From f475ed5cc1733ae768f0f7518a70e88977d33f75 Mon Sep 17 00:00:00 2001 From: Lukas Reschke Date: Mon, 15 Oct 2012 23:49:49 +0200 Subject: [PATCH] Revert "Remove old password check from changepassword and use verifyUser instead" This reverts commit e6b8153865a521a4750ec44016c5f22f453edfe1. --- settings/ajax/changepassword.php | 3 ++- settings/templates/personal.php | 5 +++-- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/settings/ajax/changepassword.php b/settings/ajax/changepassword.php index 5d94497ce58..5eab751b04e 100644 --- a/settings/ajax/changepassword.php +++ b/settings/ajax/changepassword.php @@ -10,6 +10,7 @@ OC_JSON::verifyUser(); $username = isset($_POST["username"]) ? $_POST["username"] : OC_User::getUser(); $password = $_POST["password"]; +$oldPassword=isset($_POST["oldpassword"])?$_POST["oldpassword"]:''; $userstatus = null; if(OC_Group::inGroup(OC_User::getUser(), 'admin')) { @@ -18,7 +19,7 @@ if(OC_Group::inGroup(OC_User::getUser(), 'admin')) { if(OC_SubAdmin::isUserAccessible(OC_User::getUser(), $username)) { $userstatus = 'subadmin'; } -if(OC_User::getUser() == $username) { +if(OC_User::getUser() == $username && OC_User::checkPassword($username, $oldPassword)) { $userstatus = 'user'; } diff --git a/settings/templates/personal.php b/settings/templates/personal.php index 0683bd3b64f..55ff24b4223 100644 --- a/settings/templates/personal.php +++ b/settings/templates/personal.php @@ -18,8 +18,9 @@
t('Your password was changed');?>
t('Unable to change your password');?>
- - + + +