1
0
mirror of https://github.com/pocketbase/pocketbase.git synced 2025-01-25 14:43:42 +02:00
pocketbase/forms/admin_password_reset_request.go

89 lines
2.5 KiB
Go
Raw Normal View History

2022-07-07 00:19:05 +03:00
package forms
import (
"errors"
"time"
validation "github.com/go-ozzo/ozzo-validation/v4"
"github.com/go-ozzo/ozzo-validation/v4/is"
"github.com/pocketbase/pocketbase/core"
2022-08-07 15:38:21 +03:00
"github.com/pocketbase/pocketbase/daos"
2022-07-07 00:19:05 +03:00
"github.com/pocketbase/pocketbase/mails"
"github.com/pocketbase/pocketbase/models"
2022-07-07 00:19:05 +03:00
"github.com/pocketbase/pocketbase/tools/types"
)
2022-10-30 10:28:14 +02:00
// AdminPasswordResetRequest is an admin password reset request form.
2022-07-07 00:19:05 +03:00
type AdminPasswordResetRequest struct {
2022-10-30 10:28:14 +02:00
app core.App
dao *daos.Dao
resendThreshold float64 // in seconds
2022-07-07 00:19:05 +03:00
Email string `form:"email" json:"email"`
}
2022-08-07 15:38:21 +03:00
// NewAdminPasswordResetRequest creates a new [AdminPasswordResetRequest]
2022-10-30 10:28:14 +02:00
// form initialized with from the provided [core.App] instance.
2022-08-07 15:38:21 +03:00
//
2022-10-30 10:28:14 +02:00
// If you want to submit the form as part of a transaction,
// you can change the default Dao via [SetDao()].
2022-07-07 00:19:05 +03:00
func NewAdminPasswordResetRequest(app core.App) *AdminPasswordResetRequest {
2022-10-30 10:28:14 +02:00
return &AdminPasswordResetRequest{
app: app,
dao: app.Dao(),
resendThreshold: 120, // 2min
2022-08-07 15:38:21 +03:00
}
2022-10-30 10:28:14 +02:00
}
2022-08-07 15:38:21 +03:00
2022-10-30 10:28:14 +02:00
// SetDao replaces the default form Dao instance with the provided one.
func (form *AdminPasswordResetRequest) SetDao(dao *daos.Dao) {
form.dao = dao
2022-07-07 00:19:05 +03:00
}
// Validate makes the form validatable by implementing [validation.Validatable] interface.
//
// This method doesn't verify that admin with `form.Email` exists (this is done on Submit).
func (form *AdminPasswordResetRequest) Validate() error {
return validation.ValidateStruct(form,
validation.Field(
&form.Email,
validation.Required,
validation.Length(1, 255),
is.EmailFormat,
2022-07-07 00:19:05 +03:00
),
)
}
// Submit validates and submits the form.
// On success sends a password reset email to the `form.Email` admin.
//
// You can optionally provide a list of InterceptorFunc to further
// modify the form behavior before persisting it.
func (form *AdminPasswordResetRequest) Submit(interceptors ...InterceptorFunc[*models.Admin]) error {
2022-07-07 00:19:05 +03:00
if err := form.Validate(); err != nil {
return err
}
2022-10-30 10:28:14 +02:00
admin, err := form.dao.FindAdminByEmail(form.Email)
2022-07-07 00:19:05 +03:00
if err != nil {
return err
}
now := time.Now().UTC()
lastResetSentAt := admin.LastResetSentAt.Time()
2022-10-30 10:28:14 +02:00
if now.Sub(lastResetSentAt).Seconds() < form.resendThreshold {
2022-07-07 00:19:05 +03:00
return errors.New("You have already requested a password reset.")
}
// update last sent timestamp
admin.LastResetSentAt = types.NowDateTime()
return runInterceptors(admin, func(m *models.Admin) error {
if err := mails.SendAdminPasswordReset(form.app, m); err != nil {
return err
}
return form.dao.SaveAdmin(m)
}, interceptors...)
2022-07-07 00:19:05 +03:00
}