Forgot Password leak info about valid accounts

ECOM-4703
This commit is contained in:
Ahsan Ulhaq
2016-07-26 16:20:37 +05:00
parent c8f0e00ec8
commit 4c3f68cdc4
6 changed files with 43 additions and 23 deletions

View File

@@ -70,6 +70,7 @@
};
this.platformName = options.platform_name;
this.supportURL = options.support_link;
// The login view listens for 'sync' events from the reset model
this.resetModel = new PasswordResetModel({}, {
@@ -120,7 +121,8 @@
model: model,
resetModel: this.resetModel,
thirdPartyAuth: this.thirdPartyAuth,
platformName: this.platformName
platformName: this.platformName,
supportURL: this.supportURL
});
// Listen for 'password-help' event to toggle sub-views

View File

@@ -1,13 +1,13 @@
;(function (define) {
'use strict';
define([
'jquery',
'underscore',
'gettext',
'js/student_account/views/FormView'
'jquery',
'underscore',
'gettext',
'edx-ui-toolkit/js/utils/html-utils',
'js/student_account/views/FormView'
],
function($, _, gettext, FormView) {
function($, _, gettext, HtmlUtils, FormView) {
return FormView.extend({
el: '#login-form',
tpl: '#login-tpl',
@@ -29,6 +29,7 @@
this.errorMessage = data.thirdPartyAuth.errorMessage || '';
this.platformName = data.platformName;
this.resetModel = data.resetModel;
this.supportURL = data.supportURL;
this.listenTo( this.model, 'sync', this.saveSuccess );
this.listenTo( this.resetModel, 'sync', this.resetEmail );
@@ -36,6 +37,13 @@
render: function( html ) {
var fields = html || '';
this.successMessage = HtmlUtils.interpolateHtml(
// eslint-disable-next-line
gettext('We have sent an email message with password reset instructions to the email address you provided. If you do not receive this message, {anchorStart}contact technical support{anchorEnd}.'), { // jshint ignore:line
anchorStart: HtmlUtils.HTML('<a href="' + this.supportURL + '">'),
anchorEnd: HtmlUtils.HTML('</a>')
}
);
$(this.el).html(_.template(this.tpl)({
// We pass the context object to the template so that
@@ -86,6 +94,16 @@
resetEmail: function() {
this.element.hide( this.$errors );
this.resetMessage = this.$resetSuccess.find('.message-copy');
if (this.resetMessage.find('p').length === 0) {
this.resetMessage.append(
HtmlUtils.joinHtml(
HtmlUtils.HTML('<p>'),
this.successMessage,
HtmlUtils.HTML('</p>')
).toString()
);
}
this.element.show( this.$resetSuccess );
},