2019-05-02 18:17:27 -04:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
2016-03-07 13:45:33 -05:00
|
|
|
class UsersEmailController < ApplicationController
|
2018-01-31 23:17:59 -05:00
|
|
|
requires_login only: %i[index update]
|
2023-01-09 07:20:10 -05:00
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
skip_before_action :check_xhr, only: %i[show_confirm_old_email show_confirm_new_email]
|
2023-01-09 07:20:10 -05:00
|
|
|
|
2019-11-20 02:31:25 -05:00
|
|
|
skip_before_action :redirect_to_login_if_required,
|
|
|
|
only: %i[
|
2021-01-19 19:52:25 -05:00
|
|
|
show_confirm_old_email
|
|
|
|
show_confirm_new_email
|
2024-01-30 05:32:42 -05:00
|
|
|
confirm_old_email
|
|
|
|
confirm_new_email
|
2019-11-20 02:31:25 -05:00
|
|
|
]
|
2023-01-09 07:20:10 -05:00
|
|
|
|
2016-03-07 13:45:33 -05:00
|
|
|
def index
|
|
|
|
end
|
|
|
|
|
2020-06-10 12:11:49 -04:00
|
|
|
def create
|
|
|
|
return render json: failed_json, status: 410 if !SiteSetting.enable_secondary_emails
|
|
|
|
|
|
|
|
params.require(:email)
|
|
|
|
user = fetch_user_from_params
|
|
|
|
|
|
|
|
RateLimiter.new(user, "email-hr-#{request.remote_ip}", 6, 1.hour).performed!
|
|
|
|
RateLimiter.new(user, "email-min-#{request.remote_ip}", 3, 1.minute).performed!
|
|
|
|
|
|
|
|
updater = EmailUpdater.new(guardian: guardian, user: user)
|
|
|
|
updater.change_to(params[:email], add: true)
|
|
|
|
|
|
|
|
return render_json_error(updater.errors.full_messages) if updater.errors.present?
|
|
|
|
|
|
|
|
render body: nil
|
|
|
|
rescue RateLimiter::LimitExceeded
|
|
|
|
render_json_error(I18n.t("rate_limiter.slow_down"))
|
|
|
|
end
|
|
|
|
|
2016-03-07 13:45:33 -05:00
|
|
|
def update
|
|
|
|
params.require(:email)
|
|
|
|
user = fetch_user_from_params
|
|
|
|
|
2020-06-10 12:11:49 -04:00
|
|
|
RateLimiter.new(user, "email-hr-#{request.remote_ip}", 6, 1.hour).performed!
|
|
|
|
RateLimiter.new(user, "email-min-#{request.remote_ip}", 3, 1.minute).performed!
|
2016-03-07 13:45:33 -05:00
|
|
|
|
2020-06-04 01:09:10 -04:00
|
|
|
updater = EmailUpdater.new(guardian: guardian, user: user)
|
2016-03-07 14:40:11 -05:00
|
|
|
updater.change_to(params[:email])
|
2016-03-07 13:45:33 -05:00
|
|
|
|
2016-03-07 14:40:11 -05:00
|
|
|
return render_json_error(updater.errors.full_messages) if updater.errors.present?
|
2016-03-07 13:45:33 -05:00
|
|
|
|
2017-08-31 00:06:56 -04:00
|
|
|
render body: nil
|
2016-03-07 13:45:33 -05:00
|
|
|
rescue RateLimiter::LimitExceeded
|
|
|
|
render_json_error(I18n.t("rate_limiter.slow_down"))
|
|
|
|
end
|
|
|
|
|
2019-11-20 02:31:25 -05:00
|
|
|
def confirm_new_email
|
2024-01-30 05:32:42 -05:00
|
|
|
change_request = load_change_request(:new)
|
2018-02-20 01:44:51 -05:00
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
result =
|
|
|
|
run_second_factor!(SecondFactor::Actions::ConfirmEmail, target_user: change_request.user)
|
2018-02-20 01:44:51 -05:00
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
if result.no_second_factors_enabled? || result.second_factor_auth_completed?
|
2019-11-20 02:31:25 -05:00
|
|
|
updater = EmailUpdater.new
|
|
|
|
if updater.confirm(params[:token]) == :complete
|
|
|
|
updater.user.user_stat.reset_bounce_score!
|
2024-01-30 05:32:42 -05:00
|
|
|
render json: success_json
|
2019-11-20 02:31:25 -05:00
|
|
|
else
|
2024-01-30 05:32:42 -05:00
|
|
|
render json: { error: I18n.t("change_email.already_done") }, status: 400
|
2018-02-20 01:44:51 -05:00
|
|
|
end
|
2019-11-20 02:31:25 -05:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def show_confirm_new_email
|
2024-01-30 05:32:42 -05:00
|
|
|
return render "default/empty" if request.format.html?
|
2018-02-20 01:44:51 -05:00
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
change_request = load_change_request(:new)
|
2018-02-20 01:44:51 -05:00
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
render json: {
|
|
|
|
new_email: change_request.new_email,
|
|
|
|
old_email: change_request.old_email,
|
|
|
|
token: params[:token],
|
|
|
|
}
|
2019-11-20 02:31:25 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
def confirm_old_email
|
|
|
|
load_change_request(:old)
|
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
updater = EmailUpdater.new
|
|
|
|
if updater.confirm(params[:token]) == :authorizing_new
|
|
|
|
render json: success_json
|
2019-11-20 02:31:25 -05:00
|
|
|
else
|
2024-01-30 05:32:42 -05:00
|
|
|
render json: { error: I18n.t("change_email.already_done") }, status: 400
|
2019-11-20 02:31:25 -05:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def show_confirm_old_email
|
2024-01-30 05:32:42 -05:00
|
|
|
return render "default/empty" if request.format.html?
|
2019-11-20 02:31:25 -05:00
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
change_request = load_change_request(:old)
|
2019-11-20 02:31:25 -05:00
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
render json: {
|
|
|
|
new_email: change_request.new_email,
|
|
|
|
old_email: change_request.old_email,
|
|
|
|
token: params[:token],
|
|
|
|
}
|
2016-03-07 14:40:11 -05:00
|
|
|
end
|
|
|
|
|
2019-11-20 02:31:25 -05:00
|
|
|
private
|
|
|
|
|
|
|
|
def load_change_request(type)
|
|
|
|
expires_now
|
|
|
|
|
2021-11-25 02:34:39 -05:00
|
|
|
token = EmailToken.confirmable(params[:token], scope: EmailToken.scopes[:email_update])
|
2019-11-20 02:31:25 -05:00
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
raise Discourse::NotFound if !token || !token.user
|
|
|
|
|
|
|
|
if current_user && token.user.id != current_user.id
|
|
|
|
raise Discourse::InvalidAccess.new "You are logged in, but this email change link belongs to another user account. Please log out and try again."
|
|
|
|
end
|
|
|
|
|
|
|
|
change_request_params =
|
2019-11-20 02:31:25 -05:00
|
|
|
if type == :old
|
2024-01-30 05:32:42 -05:00
|
|
|
{ old_email_token_id: token.id, change_state: EmailChangeRequest.states[:authorizing_old] }
|
2019-11-20 02:31:25 -05:00
|
|
|
elsif type == :new
|
2024-01-30 05:32:42 -05:00
|
|
|
{ new_email_token_id: token.id, change_state: EmailChangeRequest.states[:authorizing_new] }
|
2019-11-20 02:31:25 -05:00
|
|
|
end
|
|
|
|
|
2024-01-30 05:32:42 -05:00
|
|
|
token.user&.email_change_requests&.find_by!(**change_request_params)
|
2019-11-20 02:31:25 -05:00
|
|
|
end
|
2016-03-07 13:45:33 -05:00
|
|
|
end
|