Project

General

Profile

« Previous | Next » 

Revision 293

Added by stefan over 18 years ago

Forgotten password: if sending of e-mail fails, restore old password. Ticket #110

View differences:

forgot_form.php
37 37
	$email = $_POST['email'];
38 38
	
39 39
	// Check if the email exists in the database
40
	$query = "SELECT user_id,username,display_name,email,last_reset FROM ".TABLE_PREFIX."users WHERE email = '".$wb->add_slashes($_POST['email'])."'";
40
	$query = "SELECT user_id,username,display_name,email,last_reset,password FROM ".TABLE_PREFIX."users WHERE email = '".$wb->add_slashes($_POST['email'])."'";
41 41
	$results = $database->query($query);
42 42
	if($results->numRows() > 0) {
43 43
		// Get the id, username, and email from the above db query
......
65 65
				$new_pass = $new_pass . $tmp;
66 66
				$i++;
67 67
			}
68
			
68
			$old_pass = $results_array['password'];
69 69
			$database->query("UPDATE ".TABLE_PREFIX."users SET password = '".md5($new_pass)."' WHERE user_id = '".$results_array['user_id']."'");
70 70
			
71 71
			if($database->is_error()) {
......
91 91
					$message = $MESSAGE['FORGOT_PASS']['PASSWORD_RESET'];
92 92
					$display_form = false;
93 93
				} else {
94
  					$database->query("UPDATE ".TABLE_PREFIX."users SET password = '".$old_pass."' WHERE user_id = '".$results_array['user_id']."'");
94 95
					$message = $MESSAGE['FORGOT_PASS']['CANNOT_EMAIL'];
95 96
				}
96 97
			}

Also available in: Unified diff