Packages
openmaize
1.0.0-beta.4
3.0.1
retired
3.0.0
2.9.0
2.8.0
2.7.0
2.6.0
2.5.1
2.5.0
2.4.0
2.3.2
2.3.1
2.3.0
2.2.0
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0
1.0.1
1.0.0
1.0.0-beta.5
1.0.0-beta.4
1.0.0-beta.3
1.0.0-beta.2
1.0.0-beta.1
1.0.0-beta.0
0.19.3
0.19.2
0.19.1
0.19.0
0.18.1
0.18.0
0.17.2
0.17.1
0.17.0
0.16.2
0.16.1
0.16.0
0.15.1
0.15.0
0.14.0
0.13.0
0.12.0
0.11.1
0.11.0
0.10.2
0.10.1
0.10.0
0.8.1
0.8.0
0.7.5
0.7.4
0.7.2
0.7.1
0.7.0
0.6.7
0.6.6
0.6.3
0.6.2
0.6.1
0.6.0
0.5.0
0.4.1
0.4.0
Authentication library for Elixir using Plug
Current section
Files
Jump to
Current section
Files
lib/openmaize/reset_password.ex
defmodule Openmaize.ResetPassword do
@moduledoc """
Authenticate a user when resetting the password.
## Options
There are four options:
* db_module - the module that is used to query the database
* in most cases, this will be generated by `mix openmaize.gen.ectodb` and will be called MyApp.OpenmaizeEcto
* if you implement your own database module, it needs to implement the Openmaize.Database behaviour
* key_expires_after - the length, in minutes, that the token is valid for
* the default is 120 minutes (2 hours)
* unique_id - the identifier in the query string, or the parameters
* the default is :email
* mail_function - the emailing function that you need to define
## Reset password form
This function is to be used with the `reset` post request. For the
`reset` get request, you need to render a form with the name "user",
using `[as: :user]` if you are using Phoenix's `form_for` function,
which contains values for the password, email and key (the email and
key should be hidden inputs).
Before hashing the user's password and adding the hash to the database,
it is checked to make sure that it is long enough and, if you have
NotQwerty123 installed, not too weak.
## Examples
First, define a `post "/reset", SomeController, :reset_password` route
in the web/router.ex file. Then, add the following command to the
relevant controller file:
plug Openmaize.ResetPassword, [db_module: MyApp.OpenmaizeEcto,
mail_function: &Mailer.send_receipt/1] when action in [:reset_password]
This command will be run when the user sends the form with the data to
reset the password. You will need to write a function to handle the
`get "/reset"` request, that is, to render the form to reset the password.
"""
use Openmaize.Confirm.Base
def call(_, {nil, _}) do
raise ArgumentError, "You need to set the db_module value for Openmaize.ResetPassword"
end
def call(%Plug.Conn{params: %{"user" =>
%{"key" => key, "password" => password} = user_params}} = conn, opts)
when byte_size(key) == 32 do
check_user_key(conn, user_params, key, password, opts)
end
def call(conn, _opts), do: invalid_link_error(conn)
end