codekingpro/portable-devtools
114k
1"""2 flask_security.recoverable3 ~~~~~~~~~~~~~~~~~~~~~~~~~~4 5 Flask-Security recoverable module6 7 :copyright: (c) 2012 by Matt Wright.8 :copyright: (c) 2019-2023 by J. Christopher Wagner (jwag).9 :license: MIT, see LICENSE for more details.10"""11 12from flask import current_app13from .proxies import _security, _datastore14from .signals import password_reset, reset_password_instructions_sent15from .utils import (16 config_value,17 get_token_status,18 hash_data,19 hash_password,20 send_mail,21 url_for_security,22 verify_hash,23)24 25 26def send_reset_password_instructions(user):27 """Sends the reset password instructions email for the specified user.28 29 :param user: The user to send the instructions to30 """31 token = generate_reset_password_token(user)32 reset_link = url_for_security("reset_password", token=token, _external=True)33 34 if config_value("SEND_PASSWORD_RESET_EMAIL"):35 send_mail(36 config_value("EMAIL_SUBJECT_PASSWORD_RESET"),37 user.email,38 "reset_instructions",39 user=user,40 reset_link=reset_link,41 reset_token=token,42 )43 44 reset_password_instructions_sent.send(45 current_app._get_current_object(),46 _async_wrapper=current_app.ensure_sync,47 user=user,48 token=token,49 reset_token=token,50 )51 52 53def send_password_reset_notice(user):54 """Sends the password reset notice email for the specified user.55 56 :param user: The user to send the notice to57 """58 if config_value("SEND_PASSWORD_RESET_NOTICE_EMAIL"):59 send_mail(60 config_value("EMAIL_SUBJECT_PASSWORD_NOTICE"),61 user.email,62 "reset_notice",63 user=user,64 )65 66 67def generate_reset_password_token(user):68 """Generates a unique reset password token for the specified user.69 70 :param user: The user to work with71 """72 password_hash = hash_data(user.password) if user.password else None73 data = [str(user.fs_uniquifier), password_hash]74 return _security.reset_serializer.dumps(data)75 76 77def reset_password_token_status(token):78 """Returns the expired status, invalid status, and user of a password reset79 token. For example::80 81 expired, invalid, user, data = reset_password_token_status('...')82 83 :param token: The password reset token84 """85 expired, invalid, user, data = get_token_status(86 token, "reset", "RESET_PASSWORD", return_data=True87 )88 # This check looks to see if the password has been changed since the reset token89 # was created. As of #338 - we reset the fs_uniquifier on each password change90 # so the token would have been marked invalid above.91 # This made sure that the token couldn't be used twice.92 # TODO - look at removing this entire check.93 if not invalid and user:94 if user.password:95 if not verify_hash(data[1], user.password):96 invalid = True97 98 return expired, invalid, user99 100 101def update_password(user, password):102 """Update the specified user's password103 104 :param user: The user to update_password105 :param password: The unhashed new password106 """107 user.password = hash_password(password)108 # Change uniquifier - this will cause ALL sessions to be invalidated.109 _datastore.set_uniquifier(user)110 _datastore.put(user)111 send_password_reset_notice(user)112 password_reset.send(113 current_app._get_current_object(),114 _async_wrapper=current_app.ensure_sync,115 user=user,116 )117 