Project

General

Profile

Revision 7dbec6b0

Added by Assos Assos over 5 years ago

Added module recovery_pass

View differences:

drupal7/sites/all/modules/recovery_pass/LICENSE.txt
1
                    GNU GENERAL PUBLIC LICENSE
2
                       Version 2, June 1991
3

  
4
 Copyright (C) 1989, 1991 Free Software Foundation, Inc.,
5
 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
6
 Everyone is permitted to copy and distribute verbatim copies
7
 of this license document, but changing it is not allowed.
8

  
9
                            Preamble
10

  
11
  The licenses for most software are designed to take away your
12
freedom to share and change it.  By contrast, the GNU General Public
13
License is intended to guarantee your freedom to share and change free
14
software--to make sure the software is free for all its users.  This
15
General Public License applies to most of the Free Software
16
Foundation's software and to any other program whose authors commit to
17
using it.  (Some other Free Software Foundation software is covered by
18
the GNU Lesser General Public License instead.)  You can apply it to
19
your programs, too.
20

  
21
  When we speak of free software, we are referring to freedom, not
22
price.  Our General Public Licenses are designed to make sure that you
23
have the freedom to distribute copies of free software (and charge for
24
this service if you wish), that you receive source code or can get it
25
if you want it, that you can change the software or use pieces of it
26
in new free programs; and that you know you can do these things.
27

  
28
  To protect your rights, we need to make restrictions that forbid
29
anyone to deny you these rights or to ask you to surrender the rights.
30
These restrictions translate to certain responsibilities for you if you
31
distribute copies of the software, or if you modify it.
32

  
33
  For example, if you distribute copies of such a program, whether
34
gratis or for a fee, you must give the recipients all the rights that
35
you have.  You must make sure that they, too, receive or can get the
36
source code.  And you must show them these terms so they know their
37
rights.
38

  
39
  We protect your rights with two steps: (1) copyright the software, and
40
(2) offer you this license which gives you legal permission to copy,
41
distribute and/or modify the software.
42

  
43
  Also, for each author's protection and ours, we want to make certain
44
that everyone understands that there is no warranty for this free
45
software.  If the software is modified by someone else and passed on, we
46
want its recipients to know that what they have is not the original, so
47
that any problems introduced by others will not reflect on the original
48
authors' reputations.
49

  
50
  Finally, any free program is threatened constantly by software
51
patents.  We wish to avoid the danger that redistributors of a free
52
program will individually obtain patent licenses, in effect making the
53
program proprietary.  To prevent this, we have made it clear that any
54
patent must be licensed for everyone's free use or not licensed at all.
55

  
56
  The precise terms and conditions for copying, distribution and
57
modification follow.
58

  
59
                    GNU GENERAL PUBLIC LICENSE
60
   TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
61

  
62
  0. This License applies to any program or other work which contains
63
a notice placed by the copyright holder saying it may be distributed
64
under the terms of this General Public License.  The "Program", below,
65
refers to any such program or work, and a "work based on the Program"
66
means either the Program or any derivative work under copyright law:
67
that is to say, a work containing the Program or a portion of it,
68
either verbatim or with modifications and/or translated into another
69
language.  (Hereinafter, translation is included without limitation in
70
the term "modification".)  Each licensee is addressed as "you".
71

  
72
Activities other than copying, distribution and modification are not
73
covered by this License; they are outside its scope.  The act of
74
running the Program is not restricted, and the output from the Program
75
is covered only if its contents constitute a work based on the
76
Program (independent of having been made by running the Program).
77
Whether that is true depends on what the Program does.
78

  
79
  1. You may copy and distribute verbatim copies of the Program's
80
source code as you receive it, in any medium, provided that you
81
conspicuously and appropriately publish on each copy an appropriate
82
copyright notice and disclaimer of warranty; keep intact all the
83
notices that refer to this License and to the absence of any warranty;
84
and give any other recipients of the Program a copy of this License
85
along with the Program.
86

  
87
You may charge a fee for the physical act of transferring a copy, and
88
you may at your option offer warranty protection in exchange for a fee.
89

  
90
  2. You may modify your copy or copies of the Program or any portion
91
of it, thus forming a work based on the Program, and copy and
92
distribute such modifications or work under the terms of Section 1
93
above, provided that you also meet all of these conditions:
94

  
95
    a) You must cause the modified files to carry prominent notices
96
    stating that you changed the files and the date of any change.
97

  
98
    b) You must cause any work that you distribute or publish, that in
99
    whole or in part contains or is derived from the Program or any
100
    part thereof, to be licensed as a whole at no charge to all third
101
    parties under the terms of this License.
102

  
103
    c) If the modified program normally reads commands interactively
104
    when run, you must cause it, when started running for such
105
    interactive use in the most ordinary way, to print or display an
106
    announcement including an appropriate copyright notice and a
107
    notice that there is no warranty (or else, saying that you provide
108
    a warranty) and that users may redistribute the program under
109
    these conditions, and telling the user how to view a copy of this
110
    License.  (Exception: if the Program itself is interactive but
111
    does not normally print such an announcement, your work based on
112
    the Program is not required to print an announcement.)
113

  
114
These requirements apply to the modified work as a whole.  If
115
identifiable sections of that work are not derived from the Program,
116
and can be reasonably considered independent and separate works in
117
themselves, then this License, and its terms, do not apply to those
118
sections when you distribute them as separate works.  But when you
119
distribute the same sections as part of a whole which is a work based
120
on the Program, the distribution of the whole must be on the terms of
121
this License, whose permissions for other licensees extend to the
122
entire whole, and thus to each and every part regardless of who wrote it.
123

  
124
Thus, it is not the intent of this section to claim rights or contest
125
your rights to work written entirely by you; rather, the intent is to
126
exercise the right to control the distribution of derivative or
127
collective works based on the Program.
128

  
129
In addition, mere aggregation of another work not based on the Program
130
with the Program (or with a work based on the Program) on a volume of
131
a storage or distribution medium does not bring the other work under
132
the scope of this License.
133

  
134
  3. You may copy and distribute the Program (or a work based on it,
135
under Section 2) in object code or executable form under the terms of
136
Sections 1 and 2 above provided that you also do one of the following:
137

  
138
    a) Accompany it with the complete corresponding machine-readable
139
    source code, which must be distributed under the terms of Sections
140
    1 and 2 above on a medium customarily used for software interchange; or,
141

  
142
    b) Accompany it with a written offer, valid for at least three
143
    years, to give any third party, for a charge no more than your
144
    cost of physically performing source distribution, a complete
145
    machine-readable copy of the corresponding source code, to be
146
    distributed under the terms of Sections 1 and 2 above on a medium
147
    customarily used for software interchange; or,
148

  
149
    c) Accompany it with the information you received as to the offer
150
    to distribute corresponding source code.  (This alternative is
151
    allowed only for noncommercial distribution and only if you
152
    received the program in object code or executable form with such
153
    an offer, in accord with Subsection b above.)
154

  
155
The source code for a work means the preferred form of the work for
156
making modifications to it.  For an executable work, complete source
157
code means all the source code for all modules it contains, plus any
158
associated interface definition files, plus the scripts used to
159
control compilation and installation of the executable.  However, as a
160
special exception, the source code distributed need not include
161
anything that is normally distributed (in either source or binary
162
form) with the major components (compiler, kernel, and so on) of the
163
operating system on which the executable runs, unless that component
164
itself accompanies the executable.
165

  
166
If distribution of executable or object code is made by offering
167
access to copy from a designated place, then offering equivalent
168
access to copy the source code from the same place counts as
169
distribution of the source code, even though third parties are not
170
compelled to copy the source along with the object code.
171

  
172
  4. You may not copy, modify, sublicense, or distribute the Program
173
except as expressly provided under this License.  Any attempt
174
otherwise to copy, modify, sublicense or distribute the Program is
175
void, and will automatically terminate your rights under this License.
176
However, parties who have received copies, or rights, from you under
177
this License will not have their licenses terminated so long as such
178
parties remain in full compliance.
179

  
180
  5. You are not required to accept this License, since you have not
181
signed it.  However, nothing else grants you permission to modify or
182
distribute the Program or its derivative works.  These actions are
183
prohibited by law if you do not accept this License.  Therefore, by
184
modifying or distributing the Program (or any work based on the
185
Program), you indicate your acceptance of this License to do so, and
186
all its terms and conditions for copying, distributing or modifying
187
the Program or works based on it.
188

  
189
  6. Each time you redistribute the Program (or any work based on the
190
Program), the recipient automatically receives a license from the
191
original licensor to copy, distribute or modify the Program subject to
192
these terms and conditions.  You may not impose any further
193
restrictions on the recipients' exercise of the rights granted herein.
194
You are not responsible for enforcing compliance by third parties to
195
this License.
196

  
197
  7. If, as a consequence of a court judgment or allegation of patent
198
infringement or for any other reason (not limited to patent issues),
199
conditions are imposed on you (whether by court order, agreement or
200
otherwise) that contradict the conditions of this License, they do not
201
excuse you from the conditions of this License.  If you cannot
202
distribute so as to satisfy simultaneously your obligations under this
203
License and any other pertinent obligations, then as a consequence you
204
may not distribute the Program at all.  For example, if a patent
205
license would not permit royalty-free redistribution of the Program by
206
all those who receive copies directly or indirectly through you, then
207
the only way you could satisfy both it and this License would be to
208
refrain entirely from distribution of the Program.
209

  
210
If any portion of this section is held invalid or unenforceable under
211
any particular circumstance, the balance of the section is intended to
212
apply and the section as a whole is intended to apply in other
213
circumstances.
214

  
215
It is not the purpose of this section to induce you to infringe any
216
patents or other property right claims or to contest validity of any
217
such claims; this section has the sole purpose of protecting the
218
integrity of the free software distribution system, which is
219
implemented by public license practices.  Many people have made
220
generous contributions to the wide range of software distributed
221
through that system in reliance on consistent application of that
222
system; it is up to the author/donor to decide if he or she is willing
223
to distribute software through any other system and a licensee cannot
224
impose that choice.
225

  
226
This section is intended to make thoroughly clear what is believed to
227
be a consequence of the rest of this License.
228

  
229
  8. If the distribution and/or use of the Program is restricted in
230
certain countries either by patents or by copyrighted interfaces, the
231
original copyright holder who places the Program under this License
232
may add an explicit geographical distribution limitation excluding
233
those countries, so that distribution is permitted only in or among
234
countries not thus excluded.  In such case, this License incorporates
235
the limitation as if written in the body of this License.
236

  
237
  9. The Free Software Foundation may publish revised and/or new versions
238
of the General Public License from time to time.  Such new versions will
239
be similar in spirit to the present version, but may differ in detail to
240
address new problems or concerns.
241

  
242
Each version is given a distinguishing version number.  If the Program
243
specifies a version number of this License which applies to it and "any
244
later version", you have the option of following the terms and conditions
245
either of that version or of any later version published by the Free
246
Software Foundation.  If the Program does not specify a version number of
247
this License, you may choose any version ever published by the Free Software
248
Foundation.
249

  
250
  10. If you wish to incorporate parts of the Program into other free
251
programs whose distribution conditions are different, write to the author
252
to ask for permission.  For software which is copyrighted by the Free
253
Software Foundation, write to the Free Software Foundation; we sometimes
254
make exceptions for this.  Our decision will be guided by the two goals
255
of preserving the free status of all derivatives of our free software and
256
of promoting the sharing and reuse of software generally.
257

  
258
                            NO WARRANTY
259

  
260
  11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
261
FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW.  EXCEPT WHEN
262
OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
263
PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED
264
OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
265
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.  THE ENTIRE RISK AS
266
TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU.  SHOULD THE
267
PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING,
268
REPAIR OR CORRECTION.
269

  
270
  12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
271
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR
272
REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES,
273
INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING
274
OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED
275
TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY
276
YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER
277
PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE
278
POSSIBILITY OF SUCH DAMAGES.
279

  
280
                     END OF TERMS AND CONDITIONS
281

  
282
            How to Apply These Terms to Your New Programs
283

  
284
  If you develop a new program, and you want it to be of the greatest
285
possible use to the public, the best way to achieve this is to make it
286
free software which everyone can redistribute and change under these terms.
287

  
288
  To do so, attach the following notices to the program.  It is safest
289
to attach them to the start of each source file to most effectively
290
convey the exclusion of warranty; and each file should have at least
291
the "copyright" line and a pointer to where the full notice is found.
292

  
293
    <one line to give the program's name and a brief idea of what it does.>
294
    Copyright (C) <year>  <name of author>
295

  
296
    This program is free software; you can redistribute it and/or modify
297
    it under the terms of the GNU General Public License as published by
298
    the Free Software Foundation; either version 2 of the License, or
299
    (at your option) any later version.
300

  
301
    This program is distributed in the hope that it will be useful,
302
    but WITHOUT ANY WARRANTY; without even the implied warranty of
303
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
304
    GNU General Public License for more details.
305

  
306
    You should have received a copy of the GNU General Public License along
307
    with this program; if not, write to the Free Software Foundation, Inc.,
308
    51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
309

  
310
Also add information on how to contact you by electronic and paper mail.
311

  
312
If the program is interactive, make it output a short notice like this
313
when it starts in an interactive mode:
314

  
315
    Gnomovision version 69, Copyright (C) year name of author
316
    Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
317
    This is free software, and you are welcome to redistribute it
318
    under certain conditions; type `show c' for details.
319

  
320
The hypothetical commands `show w' and `show c' should show the appropriate
321
parts of the General Public License.  Of course, the commands you use may
322
be called something other than `show w' and `show c'; they could even be
323
mouse-clicks or menu items--whatever suits your program.
324

  
325
You should also get your employer (if you work as a programmer) or your
326
school, if any, to sign a "copyright disclaimer" for the program, if
327
necessary.  Here is a sample; alter the names:
328

  
329
  Yoyodyne, Inc., hereby disclaims all copyright interest in the program
330
  `Gnomovision' (which makes passes at compilers) written by James Hacker.
331

  
332
  <signature of Ty Coon>, 1 April 1989
333
  Ty Coon, President of Vice
334

  
335
This General Public License does not permit incorporating your program into
336
proprietary programs.  If your program is a subroutine library, you may
337
consider it more useful to permit linking proprietary applications with the
338
library.  If this is what you want to do, use the GNU Lesser General
339
Public License instead of this License.
drupal7/sites/all/modules/recovery_pass/README.txt
1
CONTENTS OF THIS FILE
2
---------------------
3

  
4
 * Introduction
5
 * Module Details
6
 * Recommended modules
7
 * Configuration
8
 * Troubleshooting
9
 * FAQ
10
 * Maintainers
11

  
12

  
13
INTRODUCTION
14
------------
15
Recovery Password Module alters default Drupal password reset process and makes
16
it possible to send the new password in recovery mail itself.
17
In this case, when user clicks on forgot password providing valid username
18
or email address, new password is generated randomly and is sent to the
19
user email address.
20

  
21

  
22
MODULE DETAILS
23
--------------
24
Drupal by default sends Password Reset URL by mail to user's email id in
25
password recovery mail, but Recovery Password modules makes it possible for
26
Drupal to send any random password by email instead of URL to the user.
27

  
28
Recovery Password Module alters default Drupal password reset process and
29
makes it possible to send the new password in recovery mail itself.
30
In this case, when user clicks on forgot password providing valid username or
31
email address, new password is generated randomly and is sent to the
32
user email address.
33

  
34
The password recovery mail body and subject to be sent to user is configurable
35
and corresponding configuration settings are available at
36
admin/config/people/recovery-pass.For displaying new password please use
37
[user_new_password] placeholder in the mail body.
38

  
39
Important: As of now Recovery Password Module overrides default Drupal behaviour
40
for password recovery and hence the previous settings will not work once the
41
module is enabled till it is disabled again. User tokens are available in this
42
case also.
43

  
44
Warning !!! Once forgot password is clicked for a user, the password gets
45
changed for that user immediately.
46

  
47
Added Functionality: After Password Reset, next time the user enters with old
48
password, a warning message saying that the password has been reset is shown to
49
the user which is configurable and can be disabled also. While in case user
50
enters any password other than the old one, that warning message will no more
51
bappear for that user.
52

  
53

  
54
RECOMMENDED MODULES
55
-------------------
56
* HTMLMAIL (https://www.drupal.org/project/htmlmail)
57
  When enabled Recovery Password module, it supports HTML Mail. You can use html
58
  in recovery mail's body to be sent to the user at module configuration
59
  settings.
60

  
61
* TOKEN (https://www.drupal.org/project/token)
62
  When enabled user tokens would be available in configuration settings for
63
  email body.
64

  
65

  
66
CONFIGURATION
67
-------------
68
* The password recovery mail body and subject to be sent to user is
69
configurable and corresponding configuration settings are available at
70
admin/config/people/recovery-pass.For displaying new password please use
71
[user_new_password] placeholder in the mail body.
72

  
73
* If HTMLMAIL module exists then write mail in HTML format else email body will
74
be sent as plain text considering new line.
75

  
76
* Warning Message to be shown, if user after resetting the password uses the old
77
password again is configurable and can be enabled/disabled. By default warning
78
message will be shown.
79

  
80
* Redirect Path after user submits Forgot Password Form is also made
81
configurable with recovery password module.
82

  
83

  
84
TROUBLESHOOTING
85
---------------
86
As of now, Recovery Module alters user_pass form and hence it works at only
87
Request new password form at url: /user/password .
88
In case the module is not working properly, you may try:
89
* Clear the cache
90
* Reinstall the module after disable and uninstallation.
91

  
92
FAQ
93
---
94

  
95
Q: Will existing default Drupal [user:one-time-login-url] as provided by
96
Password Recovery Settings at admin/config/people/accounts work at configuration
97
settings?
98

  
99
A: No, Recovery Password Module overrides Drupal default behaviour.
100

  
101

  
102

  
103
Q: If htmlmail module exists can we send simple plain text mail at configuration
104
settings?
105

  
106
A: Yes and new lines would be considered too automatically.
107

  
108

  
109

  
110
Q: Once Reset, will user be able to login using old password?
111

  
112
A: No
113

  
114

  
115

  
116
Q: How to include new password in mail at configuration settings?
117

  
118
A: Use [user_new_password] placeholder.
119

  
120

  
121

  
122
Q: If htmlmail module is not installed, then will new line be considered at
123
configuration settings?
124

  
125
A: Yes, new line will automatically be considered if htmlmail module is not
126
installed.
127

  
128

  
129

  
130
MAINTAINERS
131
-----------
132
Current maintainers:
133

  
134
 * Purushotam Rai (https://drupal.org/user/3193859)
135

  
136

  
137
This project has been sponsored by:
138
 * QED42
139
  QED42 is a web development agency focussed on helping organisations and
140
  individuals reach their potential, most of our work is in the space of
141
  publishing, e-commerce, social and enterprise.
drupal7/sites/all/modules/recovery_pass/recovery_pass.admin.inc
1
<?php
2
/**
3
 * @file
4
 * Contains configuration form for Recovery Password.
5
 */
6

  
7
/**
8
 * Callback to admin/config/people/recovery-pass.
9
 */
10
function recovery_pass_config_form($form, &$form_state) {
11
  $form = array();
12
  $form['recovery_pass_help_text'] = array(
13
    '#type' => 'item',
14
    '#markup' => t('Edit the e-mail messages sent to users who request a new password. The list of available tokens that can be used in e-mails is provided below. For displaying new password please use <strong>[user_new_password]</strong> placeholder.'),
15
  );
16

  
17
  $form['recovery_pass_email_subject'] = array(
18
    '#type' => 'textfield',
19
    '#title' => t('Subject'),
20
    '#required' => TRUE,
21
    '#default_value' => _recovery_pass_mail_text('email_subject'),
22
  );
23

  
24
  $form['recovery_pass_email_text'] = array(
25
    '#type' => 'textarea',
26
    '#title' => t('Email Body'),
27
    '#required' => TRUE,
28
    '#default_value' => _recovery_pass_mail_text('email_text'),
29
  );
30

  
31
  if (module_exists("htmlmail")) {
32
    // Adding description incase HTMLMAIL module exists.
33
    $form['recovery_pass_email_text']['#description'] = t('Supports HTML Mail provided HTMLMAIL module is enabled.');
34
  }
35

  
36
  if (module_exists("token")) {
37
    $form['token_help'] = array(
38
      '#type' => 'markup',
39
      '#token_types' => array('user'),
40
      '#theme' => 'token_tree_link',
41
    );
42
  }
43
  $form['recovery_pass_old_pass_show'] = array(
44
    '#type' => 'checkbox',
45
    '#title' => t('Show Warning message to users for trying old password at login form.'),
46
    '#default_value' => variable_get('recovery_pass_old_pass_show', 1),
47
  );
48

  
49
  $form['recovery_pass_old_pass_warning'] = array(
50
    '#type' => 'textarea',
51
    '#rows' => 2,
52
    '#title' => t('Old Password Warning Message'),
53
    '#description' => t('Warning message to be shown, if user after resetting the password uses the old password again.'),
54
    '#default_value' => _recovery_pass_mail_text('old_pass_warning'),
55
  );
56

  
57
  $form['recovery_pass_fpass_redirect'] = array(
58
    '#type' => 'textfield',
59
    '#title' => t('Redirect Path after Forgot Password Page'),
60
    '#maxlength' => 255,
61
    '#default_value' => variable_get('recovery_pass_fpass_redirect', 'user'),
62
    '#description' => t('The path to redirect user, after forgot password form. This can be an internal Drupal path such as %add-node or an external URL such as %drupal. Enter %front to link to the front page.',
63
      array(
64
        '%front' => '<front>',
65
        '%add-node' => 'node/add',
66
        '%drupal' => 'http://drupal.org',
67
      )
68
    ),
69
    '#required' => TRUE,
70
    '#element_validate' => array('_recovery_pass_validate_path'),
71
  );
72

  
73
  $form['recovery_pass_expiry_period'] = array(
74
    '#type' => 'textfield',
75
    '#title' => t('Expiry Period'),
76
    '#description' => t('Please enter expiry period in weeks. After these many weeks the record for old password warning to be shown to that particular user would be deleted.'),
77
    '#default_value' => variable_get('recovery_pass_expiry_period', '1'),
78
    '#element_validate' => array('element_validate_integer_positive'),
79
  );
80

  
81
  return system_settings_form($form);
82
}
83

  
84
/**
85
 * Validates path entered by user.
86
 */
87
function _recovery_pass_validate_path($element, &$form_state, $form) {
88
  if (!empty($element['#value'])) {
89
    $path = $element['#value'];
90
    if (!drupal_valid_path($path) && !drupal_lookup_path('source', $path) && !url_is_external($path)) {
91
      form_error($element, t('Please provide valid redirect path.'));
92
    }
93
  }
94
}
drupal7/sites/all/modules/recovery_pass/recovery_pass.info
1
name = Recovery Password
2
description = Provides Option to send Recovery Password in the email itself.
3
core = 7.x
4
configure = admin/config/people/recovery-pass
5

  
6
; Information added by Drupal.org packaging script on 2017-11-11
7
version = "7.x-1.2"
8
core = "7.x"
9
project = "recovery_pass"
10
datestamp = "1510407787"
11

  
drupal7/sites/all/modules/recovery_pass/recovery_pass.install
1
<?php
2
/**
3
 * @file
4
 * Install, update, and uninstall functions for the Recovery Password module.
5
 */
6

  
7
/**
8
 * Implements hook_schema().
9
 */
10
function recovery_pass_schema() {
11
  $schema['recovery_pass'] = array(
12
    'fields' => array(
13
      'id' => array(
14
        'type' => 'serial',
15
        'unsigned' => TRUE,
16
        'not null' => TRUE,
17

  
18
      ),
19
      'uid' => array(
20
        'type' => 'int',
21
        'unsigned' => TRUE,
22
        'not null' => TRUE,
23
        'description' => 'UID of user.',
24
      ),
25
      'old_pass' => array(
26
        'type' => 'varchar',
27
        'not null' => TRUE,
28
        'length' => 255,
29
        'description' => 'stores temp old pass',
30
      ),
31
      'changed' => array(
32
        'type' => 'int',
33
        'not null' => TRUE,
34
        'default' => 0,
35
        'description' => 'stores request created time',
36
      ),
37
    ),
38
    'primary key' => array('id'),
39
    'foreign keys' => array(
40
      'recovery_pass_uid' => array(
41
        'table' => 'users',
42
        'columns' => array('uid' => 'uid'),
43
      ),
44
    ),
45
  );
46
  return $schema;
47
}
48

  
49
/**
50
 * Implements hook_uninstall().
51
 */
52
function recovery_pass_uninstall() {
53
  variable_del('recovery_pass_help_text');
54
  variable_del('recovery_pass_email_subject');
55
  variable_del('recovery_pass_email_text');
56
  variable_del('recovery_pass_old_pass_show');
57
  variable_del('recovery_pass_old_pass_warning');
58
  variable_del('recovery_pass_fpass_redirect');
59
  variable_del('recovery_pass_expiry_period');
60
}
drupal7/sites/all/modules/recovery_pass/recovery_pass.module
1
<?php
2
/**
3
 * @file
4
 * Alters default Drupal password recovery process by overriding default submit.
5
 */
6

  
7
/**
8
 * Implements hook_help().
9
 */
10
function recovery_pass_help($path, $arg) {
11
  $output = '';
12
  switch ($path) {
13
    case 'admin/help#recovery_pass':
14
      $output = file_get_contents(drupal_get_path('module', 'recovery_pass') . '/README.txt');
15
  }
16
  return $output;
17
}
18

  
19
/**
20
 * Implements hook_ctools_plugin_api().
21
 */
22
function recovery_pass_ctools_plugin_api($owner, $api) {
23
  if ($owner == 'services' && $api == 'services') {
24
    return array(
25
      'version' => 3,
26
      'file' => 'recovery_pass.services.inc'
27
    );
28
  }
29
}
30

  
31
/**
32
 * Implements hook_menu().
33
 */
34
function recovery_pass_menu() {
35
  $items = array();
36

  
37
  // Menu item for module configurations.
38
  $items['admin/config/people/recovery-pass'] = array(
39
    'title' => 'Recovery Password Configuration',
40
    'description' => 'Configure email message to be sent to user for password recovery.',
41
    'page callback' => 'drupal_get_form',
42
    'page arguments' => array('recovery_pass_config_form'),
43
    'access arguments' => array('administer users'),
44
    'file' => 'recovery_pass.admin.inc',
45
  );
46
  return $items;
47
}
48

  
49
/**
50
 * Implements hook_form_FORM_ID_alter().
51
 */
52
function recovery_pass_form_user_pass_alter(&$form, &$form_state, $form_id) {
53
  // Overrides default submit handler for user_pass form.
54
  $form['#submit'] = array_diff($form['#submit'], array('user_pass_submit'));
55
  array_unshift($form['#submit'], 'recovery_pass_forgot_password_submit');
56
}
57

  
58
/**
59
 * Custom submit handler to send password in recovery mail.
60
 */
61
function recovery_pass_forgot_password_submit($form, &$form_state) {
62
  global $language;
63
  $user = $form_state['values']['account'];
64

  
65
  // Generate random password.
66
  $random_password = user_password();
67
  // Store Old Hash Password Temporarily.
68
  if (!_recovery_pass_store_old_pass($user)) {
69
    watchdog('recovery_pass', 'Error saving old password for user @id', array('@id' => $user->uid), WATCHDOG_NOTICE, 'link');
70
  }
71
  // Save new password.
72
  user_save($user, array('pass' => $random_password), 'account');
73

  
74
  // Retrive email body and subject.
75
  $message = _recovery_pass_mail_text('email_text', $language, TRUE, $user);
76
  if ($message) {
77
    // Replace [user_new_password] placeholder with new password.
78
    $message = str_replace("[user_new_password]", $random_password, $message);
79
  }
80
  $subject = _recovery_pass_mail_text('email_subject', $language, TRUE, $user);
81
  if (module_exists("htmlmail")) {
82
    // For html mail convert new lines to br.
83
    $message = nl2br($message);
84
  }
85
  $params = array(
86
    'body' => $message,
87
    'subject' => $subject,
88
  );
89
  $to = $user->mail;
90
  $from = variable_get('site_mail');
91
  if (drupal_mail('recovery_pass', 'recovery_pass', $to, language_default(), $params, $from, TRUE)) {
92
    drupal_set_message(t("Further instructions have been sent to your registered Email-id."), 'status', FALSE);
93
  }
94
  else {
95
    drupal_set_message(t("Error Sending Recovery Mail. Please contact site administrator."), 'error', FALSE);
96
  }
97
  $form_state['redirect'] = variable_get('recovery_pass_fpass_redirect', 'user');
98
}
99

  
100
/**
101
 * Temporarily stores old password in custom table for error message in future.
102
 */
103
function _recovery_pass_store_old_pass($user) {
104
  // Update or Insert using db_merge() the old password.
105
  $result = db_merge('recovery_pass')
106
    ->key(array('uid' => $user->uid))
107
    ->fields(array(
108
        'uid' => (int) $user->uid,
109
        'old_pass' => $user->pass,
110
        'changed' => time(),
111
    ))
112
    ->execute();
113
  if ($result) {
114
    // Successfully saved old password.
115
    return TRUE;
116
  }
117
  return FALSE;
118
}
119

  
120
/**
121
 * Implements hook_mail().
122
 */
123
function recovery_pass_mail($key, &$message, $params) {
124
  switch ($key) {
125
    case 'recovery_pass':
126
      // Mail parameters used for recovery mail.
127
      $message['subject'] = $params['subject'];
128
      $message['body'][] = $params['body'];
129
      if (module_exists("htmlmail")) {
130
        // For html mail.
131
        $message['headers']['Content-Type'] = 'text/html; charset=UTF-8; format=flowed';
132
      }
133
      break;
134
  }
135
}
136

  
137
/**
138
 * Returns a mail string for a variable name.
139
 *
140
 * Used by recovery_pass_mail() and the settings forms to retrieve strings.
141
 */
142
function _recovery_pass_mail_text($key, $language = NULL, $replace = TRUE, $user = array()) {
143
  $langcode = !empty($language) ? $language->language : NULL;
144
  $text = '';
145

  
146
  if ($admin_setting = variable_get('recovery_pass_' . $key, FALSE)) {
147
    // An admin setting overrides the default string.
148
    $text = $admin_setting;
149
  }
150
  else {
151
    // No override, return default string.
152
    switch ($key) {
153
      case 'email_subject':
154
        $text = t('Replacement login information for [user:name] at [site:name]', array(), array('langcode' => $langcode));
155
        break;
156

  
157
      case 'email_text':
158
        $text = t("[user:name],
159

  
160
A request to reset the password for your account has been made at [site:name].
161

  
162
Your new password is [user_new_password].
163

  
164

  
165
--  [site:name] team", array(), array('langcode' => $langcode));
166
        break;
167

  
168
      case 'old_pass_warning':
169
        $text = t('You are using <strong>old password</strong>, your password was reset recently. New Password was sent to your registered email id.');
170
        break;
171
    }
172
  }
173

  
174
  if ($replace) {
175
    // Token Replace the text.
176
    return token_replace($text, array('user' => $user));
177
  }
178

  
179
  return $text;
180
}
181

  
182
/**
183
 * Implements hook_form_alter().
184
 */
185
function recovery_pass_form_alter(&$form, &$form_state, $form_id) {
186
  if (variable_get('recovery_pass_old_pass_show', 1)) {
187
    switch ($form_id) {
188
      case 'user_login_block':
189
      case 'user_login':
190
        // Extending default drupal login validators.
191
        $insert = 'recovery_pass_user_login_validate';
192
        $form['#validate'] = _recovery_pass_insert_array($form['#validate'], 1, $insert);
193
        break;
194
    }
195
  }
196
}
197

  
198
/**
199
 * To insert our validator at index 1 between the default validators.
200
 */
201
function _recovery_pass_insert_array($array, $index, $val) {
202
  // Because this will be used one more time.
203
  $size = count($array);
204
  if (!is_int($index) || $index < 0 || $index > $size) {
205
    return -1;
206
  }
207
  else {
208
    $temp   = array_slice($array, 0, $index);
209
    $temp[] = $val;
210
    return array_merge($temp, array_slice($array, $index, $size));
211
  }
212
}
213

  
214
/**
215
 * Custom Submit handler for user login form.
216
 *
217
 * Incase user tries to login using old pass then error msg is shown that pass
218
 * has been reset, till user tries any other pass.
219
 */
220
function recovery_pass_user_login_validate($form, &$form_state) {
221
  $input_password = trim($form_state['values']['pass']);
222
  if (!empty($form_state['values']['name']) && !empty($input_password)) {
223
    $account = db_query("SELECT uid,pass FROM {users} WHERE name = :name AND status = 1", array(':name' => $form_state['values']['name']))->fetchObject();
224
    // Check uid exists in recovery_pass table.
225
    $result = db_select('recovery_pass', 'r')
226
      ->fields('r', array('uid', 'old_pass'))
227
      ->condition('uid', (int) $account->uid)
228
      ->execute()
229
      ->fetchAssoc();
230
    if ($result) {
231
      // If uid exists in table.
232
      $old_password = $result['old_pass'];
233
      // Match input password with password stored in recovery_pass table.
234
      if (_recovery_pass_match_old_password($input_password, $old_password)) {
235
        drupal_set_message(_recovery_pass_mail_text('old_pass_warning'), 'warning', FALSE);
236
      }
237
      else {
238
        // Irrespective of the input password delete the entry.
239
        $entry_deleted = db_delete('recovery_pass')
240
          ->condition('uid', $result['uid'])
241
          ->execute();
242
        if (!$entry_deleted) {
243
          watchdog('recovery_pass', 'Error deleting entry from recovery_table for user @id', array('@id' => $result['uid']), WATCHDOG_NOTICE, 'link');
244
        }
245
      }
246
    }
247
  }
248
}
249

  
250
/**
251
 * Matches old password stored in recovery_pass table with user input password.
252
 */
253
function _recovery_pass_match_old_password($password, $old_password) {
254
  // Allow alternate password hashing schemes.
255
  require_once DRUPAL_ROOT . '/' . variable_get('password_inc', 'includes/password.inc');
256
  if (substr($old_password, 0, 2) == 'U$') {
257
    // This may be an updated password from user_update_7000(). Such hashes
258
    // have 'U' added as the first character and need an extra md5().
259
    $stored_hash = substr($old_password, 1);
260
    $password = md5($password);
261
  }
262
  else {
263
    $stored_hash = $old_password;
264
  }
265

  
266
  $type = substr($stored_hash, 0, 3);
267
  switch ($type) {
268
    case '$S$':
269
      // A normal Drupal 7 password using sha512.
270
      $hash = _password_crypt('sha512', $password, $stored_hash);
271
      break;
272

  
273
    case '$H$':
274
      // phpBB3 uses "$H$" for the same thing as "$P$".
275
    case '$P$':
276
      // A phpass password generated using md5.  This is an
277
      // imported password or from an earlier Drupal version.
278
      $hash = _password_crypt('md5', $password, $stored_hash);
279
      break;
280

  
281
    default:
282
      return FALSE;
283
  }
284
  return ($hash && $stored_hash == $hash);
285
}
286

  
287
/**
288
 * Implements hook_cron().
289
 */
290
function recovery_pass_cron() {
291
  $expiry_period = strtotime("-" . variable_get('recovery_pass_expiry_period', '1') . " week");
292
  // Delete all records more created than one week ago.
293
  $entry_deleted = db_delete('recovery_pass')
294
    ->condition('changed', $expiry_period, '<')
295
    ->execute();
296

  
297
  if ($entry_deleted) {
298
    watchdog('recovery_pass', 'Error deleting entry from recovery_table at cron time.', array(), WATCHDOG_NOTICE, 'link');
299
  }
300
}
drupal7/sites/all/modules/recovery_pass/recovery_pass.resource.inc
1
<?php
2

  
3
function _recovery_pass_request_new_password($user = NULL) {
4
  global $language;
5
  $user = trim($user);
6
  $user = user_load_by_name($user);
7

  
8
  // Generate random password.
9
  $random_password = user_password();
10
  // Store Old Hash Password Temporarily.
11
  if (!_recovery_pass_store_old_pass($user)) {
12
    watchdog('recovery_pass', 'Error saving old password for user @id', array('@id' => $user->uid), WATCHDOG_NOTICE, 'link');
13
  }
14
  // Save new password.
15
  user_save($user, array('pass' => $random_password), 'account');
16

  
17
  // Retrive email body and subject.
18
  $message = _recovery_pass_mail_text('email_text', $language, TRUE, $user);
19
  if ($message) {
20
    // Replace [user_new_password] placeholder with new password.
21
    $message = str_replace("[user_new_password]", $random_password, $message);
22
  }
23
  $subject = _recovery_pass_mail_text('email_subject', $language, TRUE, $user);
24
  if (module_exists("htmlmail")) {
25
    // For html mail convert new lines to br.
26
    $message = nl2br($message);
27
  }
28
  $params = array(
29
    'body' => $message,
30
    'subject' => $subject,
31
  );
32
  $to = $user->mail;
33
  $from = variable_get('site_mail');
34
  if (drupal_mail('recovery_pass', 'recovery_pass', $to, language_default(), $params, $from, TRUE)) {
35
    return TRUE;
36
  }
37
  else {
38
    return services_error(t("Error Sending Recovery Mail. Please contact site administrator."), 406);
39
  }
40
}
41

  
42
function _recovery_pass_resource_access() {
43
  return TRUE;
44
}
drupal7/sites/all/modules/recovery_pass/recovery_pass.services.inc
1
<?php
2

  
3
/**
4
 * Implements hook_services_resources().
5
 */
6
function recovery_pass_services_resources() {
7
  $resources = array(
8
    'recovery_pass' => array(
9
      'operations' => array(
10
        'retrieve' => array(
11
          'help' => 'Request a new password, given a e-mail address',
12
          'file' => array(
13
            'type' => 'inc',
14
            'module' => 'recovery_pass',
15
            'name' => 'recovery_pass.resource',
16
          ),
17
          'callback' => '_recovery_pass_request_new_password',
18
          'args' => array(
19
            array(
20
              'name' => 'user',
21
              'type' => 'string',
22
              'description' => 'The username to request new password for.',
23
              'source' => array('path' => 0),
24
              'optional' => FALSE,
25
            ),
26
          ),
27
          'access callback' => '_recovery_pass_resource_access',
28
        ),
29
      ),
30
    ),
31
  );
32
  return $resources;
33
}
drupal7/sites/all/modules/recovery_pass/recovery_pass.variable.inc
1
<?php
2
/**
3
 * @file
4
 *
5
 * Variable information for Recovery Password.
6
 */
7

  
8
/**
9
 * Implements hook_variable_info().
10
 */
11
function recovery_pass_variable_info($options) {
12
  $variables['recovery_pass_email_subject'] = array(
13
    'type' => 'string',
14
    'title' => t('Email Subject', array(), $options),
15
    'default' => _recovery_pass_mail_text('email_subject'),
16
    'description' => t('Recovery Password Email subject', array(), $options),
17
    'required' => TRUE,
18
    'localize' => TRUE,
19
    'group' => 'recovery_pass',
20
  );
21
  $variables['recovery_pass_email_text'] = array(
22
    'type' => 'text',
23
    'title' => t('Email Body', array(), $options),
24
    'default' => _recovery_pass_mail_text('email_text'),
25
    'description' => t('Recovery Password Email Body', array(), $options),
26
    'required' => TRUE,
27
    'localize' => TRUE,
28
    'group' => 'recovery_pass',
29
  );
30
  $variables['recovery_pass_old_pass_warning'] = array(
31
    'type' => 'text',
32
    'title' => t('Old Password Warning', array(), $options),
33
    'default' => _recovery_pass_mail_text('old_pass_warning'),
34
    'description' => t('Old Password Warning Message', array(), $options),
35
    'required' => TRUE,
36
    'localize' => TRUE,
37
    'group' => 'recovery_pass',
38
  );
39
  return $variables;
40
}
41

  
42
/**
43
 * Implements hook_variable_group_info().
44
 */
45
function recovery_pass_variable_group_info() {
46
  $groups['recovery_pass'] = array(
47
    'title' => t('Recovery Password'),
48
    'access' => 'administer users',
49
    'path' => 'admin/config/people/recovery-pass',
50
  );
51
  return $groups;
52
}

Also available in: Unified diff