2013-06-12 15:59:58 +00:00
|
|
|
# Copyright (C) 2012-2013 Zammad Foundation, http://zammad-foundation.org/
|
|
|
|
|
2013-01-23 22:13:02 +00:00
|
|
|
require 'digest/sha2'
|
2013-04-20 08:52:17 +00:00
|
|
|
require 'organization'
|
2013-01-23 22:13:02 +00:00
|
|
|
|
2012-04-16 08:04:49 +00:00
|
|
|
class User < ApplicationModel
|
2013-08-06 10:29:35 +00:00
|
|
|
before_create :check_name, :check_email, :check_login, :check_image, :check_password
|
|
|
|
before_update :check_password, :check_image, :check_email, :check_login_update
|
2013-06-29 00:13:03 +00:00
|
|
|
after_create :notify_clients_after_create
|
|
|
|
after_update :notify_clients_after_update
|
|
|
|
after_destroy :notify_clients_after_destroy
|
2012-04-10 14:06:46 +00:00
|
|
|
|
2012-04-16 08:04:49 +00:00
|
|
|
has_and_belongs_to_many :groups, :after_add => :cache_update, :after_remove => :cache_update
|
|
|
|
has_and_belongs_to_many :roles, :after_add => :cache_update, :after_remove => :cache_update
|
|
|
|
has_and_belongs_to_many :organizations, :after_add => :cache_update, :after_remove => :cache_update
|
2012-04-23 06:55:16 +00:00
|
|
|
has_many :tokens, :after_add => :cache_update, :after_remove => :cache_update
|
2012-04-16 08:04:49 +00:00
|
|
|
has_many :authorizations, :after_add => :cache_update, :after_remove => :cache_update
|
|
|
|
belongs_to :organization, :class_name => 'Organization'
|
|
|
|
|
|
|
|
store :preferences
|
2012-04-14 15:53:00 +00:00
|
|
|
|
2012-07-10 08:09:58 +00:00
|
|
|
def fullname
|
|
|
|
fullname = ''
|
|
|
|
if self.firstname
|
|
|
|
fullname = fullname + self.firstname
|
|
|
|
end
|
|
|
|
if self.lastname
|
|
|
|
if fullname != ''
|
|
|
|
fullname = fullname + ' '
|
|
|
|
end
|
|
|
|
fullname = fullname + self.lastname
|
|
|
|
end
|
|
|
|
return fullname
|
|
|
|
end
|
|
|
|
|
2012-09-04 21:28:49 +00:00
|
|
|
def is_role( role_name )
|
|
|
|
self.roles.each { |role|
|
|
|
|
return role if role.name == role_name
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
end
|
|
|
|
|
2012-04-14 15:53:00 +00:00
|
|
|
def self.authenticate( username, password )
|
2012-07-29 15:27:01 +00:00
|
|
|
|
2012-04-20 12:24:37 +00:00
|
|
|
# do not authenticate with nothing
|
2012-04-20 15:39:50 +00:00
|
|
|
return if !username || username == ''
|
2013-06-12 15:59:58 +00:00
|
|
|
return if !password || password == ''
|
2012-07-29 15:27:01 +00:00
|
|
|
|
2012-04-20 08:58:31 +00:00
|
|
|
# try to find user based on login
|
2013-02-07 21:24:03 +00:00
|
|
|
user = User.where( :login => username.downcase, :active => true ).first
|
2012-07-29 15:27:01 +00:00
|
|
|
|
2012-04-20 08:58:31 +00:00
|
|
|
# try second lookup with email
|
|
|
|
if !user
|
2013-02-07 21:24:03 +00:00
|
|
|
user = User.where( :email => username.downcase, :active => true ).first
|
2012-04-20 08:58:31 +00:00
|
|
|
end
|
2012-07-29 15:27:01 +00:00
|
|
|
|
2013-02-07 21:24:03 +00:00
|
|
|
# check failed logins
|
2013-02-12 22:49:52 +00:00
|
|
|
max_login_failed = Setting.get('password_max_login_failed') || 10
|
|
|
|
if user && user.login_failed > max_login_failed
|
|
|
|
return false
|
2013-02-07 21:24:03 +00:00
|
|
|
end
|
2012-07-29 15:27:01 +00:00
|
|
|
|
2013-08-17 21:48:01 +00:00
|
|
|
user_auth = Auth.check( username, password, user )
|
2013-01-23 22:13:02 +00:00
|
|
|
|
2013-02-07 21:24:03 +00:00
|
|
|
# set login failed +1
|
2013-02-12 23:21:56 +00:00
|
|
|
if !user_auth && user
|
2013-08-17 21:48:01 +00:00
|
|
|
sleep 1
|
2013-02-12 23:21:56 +00:00
|
|
|
user.login_failed = user.login_failed + 1
|
|
|
|
user.save
|
|
|
|
end
|
2013-02-07 21:24:03 +00:00
|
|
|
|
2013-08-17 21:48:01 +00:00
|
|
|
# auth ok
|
2013-02-07 21:24:03 +00:00
|
|
|
return user_auth
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
|
|
|
|
2013-02-17 18:28:32 +00:00
|
|
|
def self.sso(params)
|
|
|
|
|
|
|
|
# try to login against configure auth backends
|
2013-08-17 21:48:01 +00:00
|
|
|
user_auth = Sso.check( params, user )
|
|
|
|
return if !user_auth
|
2013-02-17 18:28:32 +00:00
|
|
|
|
2013-08-17 21:48:01 +00:00
|
|
|
return user_auth
|
2013-02-17 18:28:32 +00:00
|
|
|
end
|
|
|
|
|
2012-04-10 14:06:46 +00:00
|
|
|
def self.create_from_hash!(hash)
|
|
|
|
url = ''
|
|
|
|
if hash['info']['urls'] then
|
|
|
|
url = hash['info']['urls']['Website'] || hash['info']['urls']['Twitter'] || ''
|
|
|
|
end
|
|
|
|
roles = Role.where( :name => 'Customer' )
|
2012-04-23 06:55:16 +00:00
|
|
|
self.create(
|
2012-04-10 14:06:46 +00:00
|
|
|
:login => hash['info']['nickname'] || hash['uid'],
|
|
|
|
:firstname => hash['info']['name'],
|
|
|
|
:email => hash['info']['email'],
|
|
|
|
:image => hash['info']['image'],
|
2013-06-12 15:59:58 +00:00
|
|
|
# :url => url.to_s,
|
2012-04-10 14:06:46 +00:00
|
|
|
:note => hash['info']['description'],
|
|
|
|
:source => hash['provider'],
|
|
|
|
:roles => roles,
|
2013-02-07 21:24:03 +00:00
|
|
|
:updated_by_id => 1,
|
|
|
|
:created_by_id => 1,
|
2012-04-10 14:06:46 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
end
|
2012-04-23 06:55:16 +00:00
|
|
|
|
|
|
|
def self.password_reset_send(username)
|
|
|
|
return if !username || username == ''
|
|
|
|
|
|
|
|
# try to find user based on login
|
2013-02-07 21:24:03 +00:00
|
|
|
user = User.where( :login => username.downcase, :active => true ).first
|
2012-10-18 08:10:12 +00:00
|
|
|
|
2012-04-23 06:55:16 +00:00
|
|
|
# try second lookup with email
|
|
|
|
if !user
|
2013-02-07 21:24:03 +00:00
|
|
|
user = User.where( :email => username.downcase, :active => true ).first
|
2012-04-23 06:55:16 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
# check if email address exists
|
2012-09-20 12:08:02 +00:00
|
|
|
return if !user
|
2012-04-23 06:55:16 +00:00
|
|
|
return if !user.email
|
|
|
|
|
|
|
|
# generate token
|
|
|
|
token = Token.create( :action => 'PasswordReset', :user_id => user.id )
|
|
|
|
|
|
|
|
# send mail
|
|
|
|
data = {}
|
|
|
|
data[:subject] = 'Reset your #{config.product_name} password'
|
|
|
|
data[:body] = 'Forgot your password?
|
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
We received a request to reset the password for your #{config.product_name} account (#{user.login}).
|
2012-04-23 06:55:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
If you want to reset your password, click on the link below (or copy and paste the URL into your browser):
|
2012-04-23 06:55:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
#{config.http_type}://#{config.fqdn}/#password_reset_verify/#{token.name}
|
2012-04-23 06:55:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
This link takes you to a page where you can change your password.
|
2012-04-23 06:55:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
If you don\'t want to reset your password, please ignore this message. Your password will not be reset.
|
2012-04-23 06:55:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
Your #{config.product_name} Team
|
|
|
|
'
|
2012-04-23 06:55:16 +00:00
|
|
|
|
|
|
|
# prepare subject & body
|
|
|
|
[:subject, :body].each { |key|
|
|
|
|
data[key.to_sym] = NotificationFactory.build(
|
2013-01-04 14:28:55 +00:00
|
|
|
:locale => user.locale,
|
2012-04-23 06:55:16 +00:00
|
|
|
:string => data[key.to_sym],
|
|
|
|
:objects => {
|
|
|
|
:token => token,
|
|
|
|
:user => user,
|
|
|
|
}
|
|
|
|
)
|
|
|
|
}
|
|
|
|
|
|
|
|
# send notification
|
|
|
|
NotificationFactory.send(
|
|
|
|
:recipient => user,
|
|
|
|
:subject => data[:subject],
|
|
|
|
:body => data[:body]
|
|
|
|
)
|
|
|
|
return true
|
|
|
|
end
|
|
|
|
|
2012-09-20 12:08:02 +00:00
|
|
|
# check token
|
2012-04-23 06:55:16 +00:00
|
|
|
def self.password_reset_check(token)
|
2013-01-03 12:00:55 +00:00
|
|
|
user = Token.check( :action => 'PasswordReset', :name => token )
|
2013-07-16 07:05:59 +00:00
|
|
|
|
|
|
|
# reset login failed if token is valid
|
|
|
|
if user
|
|
|
|
user.login_failed = 0
|
|
|
|
user.save
|
|
|
|
end
|
2013-01-03 12:00:55 +00:00
|
|
|
return user
|
2012-04-23 06:55:16 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
def self.password_reset_via_token(token,password)
|
2012-07-23 22:22:23 +00:00
|
|
|
|
2012-04-23 06:55:16 +00:00
|
|
|
# check token
|
2013-01-03 12:00:55 +00:00
|
|
|
user = Token.check( :action => 'PasswordReset', :name => token )
|
|
|
|
return if !user
|
2012-07-23 22:22:23 +00:00
|
|
|
|
2012-04-23 06:55:16 +00:00
|
|
|
# reset password
|
2013-01-03 12:00:55 +00:00
|
|
|
user.update_attributes( :password => password )
|
2012-07-23 22:22:23 +00:00
|
|
|
|
2012-04-23 06:55:16 +00:00
|
|
|
# delete token
|
2013-01-03 12:00:55 +00:00
|
|
|
Token.where( :action => 'PasswordReset', :name => token ).first.destroy
|
|
|
|
return user
|
2012-04-23 06:55:16 +00:00
|
|
|
end
|
|
|
|
|
2013-05-21 22:30:09 +00:00
|
|
|
def self.search(params)
|
|
|
|
|
|
|
|
# get params
|
|
|
|
query = params[:query]
|
|
|
|
limit = params[:limit] || 10
|
|
|
|
current_user = params[:current_user]
|
|
|
|
|
|
|
|
# enable search only for agents and admins
|
|
|
|
return [] if !current_user.is_role('Agent') && !current_user.is_role('Admin')
|
|
|
|
|
|
|
|
# do query
|
|
|
|
users = User.find(
|
|
|
|
:all,
|
|
|
|
:limit => limit,
|
|
|
|
:conditions => ['(firstname LIKE ? or lastname LIKE ? or email LIKE ?) AND id != 1', "%#{query}%", "%#{query}%", "%#{query}%"],
|
|
|
|
:order => 'firstname'
|
|
|
|
)
|
|
|
|
return users
|
|
|
|
end
|
|
|
|
|
2012-04-14 15:53:00 +00:00
|
|
|
def self.find_fulldata(user_id)
|
|
|
|
|
2013-01-04 18:42:20 +00:00
|
|
|
cache = self.cache_get(user_id, true)
|
2012-07-29 15:27:01 +00:00
|
|
|
return cache if cache
|
2012-04-14 15:53:00 +00:00
|
|
|
|
|
|
|
# get user
|
|
|
|
user = User.find(user_id)
|
2012-04-14 16:48:40 +00:00
|
|
|
data = user.attributes
|
|
|
|
|
2012-04-20 15:39:50 +00:00
|
|
|
# do not show password
|
|
|
|
user['password'] = ''
|
|
|
|
|
2012-04-14 15:53:00 +00:00
|
|
|
# get linked accounts
|
2012-04-14 16:48:40 +00:00
|
|
|
data['accounts'] = {}
|
2012-04-14 15:53:00 +00:00
|
|
|
authorizations = user.authorizations() || []
|
|
|
|
authorizations.each do | authorization |
|
2012-04-14 16:48:40 +00:00
|
|
|
data['accounts'][authorization.provider] = {
|
2012-04-14 15:53:00 +00:00
|
|
|
:uid => authorization[:uid],
|
|
|
|
:username => authorization[:username]
|
|
|
|
}
|
|
|
|
end
|
2012-07-23 22:22:23 +00:00
|
|
|
|
2012-04-14 15:53:00 +00:00
|
|
|
# set roles
|
2012-04-14 16:48:40 +00:00
|
|
|
roles = []
|
|
|
|
user.roles.select('id, name').where( :active => true ).each { |role|
|
2012-07-29 15:27:01 +00:00
|
|
|
roles.push role.attributes
|
2012-04-14 16:48:40 +00:00
|
|
|
}
|
|
|
|
data['roles'] = roles
|
2012-04-20 15:39:50 +00:00
|
|
|
data['role_ids'] = user.role_ids
|
2012-04-14 16:48:40 +00:00
|
|
|
|
|
|
|
groups = []
|
|
|
|
user.groups.select('id, name').where( :active => true ).each { |group|
|
2012-07-29 15:27:01 +00:00
|
|
|
groups.push group.attributes
|
2012-04-14 16:48:40 +00:00
|
|
|
}
|
|
|
|
data['groups'] = groups
|
2012-04-20 15:39:50 +00:00
|
|
|
data['group_ids'] = user.group_ids
|
|
|
|
|
2012-04-14 16:48:40 +00:00
|
|
|
organization = user.organization
|
2012-07-29 15:27:01 +00:00
|
|
|
if organization
|
|
|
|
data['organization'] = organization.attributes
|
|
|
|
end
|
2012-04-14 16:48:40 +00:00
|
|
|
|
|
|
|
organizations = []
|
|
|
|
user.organizations.select('id, name').where( :active => true ).each { |organization|
|
2012-07-29 15:27:01 +00:00
|
|
|
organizations.push organization.attributes
|
2012-04-14 16:48:40 +00:00
|
|
|
}
|
|
|
|
data['organizations'] = organizations
|
2012-04-20 15:39:50 +00:00
|
|
|
data['organization_ids'] = user.organization_ids
|
2012-04-14 15:53:00 +00:00
|
|
|
|
2013-01-04 18:42:20 +00:00
|
|
|
self.cache_set(user.id, data, true)
|
2012-04-14 15:53:00 +00:00
|
|
|
|
2012-04-14 16:48:40 +00:00
|
|
|
return data
|
2012-04-14 15:53:00 +00:00
|
|
|
end
|
2013-06-12 15:59:58 +00:00
|
|
|
|
2012-07-23 22:22:23 +00:00
|
|
|
def self.user_data_full (user_id)
|
|
|
|
|
|
|
|
# get user
|
|
|
|
user = User.find_fulldata(user_id)
|
|
|
|
|
|
|
|
# do not show password
|
|
|
|
user['password'] = ''
|
|
|
|
|
|
|
|
# TEMP: compat. reasons
|
|
|
|
user['preferences'] = {} if user['preferences'] == nil
|
|
|
|
|
|
|
|
items = []
|
|
|
|
if user['preferences'][:tickets_open].to_i > 0
|
|
|
|
item = {
|
|
|
|
:url => '',
|
|
|
|
:name => 'open',
|
|
|
|
:count => user['preferences'][:tickets_open] || 0,
|
|
|
|
:title => 'Open Tickets',
|
|
|
|
:class => 'user-tickets',
|
|
|
|
:data => 'open'
|
|
|
|
}
|
|
|
|
items.push item
|
|
|
|
end
|
|
|
|
if user['preferences'][:tickets_closed].to_i > 0
|
|
|
|
item = {
|
|
|
|
:url => '',
|
|
|
|
:name => 'closed',
|
|
|
|
:count => user['preferences'][:tickets_closed] || 0,
|
|
|
|
:title => 'Closed Tickets',
|
|
|
|
:class => 'user-tickets',
|
|
|
|
:data => 'closed'
|
|
|
|
}
|
|
|
|
items.push item
|
|
|
|
end
|
|
|
|
|
|
|
|
# show linked topics and items
|
|
|
|
if items.count > 0
|
|
|
|
topic = {
|
|
|
|
:title => 'Tickets',
|
|
|
|
:items => items,
|
|
|
|
}
|
|
|
|
user['links'] = []
|
|
|
|
user['links'].push topic
|
|
|
|
end
|
|
|
|
|
|
|
|
return user
|
|
|
|
end
|
2012-04-14 16:48:40 +00:00
|
|
|
|
2012-10-18 08:10:12 +00:00
|
|
|
def update_last_login
|
|
|
|
self.last_login = Time.now
|
|
|
|
self.save
|
|
|
|
end
|
|
|
|
|
2012-04-10 14:06:46 +00:00
|
|
|
private
|
2012-10-25 22:12:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
def check_name
|
2012-10-25 22:12:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
if ( self.firstname && !self.firstname.empty? ) && ( !self.lastname || self.lastname.empty? )
|
2012-10-25 22:12:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
# Lastname, Firstname
|
|
|
|
scan = self.firstname.scan(/, /)
|
|
|
|
if scan[0]
|
|
|
|
name = self.firstname.split(', ', 2)
|
|
|
|
self.lastname = name[0]
|
|
|
|
self.firstname = name[1]
|
2012-10-25 22:12:16 +00:00
|
|
|
return
|
2013-06-12 15:59:58 +00:00
|
|
|
end
|
2012-10-25 22:12:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
# Firstname Lastname
|
|
|
|
name = self.firstname.split(' ', 2)
|
|
|
|
self.firstname = name[0]
|
|
|
|
self.lastname = name[1]
|
|
|
|
return
|
2012-10-25 22:12:16 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
# -no name- firstname.lastname@example.com
|
|
|
|
elsif ( !self.firstname || self.firstname.empty? ) && ( !self.lastname || self.lastname.empty? ) && ( self.email && !self.email.empty? )
|
|
|
|
scan = self.email.scan(/^(.+?)\.(.+?)\@.+?$/)
|
|
|
|
if scan[0]
|
|
|
|
self.firstname = scan[0][0].capitalize
|
|
|
|
self.lastname = scan[0][1].capitalize
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
2013-06-12 15:59:58 +00:00
|
|
|
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
2013-06-12 15:59:58 +00:00
|
|
|
end
|
2012-04-29 20:47:35 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
def check_email
|
|
|
|
if self.email
|
|
|
|
self.email = self.email.downcase
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
2013-06-12 15:59:58 +00:00
|
|
|
end
|
2012-04-29 20:47:35 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
def check_login
|
|
|
|
if self.login
|
|
|
|
self.login = self.login.downcase
|
|
|
|
check = true
|
|
|
|
while check
|
|
|
|
exists = User.where( :login => self.login ).first
|
|
|
|
if exists
|
|
|
|
self.login = self.login + rand(99).to_s
|
|
|
|
else
|
|
|
|
check = false
|
2013-02-19 19:04:35 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2013-06-12 15:59:58 +00:00
|
|
|
end
|
2013-02-19 19:04:35 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
# FIXME: Remove me later
|
|
|
|
def check_login_update
|
|
|
|
if self.login
|
|
|
|
self.login = self.login.downcase
|
2012-11-12 12:04:14 +00:00
|
|
|
end
|
2013-06-12 15:59:58 +00:00
|
|
|
end
|
2012-11-12 12:04:14 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
def check_image
|
|
|
|
require 'digest/md5'
|
|
|
|
if !self.image || self.image == ''
|
|
|
|
if self.email
|
|
|
|
hash = Digest::MD5.hexdigest(self.email)
|
|
|
|
self.image = "http://www.gravatar.com/avatar/#{hash}?s=48"
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
|
|
|
end
|
2013-06-12 15:59:58 +00:00
|
|
|
end
|
2012-04-29 20:47:35 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
def check_password
|
2012-10-18 11:42:05 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
# set old password again if not given
|
|
|
|
if self.password == '' || !self.password
|
2012-04-20 15:39:50 +00:00
|
|
|
|
2013-06-12 15:59:58 +00:00
|
|
|
# get current record
|
|
|
|
if self.id
|
|
|
|
current = User.find(self.id)
|
|
|
|
self.password = current.password
|
|
|
|
end
|
2013-01-23 22:13:02 +00:00
|
|
|
|
|
|
|
# create crypted password if not already crypted
|
2013-06-12 15:59:58 +00:00
|
|
|
else
|
|
|
|
if self.password !~ /^\{sha2\}/
|
|
|
|
crypted = Digest::SHA2.hexdigest( self.password )
|
|
|
|
self.password = "{sha2}#{crypted}"
|
2012-04-20 15:39:50 +00:00
|
|
|
end
|
|
|
|
end
|
2013-06-12 15:59:58 +00:00
|
|
|
end
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|