Option to force a user to change his password (#3872).

git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@12081 e93f8b46-1217-0410-a6f0-8f06a7374b81
This commit is contained in:
Jean-Philippe Lang
2013-08-05 17:58:33 +00:00
parent bd4fba08e5
commit b764e39847
10 changed files with 78 additions and 6 deletions
+8 -3
View File
@@ -17,6 +17,8 @@
class MyController < ApplicationController
before_filter :require_login
# let user change his password when he has to
skip_before_filter :check_password_change, :only => :password
helper :issues
helper :users
@@ -90,14 +92,17 @@ class MyController < ApplicationController
return
end
if request.post?
if @user.check_password?(params[:password])
if !@user.check_password?(params[:password])
flash.now[:error] = l(:notice_account_wrong_password)
elsif params[:password] == params[:new_password]
flash.now[:error] = 'Your new password must be different from your current password'
else
@user.password, @user.password_confirmation = params[:new_password], params[:new_password_confirmation]
@user.must_change_passwd = false
if @user.save
flash[:notice] = l(:notice_account_password_updated)
redirect_to my_account_path
end
else
flash[:error] = l(:notice_account_wrong_password)
end
end
end