← All changes
|
src/DonorDashboards/Tabs/EditProfileTab/PasswordRoute.php
+35
-8
4.16.2
→
4.18.0
View file →
| @@ -1,12 +1,12 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | namespace Give\DonorDashboards\Tabs\EditProfileTab; |
| 4 | 4 | |
| 5 | -use Give\DonorDashboards\Helpers\SanitizeProfileData as SanitizeHelper; | |
| 6 | -use Give\DonorDashboards\Profile as Profile; | |
| 5 | +use Give\Donors\Models\Donor; | |
| 7 | 6 | use Give\DonorDashboards\Tabs\Contracts\Route as RouteAbstract; |
| 8 | 7 | use WP_REST_Request; |
| 8 | +use WP_REST_Response; | |
| 9 | 9 | |
| 10 | 10 | /** |
| 11 | 11 | * @since 2.10.0 |
| 12 | 12 | */ |
| @@ -37,21 +37,48 @@ | ||
| 37 | 37 | |
| 38 | 38 | /** |
| 39 | 39 | * Handles password update. |
| 40 | 40 | * |
| 41 | + * @since 4.16.6 added password validation | |
| 41 | 42 | * @since 3.3.0 |
| 42 | 43 | * |
| 43 | 44 | * @param WP_REST_Request $request |
| 44 | 45 | * |
| 45 | - * @return array | |
| 46 | - * | |
| 46 | + * @return array|WP_REST_Response | |
| 47 | 47 | */ |
| 48 | 48 | public function handleRequest(WP_REST_Request $request) |
| 49 | 49 | { |
| 50 | - wp_update_user([ | |
| 51 | - 'ID' => wp_get_current_user()->ID, | |
| 52 | - 'user_pass' => $request->get_param('newPassword'), | |
| 53 | - ]); | |
| 50 | + $newPassword = trim($request->get_param('newPassword')); | |
| 51 | + | |
| 52 | + if (empty($newPassword)) { | |
| 53 | + return new WP_REST_Response( | |
| 54 | + [ | |
| 55 | + 'status' => 400, | |
| 56 | + 'response' => 'invalid_password', | |
| 57 | + 'body_response' => [ | |
| 58 | + 'message' => esc_html__('Please enter a valid password.', 'give'), | |
| 59 | + ], | |
| 60 | + ] | |
| 61 | + ); | |
| 62 | + } | |
| 63 | + | |
| 64 | + $donorId = give()->donorDashboard->getId(); | |
| 65 | + | |
| 66 | + $donor = Donor::find($donorId); | |
| 67 | + | |
| 68 | + if ( ! $donor || empty($donor->userId)) { | |
| 69 | + return new WP_REST_Response( | |
| 70 | + [ | |
| 71 | + 'status' => 400, | |
| 72 | + 'response' => 'no_user_account', | |
| 73 | + 'body_response' => [ | |
| 74 | + 'message' => esc_html__('Unable to update password. Contact a site administrator.', 'give'), | |
| 75 | + ], | |
| 76 | + ] | |
| 77 | + ); | |
| 78 | + } | |
| 79 | + | |
| 80 | + wp_set_password($newPassword, $donor->userId); | |
| 54 | 81 | |
| 55 | 82 | return [ |
| 56 | 83 | 'success' => true, |
| 57 | 84 | ]; |