public, must-revalidate');
42
43if (GETPOST('dol_hide_topmenu')) {
44 $conf->dol_hide_topmenu = 1;
45}
46if (GETPOST('dol_hide_leftmenu')) {
47 $conf->dol_hide_leftmenu = 1;
48}
49if (GETPOST('dol_optimize_smallscreen')) {
50 $conf->dol_optimize_smallscreen = 1;
51}
52if (GETPOST('dol_no_mouse_hover')) {
53 $conf->dol_no_mouse_hover = 1;
54}
55if (GETPOST('dol_use_jmobile')) {
56 $conf->dol_use_jmobile = 1;
57}
58
59// If we force to use jmobile, then we reenable javascript
60if (!empty($conf->dol_use_jmobile)) {
61 $conf->use_javascript_ajax = 1;
62}
63
64$php_self = $_SERVER['PHP_SELF'];
65$php_self .= dol_escape_htmltag($_SERVER["QUERY_STRING"]) ? '?'.dol_escape_htmltag($_SERVER["QUERY_STRING"]) : '';
66$php_self = str_replace('action=validatenewpassword', '', $php_self);
67
68$titleofpage = $langs->trans('ResetPassword');
69
70// Javascript code on logon page only to detect user tz, dst_observed, dst_first, dst_second
71$arrayofjs = array();
72
73$disablenofollow = 1;
74if (!preg_match('/'.constant('DOL_APPLICATION_TITLE').'/', $title)) {
75 $disablenofollow = 0;
76}
77if (getDolGlobalString('MAIN_OPTIMIZEFORTEXTBROWSER')) {
78 $disablenofollow = 0;
79}
80
81top_htmlhead('', $titleofpage, 0, 0, $arrayofjs, array(), 1, $disablenofollow);
82
83
84$colorbackhmenu1 = '60,70,100'; // topmenu
85if (!isset($conf->global->THEME_ELDY_TOPMENU_BACK1)) {
86 $conf->global->THEME_ELDY_TOPMENU_BACK1 = $colorbackhmenu1;
87}
88$colorbackhmenu1 = getDolUserString('THEME_ELDY_ENABLE_PERSONALIZED') ? getDolUserString('THEME_ELDY_TOPMENU_BACK1', $colorbackhmenu1) : getDolGlobalString('THEME_ELDY_TOPMENU_BACK1', $colorbackhmenu1);
89$colorbackhmenu1 = implode(',', colorStringToArray($colorbackhmenu1)); // Normalize value to 'x,y,z'
90
91
92$edituser = new User($db);
93
94
95// Validate parameters
96if ($setnewpassword && $username && $passworduidhash) {
97 $result = $edituser->fetch(0, $username);
98 if ($result < 0) {
99 $message = '<div class="error">'.dol_escape_htmltag($langs->trans("ErrorTechnicalError")).'</div>';
100 } else {
101 global $conf;
102
103 //print $edituser->pass_temp.'-'.$edituser->id.'-'.$conf->file->instance_unique_id.' '.$passworduidhash;
104 if ($edituser->pass_temp && dol_verifyHash($edituser->pass_temp.'-'.$edituser->id.'-'.$conf->file->instance_unique_id, $passworduidhash)) {
105 // Clear session
106 unset($_SESSION['dol_login']);
107
108 // Parameters to reset the user are validated
109 } else {
110 $langs->load("errors");
111 $message = '<div class="error">'.$langs->trans("ErrorFailedToValidatePasswordReset").'</div>';
112 }
113 }
114} else {
115 $langs->load("errors");
116 $message = '<div class="error">'.$langs->trans("ErrorFailedToValidatePasswordReset").'</div>';
117}
118
119
120?>
121<!-- BEGIN PHP TEMPLATE PASSWORDRESET.TPL.PHP -->
122
123<body class="body bodylogin"<?php print !getDolGlobalString('MAIN_LOGIN_BACKGROUND') ? '' : ' style="background-size: cover; background-position: center center; background-attachment: fixed; background-repeat: no-repeat; background-image: url(\''.DOL_URL_ROOT.'/viewimage.php?cache=1&noalt=1&modulepart=mycompany&file='.urlencode('logos/' . getDolGlobalString('MAIN_LOGIN_BACKGROUND')).'\')"'; ?>>
124
125<?php if (empty($conf->dol_use_jmobile)) { ?>
126<script>
127$(document).ready(function () {
128 // Set focus on correct field
129 <?php if ($focus_element) {
130 ?>$('#<?php echo $focus_element; ?>').focus(); <?php
131 } ?> // Warning to use this only on visible element
132});
133</script>
134<?php } ?>
135
136
137<div class="login_center center"<?php
138if (!getDolGlobalString('ADD_UNSPLASH_LOGIN_BACKGROUND')) {
139 $backstyle = 'background: linear-gradient('.($conf->browser->layout == 'phone' ? '0deg' : '4deg').', rgb(240,240,240) 52%, rgb('.$colorbackhmenu1.') 52.1%);';
140 // old style: $backstyle = 'background-image: linear-gradient(rgb('.$colorbackhmenu1.',0.3), rgb(240,240,240));';
141 $backstyle = getDolGlobalString('MAIN_LOGIN_BACKGROUND_STYLE', $backstyle);
142 print !getDolGlobalString('MAIN_LOGIN_BACKGROUND') ? ' style="background-size: cover; background-position: center center; background-attachment: fixed; background-repeat: no-repeat; '.$backstyle.'"' : '';
143}
144?>>
145<div class="login_vertical_align">
146
147<form id="login" name="login" method="POST" action="<?php echo $php_self; ?>">
148<input type="hidden" name="token" value="<?php echo newToken(); ?>">
149<input type="hidden" name="action" value="buildnewpassword">
150
151
152<!-- Title with version -->
153<div class="login_table_title center" title="<?php echo dol_escape_htmltag($title); ?>">
154<?php
155if (!empty($disablenofollow)) {
156 echo '<a class="login_table_title" href="https://www.dolibarr.org" target="_blank" rel="noopener noreferrer external">';
157}
158echo dol_escape_htmltag($title);
159if (!empty($disablenofollow)) {
160 echo '</a>';
161}
162?>
163</div>
164
165
166
167<div class="login_table">
168
169<div id="login_line1">
170
171<div id="login_left">
172<img alt="" title="" src="<?php echo $urllogo; ?>" id="img_logo" />
173</div>
174
175<br>
176
177<div id="login_right">
178
179<div class="tagtable centpercent" title="Login pass" >
180
181<!-- New pass 1 -->
182<div class="trinputlogin">
183<div class="tagtd nowraponall center valignmiddle tdinputlogin">
184<!-- <span class="span-icon-user">-->
185<span class="fa fa-user"></span>
186<input type="text" maxlength="255" placeholder="<?php echo $langs->trans("NewPassword"); ?>" <?php echo $disabled; ?> id="newpass1" name="newpass1" class="flat input-icon-user minwidth150" value="<?php echo dol_escape_htmltag($newpass1); ?>" tabindex="1" autofocus />
187</div>
188</div>
189<div class="trinputlogin">
190<div class="tagtd nowraponall center valignmiddle tdinputlogin">
191<!-- <span class="span-icon-user">-->
192<span class="fa fa-user"></span>
193<input type="text" maxlength="255" placeholder="<?php echo $langs->trans("PasswordRetype"); ?>" <?php echo $disabled; ?> id="newpass2" name="newpass2" class="flat input-icon-user minwidth150" value="<?php echo dol_escape_htmltag($newpass2); ?>" tabindex="1" />
194</div>
195</div>
196
197
198<?php
199$captcha = 0;
200if (!empty($captcha)) {
201 // Add a variable param to force not using cache (jmobile)
202 $php_self = preg_replace('/[&\?]time=(\d+)/', '', $php_self); // Remove param time
203 if (preg_match('/\?/', $php_self)) {
204 $php_self .= '&time='.dol_print_date(dol_now(), 'dayhourlog');
205 } else {
206 $php_self .= '?time='.dol_print_date(dol_now(), 'dayhourlog');
207 }
208 // TODO: provide accessible captcha variants?>
209 <!-- Captcha -->
210 <div class="trinputlogin">
211 <div class="tagtd tdinputlogin nowrap none valignmiddle">
212
213 <span class="fa fa-unlock"></span>
214 <span class="nofa inline-block">
215 <input id="securitycode" placeholder="<?php echo $langs->trans("SecurityCode"); ?>" class="flat input-icon-security width125" type="text" maxlength="5" name="code" tabindex="3" autocomplete="off" />
216 </span>
217 <span class="nowrap inline-block">
218 <img class="inline-block valignmiddle" src="<?php echo DOL_URL_ROOT ?>/core/antispamimage.php" border="0" width="80" height="32" id="img_securitycode" />
219 <a class="inline-block valignmiddle" href="<?php echo $php_self; ?>" tabindex="4"><?php echo $captcha_refresh; ?></a>
220 </span>
221
222 </div></div>
223 <?php
224}
225
226if (!empty($morelogincontent)) {
227 if (is_array($morelogincontent)) {
228 foreach ($morelogincontent as $format => $option) {
229 if ($format == 'table') {
230 echo '<!-- Option by hook -->';
231 echo $option;
232 }
233 }
234 } else {
235 echo '<!-- Option by hook -->';
236 echo $morelogincontent;
237 }
238}
239?>
240
241</div>
242
243</div> <!-- end div login_right -->
244
245</div> <!-- end div login_line1 -->
246
247
248<div id="login_line2" style="clear: both">
249
250<!-- Button "Regenerate and Send password" -->
251<br><input type="submit" <?php echo $disabled; ?> class="button small" name="button_password" value="<?php echo $langs->trans('Save'); ?>" tabindex="4" />
252
253<br>
254<div class="center" style="margin-top: 15px;">
255 <?php
256 $moreparam = '';
257 if (!empty($conf->dol_hide_topmenu)) {
258 $moreparam .= (strpos($moreparam, '?') === false ? '?' : '&').'dol_hide_topmenu='.$conf->dol_hide_topmenu;
259 }
260 if (!empty($conf->dol_hide_leftmenu)) {
261 $moreparam .= (strpos($moreparam, '?') === false ? '?' : '&').'dol_hide_leftmenu='.$conf->dol_hide_leftmenu;
262 }
263 if (!empty($conf->dol_no_mouse_hover)) {
264 $moreparam .= (strpos($moreparam, '?') === false ? '?' : '&').'dol_no_mouse_hover='.$conf->dol_no_mouse_hover;
265 }
266 if (!empty($conf->dol_use_jmobile)) {
267 $moreparam .= (strpos($moreparam, '?') === false ? '?' : '&').'dol_use_jmobile='.$conf->dol_use_jmobile;
268 }
269
270 print '<a class="alogin" href="'.$dol_url_root.'/index.php'.$moreparam.'">'.$langs->trans('BackToLoginPage').'</a>';
271 ?>
272</div>
273
274</div>
275
276</div>
277
278</form>
279
280
281<?php
282if ($mode == 'dolibarr' || !$disabled) {
283 if (empty($message)) {
284 print '<div class="center login_main_home divpasswordmessagedesc paddingtopbottom'.(!getDolGlobalString('MAIN_LOGIN_BACKGROUND') ? '' : ' backgroundsemitransparent boxshadow').'" style="max-width: 70%">';
285 print '<span class="passwordmessagedesc opacitymedium">';
286 print $langs->trans('EnterNewPasswordHere');
287 print '</span>';
288 print '</div>';
289 }
290} else {
291 print '<div class="center login_main_home divpasswordmessagedesc paddingtopbottom'.(!getDolGlobalString('MAIN_LOGIN_BACKGROUND') ? '' : ' backgroundsemitransparent boxshadow').'" style="max-width: 70%">';
292 print '<div class="warning center">';
293 print $langs->trans('AuthenticationDoesNotAllowSendNewPassword', $mode);
294 print '</div>';
295 print '</div>';
296}
297?>
298
299
300<br>
301
302<?php if (!empty($message)) { ?>
303 <div class="center login_main_message">
304 <?php dol_htmloutput_mesg($message, [], '', 1); ?>
305 </div>
306<?php } ?>
307
308
309<!-- Common footer is not used for passwordforgotten page, this is same than footer but inside passwordforgotten tpl -->
310
311<?php
312if (getDolGlobalString('MAIN_HTML_FOOTER')) {
313 print $conf->global->MAIN_HTML_FOOTER;
314}
315
316if (!empty($morelogincontent) && is_array($morelogincontent)) {
317 foreach ($morelogincontent as $format => $option) {
318 if ($format == 'js') {
319 echo "\n".'<!-- Javascript by hook -->';
320 echo $option."\n";
321 }
322 }
323} elseif (!empty($moreloginextracontent)) {
324 echo '<!-- Javascript by hook -->';
325 echo $moreloginextracontent;
326}
327
328// Google Analytics
329// TODO Remove this, and add content into hook getPasswordForgottenPageExtraOptions() instead
330if (isModEnabled('google') && getDolGlobalString('MAIN_GOOGLE_AN_ID')) {
331 $tmptagarray = explode(',', getDolGlobalString('MAIN_GOOGLE_AN_ID'));
332 foreach ($tmptagarray as $tmptag) {
333 print "\n";
334 print "<!-- JS CODE TO ENABLE for google analtics tag -->\n";
335 print "
336 <!-- Global site tag (gtag.js) - Google Analytics -->
337 <script async src=\"https://www.googletagmanager.com/gtag/js?id=".trim($tmptag)."\"></script>
338 <script>
339 window.dataLayer = window.dataLayer || [];
340 function gtag(){dataLayer.push(arguments);}
341 gtag('js', new Date());
342
343 gtag('config', '".trim($tmptag)."');
344 </script>";
345 print "\n";
346 }
347}
348
349// TODO Replace this with a hook
350// Google Adsense (need Google module)
351if (isModEnabled('google') && getDolGlobalString('MAIN_GOOGLE_AD_CLIENT') && getDolGlobalString('MAIN_GOOGLE_AD_SLOT')) {
352 if (empty($conf->dol_use_jmobile)) {
353 ?>
354 <div class="center"><br>
355 <script><!--
356 google_ad_client = "<?php echo $conf->global->MAIN_GOOGLE_AD_CLIENT ?>";
357 google_ad_slot = "<?php echo $conf->global->MAIN_GOOGLE_AD_SLOT ?>";
358 google_ad_width = <?php echo $conf->global->MAIN_GOOGLE_AD_WIDTH ?>;
359 google_ad_height = <?php echo $conf->global->MAIN_GOOGLE_AD_HEIGHT ?>;
360 //-->
361 </script>
362 <script src="//pagead2.googlesyndication.com/pagead/show_ads.js"></script>
363 </div>
364 <?php
365 }
366}
367?>
368
369
370</div>
371</div> <!-- end of center -->
372
373
374</body>
375</html>
376<!-- END PHP TEMPLATE -->
print $object position
Definition edit.php:195
Class to manage Dolibarr users.
colorStringToArray($stringcolor, $colorifnotfound=array(88, 88, 88))
Convert a string RGB value ('FFFFFF', '255,255,255') into an array RGB array(255,255,...
getDolUserString($key, $default='', $tmpuser=null)
Return Dolibarr user constant string value.
dol_now($mode='auto')
Return date for now.
newToken()
Return the value of token currently saved into session with name 'newtoken'.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0)
Return value of a param into GET or POST supervariable.
dol_htmloutput_mesg($mesgstring='', $mesgarray=array(), $style='ok', $keepembedded=0)
Print formatted messages to output (Used to show messages on html output).
getDolGlobalString($key, $default='')
Return a Dolibarr global constant string value.
dol_escape_htmltag($stringtoescape, $keepb=0, $keepn=0, $noescapetags='', $escapeonlyhtmltags=0, $cleanalsojavascript=0)
Returns text escaped for inclusion in HTML alt or title or value tags, or into values of HTML input f...
top_htmlhead($head, $title='', $disablejs=0, $disablehead=0, $arrayofjs=array(), $arrayofcss=array(), $disableforlogin=0, $disablenofollow=0, $disablenoindex=0)
Output html header of a page.
if(preg_match('/crypted:/i', $dolibarr_main_db_pass)||!empty($dolibarr_main_db_encrypted_pass)) $conf db type
Definition repair.php:137
$conf db name
Only used if Module[ID]Name translation string is not found.
Definition repair.php:140
httponly_accessforbidden($message='1', $http_response_code=403, $stringalreadysanitized=0)
Show a message to say access is forbidden and stop program.
dol_verifyHash($chain, $hash, $type='0')
Compute a hash and compare it to the given one For backward compatibility reasons,...