(* COCANWIKI - a wiki written in Objective CAML.
* Written by Richard W.M. Jones <rich@merjis.com>.
* Copyright (C) 2004 Merjis Ltd.
- * $Id: change_password.ml,v 1.2 2004/10/14 15:57:15 rich Exp $
+ * $Id: change_password.ml,v 1.5 2006/03/27 18:09:46 rich Exp $
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
open Cocanwiki
open Cocanwiki_ok
-let run r (q : cgi) (dbh : Dbi.connection) hostid _ user =
+let run r (q : cgi) dbh hostid _ user =
let old_password = q#param "old_password" in
(* Check the old password was supplied correctly. *)
let userid =
match user with
Anonymous -> assert false (* cannot happen *)
- | User (userid, _, _) -> userid in
+ | User (userid, _, _, _) -> userid in
- let sth = dbh#prepare_cached "select 1 from users
- where hostid = ? and id = ?
- and password = ?" in
- sth#execute [`Int hostid; `Int userid; `String old_password];
+ let rows = PGSQL(dbh)
+ "select 1 from users
+ where hostid = $hostid and id = $userid and password = $old_password" in
let old_password_ok =
- try 1 = sth#fetch1int ()
- with
- Not_found -> false in
+ match rows with
+ | [Some 1l] -> true
+ | [] -> false
+ | _ -> assert false in
if not old_password_ok then (
error ~title:"Bad password"
~back_button:true
- q "The password you gave is wrong.";
+ dbh hostid q "The password you gave is wrong.";
return ()
);
if password1 = "" || password2 = "" then (
error ~back_button:true ~title:"Bad password"
- q "The password you gave is empty.";
+ dbh hostid q "The password you gave is empty.";
return ()
);
if password1 <> password2 then (
error ~back_button:true ~title:"Passwords don't match"
- q "The two passwords you gave aren't identical.";
+ dbh hostid q "The two passwords you gave aren't identical.";
return ()
);
let password = password1 in
(* Change the password. *)
- let sth =
- dbh#prepare_cached
- "update users set password = ?, force_password_change = false
- where hostid = ? and id = ?" in
- sth#execute [`String password; `Int hostid; `Int userid];
+ PGSQL(dbh)
+ "update users set password = $password, force_password_change = false
+ where hostid = $hostid and id = $userid";
- dbh#commit ();
+ PGOCaml.commit dbh;
let buttons = [ ok_button "/" ] in
ok ~buttons ~title:"Password changed"
- q "The password was changed."
+ dbh hostid q "The password was changed."
let () =
register_script ~anonymous:false run