From b1945c7923fc4f1fcc5a1e5211b85944028cb047 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?F=C3=A1bio=20Souto?= Date: Mon, 9 Jan 2012 11:16:30 +0000 Subject: [PATCH 1/2] Updated bugfix according to Jerome suggestions password check is done at lib.php instead of externallib.php Conflicts: user/lib.php Conflicts: user/lib.php --- user/lib.php | 21 ++++++++++++++++++--- 1 file changed, 18 insertions(+), 3 deletions(-) diff --git a/user/lib.php b/user/lib.php index 92ffdf7c2a2..b291c78ea7d 100644 --- a/user/lib.php +++ b/user/lib.php @@ -65,12 +65,27 @@ function user_update_user($user) { if (!is_object($user)) { $user = (object)$user; } - - /// hash the password - $user->password = hash_internal_user_password($user->password); + + //MDL-30878 + //unset password here, for updating later + if (isset($user->password)) { + $passwd = $user->password; + unset($user->password); + } $user->timemodified = time(); $DB->update_record('user', $user); + + /// trigger user_updated event on the full database user row + $updateduser = $DB->get_record('user', array('id' => $user->id)); + + //MDL-30878 + //if password was set, then update its hash + if (isset($passwd)) + update_internal_user_password($updateduser, $passwd); + + events_trigger('user_updated', $updateduser); + } From 2e91e1ae9d2ce75917bdad05180fe63b9dacd809 Mon Sep 17 00:00:00 2001 From: Jerome Mouneyrac Date: Fri, 27 Jan 2012 15:16:11 +0800 Subject: [PATCH 2/2] MDL-30878 core_user_update_users user password is reset if not specified Conflicts: user/lib.php --- user/lib.php | 47 +++++++++++++++++++++++++++++------------------ 1 file changed, 29 insertions(+), 18 deletions(-) diff --git a/user/lib.php b/user/lib.php index b291c78ea7d..f60b361a739 100644 --- a/user/lib.php +++ b/user/lib.php @@ -27,47 +27,60 @@ /** * Creates a user + * * @param object $user user to create * @return int id of the newly created user */ function user_create_user($user) { global $DB; -/// set the timecreate field to the current time + // set the timecreate field to the current time if (!is_object($user)) { $user = (object)$user; } - /// hash the password - $user->password = hash_internal_user_password($user->password); + // save the password in a temp value for later + if (isset($user->password)) { + $userpassword = $user->password; + unset($user->password); + } $user->timecreated = time(); $user->timemodified = $user->timecreated; -/// insert the user into the database + // insert the user into the database $newuserid = $DB->insert_record('user', $user); -/// create USER context for this user + // trigger user_created event on the full database user row + $newuser = $DB->get_record('user', array('id' => $newuserid)); + events_trigger('user_created', $newuser); + + // create USER context for this user get_context_instance(CONTEXT_USER, $newuserid); + // update user password if necessary + if (isset($userpassword)) { + update_internal_user_password($newuser, $userpassword); + } + return $newuserid; } /** * Update a user with a user object (will compare against the ID) - * @param object $user - the user to update + * + * @param object $user the user to update */ function user_update_user($user) { global $DB; - /// set the timecreate field to the current time + // set the timecreate field to the current time if (!is_object($user)) { $user = (object)$user; } - - //MDL-30878 - //unset password here, for updating later + + // unset password here, for updating later if (isset($user->password)) { $passwd = $user->password; unset($user->password); @@ -76,18 +89,16 @@ function user_update_user($user) { $user->timemodified = time(); $DB->update_record('user', $user); - /// trigger user_updated event on the full database user row + // trigger user_updated event on the full database user row $updateduser = $DB->get_record('user', array('id' => $user->id)); - - //MDL-30878 - //if password was set, then update its hash - if (isset($passwd)) - update_internal_user_password($updateduser, $passwd); - events_trigger('user_updated', $updateduser); -} + // if password was set, then update its hash + if (isset($passwd)) { + update_internal_user_password($updateduser, $passwd); + } +} /** * Marks user deleted in internal user database and notifies the auth plugin.