refined EditProfile page by adding password reset option in case user has validated e-mail address

This commit is contained in:
Axel Uhl committed 2014-10-20 20:33:08 +02:00
1 parent 356391b1cb
commit 31a6d1741f
8 files changed
+82 -21

No files matched your search

@@ -23,6 +23,7 @@ import com.google.gwt.user.client.ui.RootLayoutPanel;
import com.google.gwt.user.client.ui.SubmitButton;
import com.google.gwt.user.client.ui.TextBox;
import com.sap.sse.gwt.client.EntryPointHelper;
import com.sap.sse.gwt.client.async.MarkedAsyncCallback;
import com.sap.sse.security.shared.UserManagementException;
import com.sap.sse.security.ui.client.RemoteServiceMappingConstants;
import com.sap.sse.security.ui.client.StringMessages;
@@ -71,6 +72,40 @@ public class EditProfileEntryPoint implements EntryPoint {
emailText.setEnabled(false);
emailTextBoxAndButtonPanel.add(emailText);
final Button updateEmailButton = new Button(stringMessages.editEmail());
emailTextBoxAndButtonPanel.add(updateEmailButton);
fp.add(emailTextBoxAndButtonPanel);
Label currentPasswordLabel = new Label(stringMessages.currentPassword());
fp.add(currentPasswordLabel);
HorizontalPanel currentPasswordAndResetButtonPanel = new HorizontalPanel();
final TextBox currentPasswordText = new PasswordTextBox();
currentPasswordAndResetButtonPanel.add(currentPasswordText);
final Button passwordReset = new Button(stringMessages.resetPassword());
passwordReset.addClickHandler(new ClickHandler() {
@Override
public void onClick(ClickEvent event) {
userManagementService.resetPassword(nameText.getText(), new MarkedAsyncCallback<Void>(new AsyncCallback<Void>() {
@Override
public void onFailure(Throwable caught) {
if (caught instanceof UserManagementException) {
if (UserManagementException.CANNOT_RESET_PASSWORD_WITHOUT_VALIDATED_EMAIL.equals(caught.getMessage())) {
Window.alert(stringMessages.cannotResetPasswordWithoutValidatedEmail(nameText.getText()));
} else {
Window.alert(stringMessages.errorDuringPasswordReset(caught.getMessage()));
}
} else {
Window.alert(stringMessages.errorDuringPasswordReset(caught.getMessage()));
}
}
@Override
public void onSuccess(Void result) {
Window.alert(stringMessages.newPasswordSent(nameText.getText()));
}
}));
}
});
currentPasswordAndResetButtonPanel.add(passwordReset);
fp.add(currentPasswordAndResetButtonPanel);
updateEmailButton.addClickHandler(new ClickHandler() {
@Override
public void onClick(ClickEvent event) {
@@ -79,13 +114,12 @@ public class EditProfileEntryPoint implements EntryPoint {
@Override
public void onSuccess(UserData result) {
emailText.setText(result.getEmail());
passwordReset.setEnabled(false); // an updated e-mail first needs to be re-validated
}
@Override public void onFailure(Throwable caught) {}
}).show();
}
});
emailTextBoxAndButtonPanel.add(updateEmailButton);
fp.add(emailTextBoxAndButtonPanel);
userService.addUserStatusEventHandler(new UserStatusEventHandler() {
@Override
public void onUserStatusChange(UserDTO user) {
@@ -93,17 +127,15 @@ public class EditProfileEntryPoint implements EntryPoint {
nameText.setText("");
emailText.setText("");
rolesLabel.setText("");
passwordReset.setEnabled(false);
} else {
nameText.setText(user.getName());
emailText.setText(user.getEmail());
rolesLabel.setText(user.getRoles().toString());
passwordReset.setEnabled(user.isEmailValidated());
}
}
});
Label currentPasswordLabel = new Label(stringMessages.currentPassword());
fp.add(currentPasswordLabel);
final TextBox currentPasswordText = new PasswordTextBox();
fp.add(currentPasswordText);
Label pwLabel = new Label(stringMessages.password());
fp.add(pwLabel);
final PasswordTextBox pwText = new PasswordTextBox();
@@ -2,6 +2,8 @@ package com.sap.sse.security.ui.client;
import java.util.Map;
import com.google.gwt.http.client.UrlBuilder;
import com.google.gwt.user.client.Window;
import com.sap.sse.gwt.client.AbstractEntryPointLinkFactory;
public class EntryPointLinkFactory extends AbstractEntryPointLinkFactory {
@@ -22,7 +24,14 @@ public class EntryPointLinkFactory extends AbstractEntryPointLinkFactory {
return createEntryPointLink("/security/ui/UserManagement.html", parameters);
}
/**
* Produces an absolute base URL for the validation
*/
public static String createEmailValidationLink(Map<String, String> parameters) {
return createEntryPointLink("/security/ui/EmailValidation.html", parameters);
UrlBuilder builder = Window.Location.createUrlBuilder().setPath("/security/ui/EmailValidation.html");
for (Map.Entry<String, String> param : parameters.entrySet()) {
builder.setParameter(param.getKey(), param.getValue());
}
return builder.buildString();
}
}
@@ -30,7 +30,8 @@ public class EditEmailDialogWithDefaultCallback extends EditEmailDialog {
super(stringMessages, userManagementService, user, new DialogCallback<UserData>() {
@Override
public void ok(final UserData userData) {
userManagementService.updateSimpleUserEmail(userData.getUsername(), userData.getEmail(), EntryPointLinkFactory.createEmailValidationLink(Collections.<String, String>emptyMap()),
userManagementService.updateSimpleUserEmail(userData.getUsername(), userData.getEmail(),
EntryPointLinkFactory.createEmailValidationLink(Collections.<String, String>emptyMap()),
new MarkedAsyncCallback<Void>(
new AsyncCallback<Void>() {
@Override
@@ -11,6 +11,7 @@ import com.sap.sse.gwt.client.EntryPointHelper;
import com.sap.sse.gwt.client.async.MarkedAsyncCallback;
import com.sap.sse.security.ui.client.RemoteServiceMappingConstants;
import com.sap.sse.security.ui.client.StringMessages;
import com.sap.sse.security.ui.client.UserService;
import com.sap.sse.security.ui.shared.UserManagementService;
import com.sap.sse.security.ui.shared.UserManagementServiceAsync;
@@ -23,6 +24,7 @@ public class EmailValidationEntryPoint implements EntryPoint {
EntryPointHelper.registerASyncService((ServiceDefTarget) userManagementService,
RemoteServiceMappingConstants.WEB_CONTEXT_PATH,
RemoteServiceMappingConstants.userManagementServiceRemotePath);
final UserService userService = new UserService(userManagementService);
final String username = Window.Location.getParameter("u");
final String validationSecret = Window.Location.getParameter("v");
RootLayoutPanel rootPanel = RootLayoutPanel.get();
@@ -36,6 +38,7 @@ public class EmailValidationEntryPoint implements EntryPoint {
@Override
public void onSuccess(Boolean result) {
if (result) {
userService.updateUser(/* notifyOtherInstances */ true);
resultLabel.setText(stringMessages.emailValidatedSuccessfully(username));
} else {
resultLabel.setText(stringMessages.emailValidationUnsuccessful(username));
@@ -141,7 +141,7 @@ public class UserManagementServiceImpl extends RemoteServiceServlet implements U
@Override
public void updateSimpleUserPassword(String username, String oldPassword, String newPassword) throws UserManagementException, MailException {
public void updateSimpleUserPassword(final String username, String oldPassword, String newPassword) throws UserManagementException {
final Subject subject = SecurityUtils.getSubject();
if (!subject.hasRole(DefaultRoles.ADMIN.getRolename())) {
// validate old password before proceeding
@@ -151,7 +151,15 @@ public class UserManagementServiceImpl extends RemoteServiceServlet implements U
}
if (subject.hasRole(DefaultRoles.ADMIN.getRolename()) || username.equals(SessionUtils.loadUsername())) {
getSecurityService().updateSimpleUserPassword(username, newPassword);
getSecurityService().sendMail(username, "Password Changed", "Somebody changed your password for your user named "+username+".\nIf that wasn't you, I'd be worried...");
new Thread("sending updated password to user "+username+" by e-mail") {
@Override public void run() {
try {
getSecurityService().sendMail(username, "Password Changed", "Somebody changed your password for your user named "+username+".\nIf that wasn't you, I'd be worried...");
} catch (MailException e) {
logger.log(Level.SEVERE, "Error sending new password to user "+username+" by e-mail", e);
}
}
}.start();
} else {
throw new UserManagementException(UserManagementException.INVALID_CREDENTIALS);
}
@@ -168,7 +176,7 @@ public class UserManagementServiceImpl extends RemoteServiceServlet implements U
}
@Override
public void resetPassword(String username) throws UserManagementException, MailException {
public void resetPassword(String username) throws UserManagementException {
getSecurityService().resetPassword(username);
}
@@ -24,7 +24,7 @@ public interface UserManagementService extends RemoteService {
void updateSimpleUserEmail(String username, String newEmail, String validationBaseURL) throws UserManagementException, MailException;
void resetPassword(String username) throws UserManagementException, MailException;
void resetPassword(String username) throws UserManagementException;
boolean validateEmail(String username, String validationSecret) throws UserManagementException;
@@ -39,9 +39,9 @@ public interface SecurityService {
*/
User createSimpleUser(String username, String email, String password, String validationBaseURL) throws UserManagementException, MailException;
void updateSimpleUserPassword(String name, String newPassword) throws UserManagementException, MailException;
void updateSimpleUserPassword(String name, String newPassword) throws UserManagementException;
void updateSimpleUserEmail(String username, String newEmail, String validationBaseURL) throws UserManagementException, MailException;
void updateSimpleUserEmail(String username, String newEmail, String validationBaseURL) throws UserManagementException;
User createSocialUser(String username, SocialUserAccount socialUserAccount) throws UserManagementException;
@@ -81,7 +81,7 @@ public interface SecurityService {
* Generates a new random password for the user identified by <code>username</code> and sends it
* to the user's e-mail address.
*/
void resetPassword(String username) throws UserManagementException, MailException;
void resetPassword(String username) throws UserManagementException;
boolean validateEmail(String username, String validationSecret) throws UserManagementException;
@@ -162,7 +162,7 @@ public class SecurityServiceImpl extends RemoteServiceServlet implements Securit
}
@Override
public void resetPassword(String username) throws UserManagementException, MailException {
public void resetPassword(final String username) throws UserManagementException {
final User user = store.getUserByName(username);
if (user == null) {
throw new UserManagementException(UserManagementException.USER_DOES_NOT_EXIST);
@@ -174,8 +174,17 @@ public class SecurityServiceImpl extends RemoteServiceServlet implements Securit
new Random().nextBytes(randomBytes);
final String newPassword = new Sha256Hash(randomBytes).toBase64();
updateSimpleUserPassword(user, newPassword);
sendMail(username, "Password Reset", "Your new password for your username "+username+
" is \n "+newPassword+"\nPlease change after next sign-in.");
new Thread("sending new password to user "+username+" by e-mail") {
@Override public void run() {
try {
sendMail(username, "Password Reset", "Your new password for your username "+username+
" is \n "+newPassword+"\nPlease change after next sign-in.");
} catch (MailException e) {
// TODO Auto-generated catch block
e.printStackTrace();
}
}
}.start();
}
@Override
@@ -253,7 +262,7 @@ public class SecurityServiceImpl extends RemoteServiceServlet implements Securit
}
@Override
public void updateSimpleUserPassword(String username, String newPassword) throws UserManagementException, MailException {
public void updateSimpleUserPassword(String username, String newPassword) throws UserManagementException {
final User user = store.getUserByName(username);
if (user == null) {
throw new UserManagementException(UserManagementException.USER_DOES_NOT_EXIST);
@@ -287,8 +296,7 @@ public class SecurityServiceImpl extends RemoteServiceServlet implements Securit
}
@Override
public void updateSimpleUserEmail(final String username, final String newEmail, final String validationBaseURL)
throws UserManagementException, MailException {
public void updateSimpleUserEmail(final String username, final String newEmail, final String validationBaseURL) throws UserManagementException {
final User user = store.getUserByName(username);
if (user == null) {
throw new UserManagementException(UserManagementException.USER_DOES_NOT_EXIST);