Add password reset

Closes #15
This commit is contained in:
ricola 2025-06-07 18:38:33 -06:00
parent 84278741a5
commit fa4f77c365
14 changed files with 222 additions and 32 deletions

View file

@ -4,7 +4,9 @@ require 'bcrypt'
require 'gettext'
require 'securerandom'
require 'chartkick'
require 'mail'
require_relative 'mj'
require_relative "config/environments/#{settings.environment}"
class Vote < ActiveRecord::Base
has_many :candidates, dependent: :destroy
@ -65,6 +67,7 @@ set :values, [ { :id => 1, :label => _("Awful"), :color => '#ff4500' },
{ :id => 4, :label => _("Mediocre"), :color => '#9acd32' },
{ :id => 5, :label => _("Good"), :color => '#228b22' },
{ :id => 6, :label => _("Very good"), :color => '#006400' } ]
set :admin_email, 'vedia@potager.org'
MajorityJudgment.values = settings.values
get '/' do
@ -107,6 +110,10 @@ end
post '/login' do
user = User.find_by(email: params[:email])
if user && verify_password(params[:password], user.password)
if not user.reset.nil?
user.reset = nil
user.save
end
session.clear
session[:user_id] = user.id
redirect '/'
@ -116,6 +123,57 @@ post '/login' do
end
end
get '/reset' do
erb :reset
end
post '/reset' do
@user = User.find_by(email: params[:email])
if @user
@user.reset = SecureRandom.uuid
@user.save
mail = Mail.new
mail.from = settings.admin_email
mail.to = @user.email
mail.subject = _("Reset your password")
mail.body = erb :reset_email, :layout => false
mail.deliver
end
erb :reset_sent
end
get '/reset/:uuid' do
@user = User.find_by(reset: params[:uuid])
if @user
erb :reset_change
else
erb :reset_invalid
end
end
post '/reset/:uuid' do
@user = User.find_by(reset: params[:uuid])
if @user
@errors = []
if params[:password].empty?
@errors << OpenStruct.new(:attribute => :password, :type => :blank)
else
@user.password = hash_password(params[:password])
end
if @errors.empty? and @user.valid?
@user.reset = nil
@user.save
session.clear
session[:user_id] = @user.id
redirect '/'
else
erb :reset_change
end
else
erb :reset_invalid
end
end
get '/logout' do
session.clear
redirect '/login'