(* COCANWIKI - a wiki written in Objective CAML. * Written by Richard W.M. Jones . * Copyright (C) 2004 Merjis Ltd. * $Id: invite_user_confirm_form.ml,v 1.1 2004/10/14 15:57:15 rich Exp $ * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation; either version 2 of the License, or * (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program; see the file COPYING. If not, write to * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, * Boston, MA 02111-1307, USA. *) open Apache open Registry open Cgi open Printf open Cocanwiki open Cocanwiki_ok open Cocanwiki_template open Cocanwiki_strings let run r (q : cgi) (dbh : Dbi.connection) hostid _ _ = let template = get_template dbh hostid "invite_user_confirm_form.html" in (* Get the password. It's supposed to be unique so we can look up the * user by this. Do a bit of sanity checking on it, however, to make * sure we can't just use it to search for passwords, or some other type * of strange exploit. *) let password = q#param "p" in assert (String.length password = 32 && string_for_all isxdigit password); let sth = dbh#prepare_cached "select name from users where hostid = ? and password = ?" in sth#execute [`Int hostid; `String password]; let username = sth#fetch1string () in (* Update the template so that the user can set their preferred password. *) template#set "username" username; template#set "old_password" password; q#template template let () = register_script run