Search moodle.org's
Developer Documentation

See Release Notes

  • Bug fixes for general core bugs in 3.10.x will end 8 November 2021 (12 months).
  • Bug fixes for security issues in 3.10.x will end 9 May 2022 (18 months).
  • PHP version: minimum PHP 7.2.0 Note: minimum PHP version has increased since Moodle 3.8. PHP 7.3.x and 7.4.x are supported too.

Differences Between: [Versions 310 and 400] [Versions 310 and 401] [Versions 310 and 402] [Versions 310 and 403]

   1  <?php
   2  // This file is part of Moodle - http://moodle.org/
   3  //
   4  // Moodle is free software: you can redistribute it and/or modify
   5  // it under the terms of the GNU General Public License as published by
   6  // the Free Software Foundation, either version 3 of the License, or
   7  // (at your option) any later version.
   8  //
   9  // Moodle is distributed in the hope that it will be useful,
  10  // but WITHOUT ANY WARRANTY; without even the implied warranty of
  11  // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
  12  // GNU General Public License for more details.
  13  //
  14  // You should have received a copy of the GNU General Public License
  15  // along with Moodle.  If not, see <http://www.gnu.org/licenses/>.
  16  
  17  /**
  18   * Forgot password routine.
  19   *
  20   * Finds the user and calls the appropriate routine for their authentication type.
  21   *
  22   * There are several pathways to/through this page, summarised below:
  23   * 1. User clicks the 'forgotten your username or password?' link on the login page.
  24   *  - No token is received, render the username/email search form.
  25   * 2. User clicks the link in the forgot password email
  26   *  - Token received as GET param, store the token in session, redirect to self
  27   * 3. Redirected from (2)
  28   *  - Fetch token from session, and continue to run the reset routine defined in 'core_login_process_password_set()'.
  29   *
  30   * @package    core
  31   * @subpackage auth
  32   * @copyright  1999 onwards Martin Dougiamas  http://dougiamas.com
  33   * @license    http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
  34   */
  35  
  36  require('../config.php');
  37  require_once($CFG->libdir.'/authlib.php');
  38  require_once (__DIR__ . '/lib.php');
  39  require_once ('forgot_password_form.php');
  40  require_once ('set_password_form.php');
  41  
  42  $token = optional_param('token', false, PARAM_ALPHANUM);
  43  
  44  $PAGE->set_url('/login/forgot_password.php');
  45  $systemcontext = context_system::instance();
  46  $PAGE->set_context($systemcontext);
  47  
  48  // setup text strings
  49  $strforgotten = get_string('passwordforgotten');
  50  $strlogin     = get_string('login');
  51  
  52  $PAGE->navbar->add($strlogin, get_login_url());
  53  $PAGE->navbar->add($strforgotten);
  54  $PAGE->set_title($strforgotten);
  55  $PAGE->set_heading($COURSE->fullname);
  56  
  57  // if alternatepasswordurl is defined, then we'll just head there
  58  if (!empty($CFG->forgottenpasswordurl)) {
  59      redirect($CFG->forgottenpasswordurl);
  60  }
  61  
  62  // if you are logged in then you shouldn't be here!
  63  if (isloggedin() and !isguestuser()) {
  64      redirect($CFG->wwwroot.'/index.php', get_string('loginalready'), 5);
  65  }
  66  
  67  // Fetch the token from the session, if present, and unset the session var immediately.
  68  $tokeninsession = false;
  69  if (!empty($SESSION->password_reset_token)) {
  70      $token = $SESSION->password_reset_token;
  71      unset($SESSION->password_reset_token);
  72      $tokeninsession = true;
  73  }
  74  
  75  if (empty($token)) {
  76      // This is a new password reset request.
  77      // Process the request; identify the user & send confirmation email.
  78      core_login_process_password_reset_request();
  79  } else {
  80      // A token has been found, but not in the session, and not from a form post.
  81      // This must be the user following the original rest link, so store the reset token in the session and redirect to self.
  82      // The session var is intentionally used only during the lifespan of one request (the redirect) and is unset above.
  83      if (!$tokeninsession && $_SERVER['REQUEST_METHOD'] === 'GET') {
  84          $SESSION->password_reset_token = $token;
  85          redirect($CFG->wwwroot . '/login/forgot_password.php');
  86      } else {
  87          // Continue with the password reset process.
  88          core_login_process_password_set($token);
  89      }
  90  }