--- loncom/interface/resetpw.pm	2009/10/01 17:22:13	1.19
+++ loncom/interface/resetpw.pm	2010/12/01 23:15:47	1.22.2.4
@@ -1,7 +1,7 @@
 # The LearningOnline Network
 # Allow access to password changing via a token sent to user's e-mail. 
 #
-# $Id: resetpw.pm,v 1.19 2009/10/01 17:22:13 raeburn Exp $
+# $Id: resetpw.pm,v 1.22.2.4 2010/12/01 23:15:47 raeburn Exp $
 #
 # Copyright Michigan State University Board of Trustees
 #
@@ -26,6 +26,28 @@
 # http://www.lon-capa.org/
 #
 #
+
+=pod
+
+=head1 NAME
+
+Apache::resetpw: reset user password.
+
+=head1 SYNOPSIS
+
+Handles resetting of forgotten passwords.
+
+This is part of the LearningOnline Network with CAPA project
+described at http://www.lon-capa.org.
+ 
+=head1 OVERVIEW
+
+A user with an e-mail address associated with his/her LON-CAPA username
+can reset a forgotten password, using a link sent to the e-mail address
+if the authentication type for the account is "internal".
+
+=cut
+
 package Apache::resetpw;
 
 use strict;
@@ -47,28 +69,68 @@ sub handler {
     my $contact_email =  $r->dir_config('lonSupportEMail');
     my $server = $r->dir_config('lonHostID');
     my $defdom = &Apache::lonnet::default_login_domain();
+    my $handle = &Apache::lonnet::check_for_valid_session($r);
+    my $lonidsdir=$r->dir_config('lonIDsDir');
+    if ($handle ne '') {
+        if ($handle=~/^publicuser\_/) {
+            unlink($r->dir_config('lonIDsDir')."/$handle.id");
+        } else {
+            &Apache::lonnet::transfer_profile_to_env($lonidsdir,$handle);
+        }
+    }
     &Apache::lonacc::get_posted_cgi($r);
     &Apache::lonlocal::get_language_handle($r);
-    &Apache::loncommon::get_unprocessed_cgi($ENV{'QUERY_STRING'},['token']);
+    &Apache::loncommon::get_unprocessed_cgi($ENV{'QUERY_STRING'},['token',
+                                            'uname','useremail','referrer']);
     
     my @emailtypes = ('permanentemail','critnotification','notification');
-    my $uname = &unescape($env{'form.uname'});
+    my $uname = $env{'form.uname'};
+    my $useremail = $env{'form.useremail'};
     my $udom = $env{'form.udom'};
     my $token = $env{'form.token'};
-    my $start_page =
-        &Apache::loncommon::start_page('Reset password','',
-                                           {
-                                             'no_inline_link'   => 1,});
-    $r->print($start_page);
+    my $case_change;
+    my $brcrum = [];
+    my $bread_crumbs_component = 'Forgotten Password';
+    if ($token) {
+        push (@{$brcrum},
+            {href => '/adm/resetpw',
+             text => 'Update Password'});
+
+        $bread_crumbs_component = 'Reset Password';
+    } else {
+        push (@{$brcrum},
+            {href => '/adm/resetpw',
+             text => 'Account Information'});
+        if ($uname && $udom) {
+            push (@{$brcrum},
+                {href => '/adm/resetpw',
+                 text => 'Result'});
+        }
+    }
+    my $args = {no_inline_link         => 1,
+                bread_crumbs           => $brcrum,
+                bread_crumbs_component => $bread_crumbs_component};
+    $r->print(&Apache::loncommon::start_page('Reset password','',$args));
     $r->print('<h3>'.&mt('Reset forgotten LON-CAPA password').'</h3>');
     my $output;
     if ($token) {
         $output = &reset_passwd($r,$token,$contact_name,$contact_email);
-    } elsif ($uname && $udom) {
+    } elsif ($uname && $udom && ($env{'form.referrer'} ne 'createaccount')) {
         my $domdesc = &Apache::lonnet::domain($udom,'description');
+        my $homeserver = &Apache::lonnet::homeserver($uname,$udom);
+        if ($homeserver eq 'no_host') {
+            my $lc_uname =  lc($uname);
+            if ($lc_uname ne $uname) {
+                $homeserver = &Apache::lonnet::homeserver($lc_uname,$udom);
+                unless ($homeserver eq 'no_host') {
+                    $uname = $lc_uname;
+                    $useremail = lc($env{'form.useremail'});
+                    $case_change = 1;
+                }
+            }
+        }
         my $authtype = &Apache::lonnet::queryauthenticate($uname,$udom);
         if ($authtype =~ /^internal/) {
-            my $useremail = $env{'form.useremail'};
             if ($useremail !~ /^[^\@]+\@[^\@]+\.[^\@\.]+$/) {
                 $output = &invalid_state('baduseremail',$domdesc,
                                          $contact_name,$contact_email);
@@ -87,8 +149,15 @@ sub handler {
                     }
                     foreach my $item (@items) {
                         if ($item =~ /^[^\@]+\@[^\@]+\.[^\@\.]+$/) {
-                            unless(grep(/^\Q$item\E$/,@allemails)) { 
-                                push(@allemails,$item);
+                            if ($case_change) {
+                                my $lcitem = lc($item);
+                                unless(grep(/^\Q$lcitem\E$/,@allemails)) {
+                                    push(@allemails,$lcitem);
+                                }
+                            } else {
+                                unless(grep(/^\Q$item\E$/,@allemails)) { 
+                                    push(@allemails,$item);
+                                }
                             }
                         }
                     }
@@ -116,7 +185,7 @@ sub handler {
                                      $contact_name,$contact_email);
         }
     } else {
-        $output = &get_uname($defdom);
+        $output = &get_uname($defdom,$uname,$useremail);
     }
     $r->print($output);
     $r->print(&Apache::loncommon::end_page());
@@ -124,36 +193,31 @@ sub handler {
 }
 
 sub get_uname {
-    my ($defdom) = @_;
+    my ($defdom,$uname,$useremail) = @_;
     my %lt = &Apache::lonlocal::texthash(
-                                         unam => 'username',
-                                         udom => 'domain',
+                                         unam => 'LON-CAPA username',
+                                         udom => 'LON-CAPA domain',
                                          uemail => 'E-mail address in LON-CAPA',
                                          proc => 'Proceed');
-
-    my $msg = &mt('If you use the same account for other campus services besides LON-CAPA, (e.g., e-mail, course registration, etc.), a separate centrally managed mechanism likely exists to reset a password.  However, if your account is used for just LON-CAPA access you will probably be able to reset a password from this page.');
-    $msg .= '<br /><br />'.&mt('Three conditions must be met:')
+    my %value;
+    if ($env{'form.referrer'} eq 'createaccount') {
+        $value{'uname'} = $uname;
+        $value{'useremail'} = $useremail;
+    }
+    my $msg = '<br />'.&mt('To be able to reset a forgotten password:')
            .'<ul><li>'.&mt('An e-mail address must have previously been associated with your LON-CAPA username.').'</li>'
-           .'<li>'.&mt('You must be able to access e-mail sent to that address.').'</li>'
-           .'<li>'.&mt('Your LON-CAPA account must be of a type for which LON-CAPA can reset a password.')
-           .'</ul>';
-    $msg .= qq|
-<form name="forgotpw" method="post">
-<table>
-<tr><td>
-<tr><td align="left">LON-CAPA $lt{'unam'}:                      </td>
-    <td><input type="text" name="uname" size="15" /></td></tr>
-<tr><td align="left">LON-CAPA $lt{'udom'}:                      </td>
-    <td>|;
-    $msg .= &Apache::loncommon::select_dom_form($defdom,'udom');
-    $msg .= qq|</td></tr>
-<tr><td align="left">$lt{'uemail'}:                             </td>
-    <td><input type="text" name="useremail" size="30" /></td></tr>
-<tr><td colspan="2" align="left"><br />
-    <input type="submit" value="$lt{'proc'}" /></td></tr>
-</table>
-</form>
-|;
+           .'<li>'.&mt('You must be able to access e-mail sent to the e-mail address associated with your WebCenter account.').'</li></ul><br />'
+           .&mt('In most cases the GCI WebCenter username is the same as your e-mail address, in which case you will enter the same information twice. ').'<br /><br />';
+    $msg .= '<form name="forgotpw" method="post" action="/adm/resetpw">'.
+            &Apache::lonhtmlcommon::start_pick_box().
+            &Apache::lonhtmlcommon::row_title($lt{'unam'}).
+            '<input type="text" name="uname" size="30" value="'.$value{'uname'}.'" />'.
+            '<input type="hidden" name="udom" value="'.$defdom.'" />'.
+            &Apache::lonhtmlcommon::row_closure(1).
+            &Apache::lonhtmlcommon::row_title($lt{'uemail'}).
+            '<input type="text" name="useremail" size="30" value="'.$value{'useremail'}.'" />'.
+            &Apache::lonhtmlcommon::end_pick_box().
+            '<br /><br /><input type="submit" name="resetter" value="'.$lt{'proc'}.'" /></form>'."\n";
     return $msg;
 }
 
@@ -176,16 +240,16 @@ sub send_token {
         my $esc_token = &escape($token);
         my $showtime = &Apache::lonlocal::locallocaltime(time);
         my $reseturl = &Apache::lonnet::absolute_url().'/adm/resetpw?token='.$esc_token;
-        my $mailmsg = &mt('A request was submitted on [_1] for reset of the password for your LON-CAPA account.',$showtime).' '.&mt('To complete this process please open a web browser and enter the following URL in the address/location box: [_1]',$reseturl);
+        my $mailmsg = &mt('A request was submitted on [_1] for reset of the password for your LON-CAPA account.',$showtime)." \n".&mt('To complete this process please open a web browser and enter the following URL in the address/location box: [_1]',"\n\n".$reseturl);
         my $result = &send_mail($domdesc,$email,$mailmsg,$contact_name,
                                 $contact_email);
         if ($result eq 'ok') {
-            $msg .= &mt("An e-mail sent to the e-mail address associated with your LON-CAPA account includes the web address for the link you should use to complete the reset process.<br /><br />The link included in the message will be valid for the next <b>two</b> hours.");
+            $msg .= &mt('An e-mail sent to the e-mail address associated with your LON-CAPA account includes the web address for the link you should use to complete the reset process.').'<br /><br />'.&mt('The link included in the message will be valid for the next [_1]two[_2] hours.','<b>','</b>');
         } else {
-            $msg .= &mt("An error occurred when sending a message to the e-mail address associated with your LON-CAPA account. Please contact the [_1] ([_2]) for assistance.",$contact_name,$contact_email);
+            $msg .= &mt('An error occurred when sending a message to the e-mail address associated with your LON-CAPA account. Please contact the [_1] ([_2]) for assistance.',$contact_name,$contact_email);
         }
     } else {
-        $msg .= &mt("An error occurred creating a token required for the password reset process. Please contact the [_1] ([_2]) for assistance.",$contact_name,$contact_email);
+        $msg .= &mt('An error occurred creating a token required for the password reset process. Please contact the [_1] ([_2]) for assistance.',$contact_name,$contact_email);
     }
     return $msg;
 }
@@ -213,8 +277,8 @@ sub invalid_state {
     my ($error,$domdesc,$contact_name,$contact_email) = @_;
     my $msg;
     if ($error eq 'invalid') {
-        $msg = &mt('The username you provided was not verified as a valid username in the LON-CAPA system for the [_1] domain.',$domdesc)
-              .' '.&mt('Please [_1]go back[_2] and try again.','<a href="javascript:history.go(-1)"><u>','</u></a>');
+        $msg = '<p class="LC_warning">'.&mt('The username you provided was not verified as a valid username in the LON-CAPA system for the [_1] domain.',$domdesc)
+              .'</p>'.&mt('Please [_1]go back[_2] and try again.','<a href="javascript:history.go(-1)"><u>','</u></a>');
     } else {
         if ($error eq 'baduseremail') {
             $msg = &mt('The e-mail address you provided does not appear to be a valid address.');
@@ -225,6 +289,7 @@ sub invalid_state {
         } elsif ($error eq 'authentication') {
             $msg = &mt('The username you provided uses an authentication type which can not be reset directly via LON-CAPA.');
         }
+        $msg = '<p class="LC_warning">'.$msg.'</p>';
         if ($contact_email ne '') {
             my $escuri = &HTML::Entities::encode('/adm/resetpw','&<>"');
             $msg .= '<br /> '.&mt('You may wish to contact the [_1]LON-CAPA helpdesk[_2] for the [_3] domain.'
@@ -254,6 +319,23 @@ sub reset_passwd {
         my $reqtime = &Apache::lonlocal::locallocaltime($data{'time'});
         if ($now - $data{'time'} < 7200) {
             if ($env{'form.action'} eq 'verify_and_change_pass') {
+                my $homeserver = &Apache::lonnet::homeserver($env{'form.uname'},$env{'form.udom'});
+                if ($homeserver eq 'no_host') {
+                    my $lc_uname =  lc($env{'form.uname'});
+                    if ($lc_uname ne $env{'form.uname'}) {
+                        $homeserver = &Apache::lonnet::homeserver($lc_uname,$env{'form.udom'});
+                        unless ($homeserver eq 'no_host') {
+                            if ($env{'form.uname'} eq $env{'form.email'}) {
+                                $env{'form.email'} = $lc_uname;
+                            }
+                            $env{'form.uname'} = $lc_uname;
+                        }
+                    }
+                }
+                unless (($env{'form.uname'} eq $data{'username'}) && ($env{'form.udom'} eq $data{'domain'}) && ($env{'form.email'} eq $data{'email'})) {
+                    $msg = &generic_failure_msg($contact_name,$contact_email);
+                    return $msg;
+                }
                 my $change_failed = 
 		    &Apache::lonpreferences::verify_and_change_password($r,'reset_by_email',$token);
                 if (!$change_failed) {
@@ -271,14 +353,31 @@ sub reset_passwd {
                     }
                     $msg .= '<br /><br />'
                            .'<a href="/adm/login">'.&mt('Go to the login page').'</a>.';
+                } elsif ($change_failed eq 'invalid_client') {
+                    my $homeserver = &Apache::lonnet::homeserver($data{'username'},$data{'domain'});
+                    if ($homeserver eq 'no_host') {
+                        $msg .= &generic_failure_msg($contact_name,$contact_email);
+                    } else {
+                        my $protocol = $Apache::lonnet::protocol{$homeserver};
+                        $protocol = 'http' if ($protocol ne 'https');
+                        my $url = $protocol.'://'.&Apache::lonnet::hostname($homeserver).
+                                  '/adm/resetpw';
+                        my ($opentag,$closetag);
+                        if ($url) {
+                           $opentag = '<a href="'.$url.'">';
+                           $closetag = '</a>';
+                        }
+                        $msg .= &mt('A problem occurred when attempting to reset the password for your account. Please try again from your [_1]home server[_2].',$opentag,$closetag);
+                    }
                 } else {
-                    $msg .= &mt('A problem occurred when attempting to reset the password for your account. Please contact the [_1] - ([_2]) for assistance.'
-                               ,$contact_name
-                               ,'<a href="mailto:'.$contact_email.'">'.$contact_email.'</a>');
+                    $msg .= &generic_failure_msg($contact_name,$contact_email);
                 }
             } else {
-                $r->print(&mt('The token included in an e-mail sent to you [_1] has been verified, so you may now proceed to reset the password for your LON-CAPA account.',$reqtime).'<br /><br />');
-                $r->print(&mt('Please enter the username and domain of the LON-CAPA account, and the associated e-mail address, for which you are setting a password. The new password must contain at least 7 characters.').' '.&mt('Your new password will be sent to the LON-CAPA server in an encrypted form.').'<br />');
+                $r->print(&mt('The token included in an e-mail sent to you [_1] has been verified, so you may now proceed to reset the password for your LON-CAPA account.',$reqtime).'<br />'.
+                          '<p>'.&mt('Please enter the username and domain of the LON-CAPA account, and the associated e-mail address, for which you are setting a password.').'<br />'.
+                          &mt('In most cases the GCI WebCenter username is the same as your e-mail address, in which case you will enter the same information twice.').'</p>'.
+                          '<p>'.&mt('The new password must contain at least 7 characters.').' '.
+                          &mt('Your new password will be sent to the LON-CAPA server in an encrypted form.').'<br /></p>');
                 &Apache::lonpreferences::passwordchanger($r,'','reset_by_email',$token);
             }
         } else {
@@ -292,6 +391,12 @@ sub reset_passwd {
     return $msg;
 }
 
+sub generic_failure_msg {
+    my ($contact_name,$contact_email) = @_;
+    return &mt('A problem occurred when attempting to reset the password for your account. Please contact the [_1] - ([_2]) for assistance.',
+              $contact_name,'<a href="mailto:'.$contact_email.'">'.$contact_email.'</a>');
+}
+
 sub create_passwd {
     my $passwd = '';
     my @letts = ("a".."z");