(* COCANWIKI - a wiki written in Objective CAML.
* Written by Richard W.M. Jones <rich@merjis.com>.
* Copyright (C) 2004 Merjis Ltd.
- * $Id: change_password.ml,v 1.1 2004/09/25 13:17:00 rich Exp $
+ * $Id: change_password.ml,v 1.4 2005/11/24 14:54:11 rich Exp $
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
let userid =
match user with
Anonymous -> assert false (* cannot happen *)
- | User (userid, _, _) -> userid in
+ | User (userid, _, _, _) -> userid in
let sth = dbh#prepare_cached "select 1 from users
- where id = ? and password = ?" in
- sth#execute [`Int userid; `String old_password];
+ where hostid = ? and id = ?
+ and password = ?" in
+ sth#execute [`Int hostid; `Int userid; `String old_password];
let old_password_ok =
try 1 = sth#fetch1int ()
if not old_password_ok then (
error ~title:"Bad password"
~back_button:true
- q "The password you gave is wrong.";
+ dbh hostid q "The password you gave is wrong.";
return ()
);
if password1 = "" || password2 = "" then (
error ~back_button:true ~title:"Bad password"
- q "The password you gave is empty.";
+ dbh hostid q "The password you gave is empty.";
return ()
);
if password1 <> password2 then (
error ~back_button:true ~title:"Passwords don't match"
- q "The two passwords you gave aren't identical.";
+ dbh hostid q "The two passwords you gave aren't identical.";
return ()
);
let sth =
dbh#prepare_cached
"update users set password = ?, force_password_change = false
- where id = ?" in
- sth#execute [`String password; `Int userid];
+ where hostid = ? and id = ?" in
+ sth#execute [`String password; `Int hostid; `Int userid];
dbh#commit ();
let buttons = [ ok_button "/" ] in
ok ~buttons ~title:"Password changed"
- q "The password was changed."
+ dbh hostid q "The password was changed."
let () =
register_script ~anonymous:false run