3 * Implements Special:ChangeEmail
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License, or
8 * (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
15 * You should have received a copy of the GNU General Public License along
16 * with this program; if not, write to the Free Software Foundation, Inc.,
17 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
18 * http://www.gnu.org/copyleft/gpl.html
21 * @ingroup SpecialPage
24 use MediaWiki\Auth\AuthManager
;
25 use MediaWiki\Logger\LoggerFactory
;
28 * Let users change their email address.
30 * @ingroup SpecialPage
32 class SpecialChangeEmail
extends FormSpecialPage
{
38 public function __construct() {
39 parent
::__construct( 'ChangeEmail', 'editmyprivateinfo' );
42 public function doesWrites() {
49 public function isListed() {
50 return AuthManager
::singleton()->allowsPropertyChange( 'emailaddress' );
54 * Main execution point
57 function execute( $par ) {
58 $out = $this->getOutput();
59 $out->disallowUserJs();
61 parent
::execute( $par );
64 protected function getLoginSecurityLevel() {
65 return $this->getName();
68 protected function checkExecutePermissions( User
$user ) {
69 if ( !AuthManager
::singleton()->allowsPropertyChange( 'emailaddress' ) ) {
70 throw new ErrorPageError( 'changeemail', 'cannotchangeemail' );
73 $this->requireLogin( 'changeemail-no-info' );
75 // This could also let someone check the current email address, so
76 // require both permissions.
77 if ( !$this->getUser()->isAllowed( 'viewmyprivateinfo' ) ) {
78 throw new PermissionsError( 'viewmyprivateinfo' );
81 parent
::checkExecutePermissions( $user );
84 protected function getFormFields() {
85 $user = $this->getUser();
90 'label-message' => 'username',
91 'default' => $user->getName(),
95 'label-message' => 'changeemail-oldemail',
96 'default' => $user->getEmail() ?
: $this->msg( 'changeemail-none' )->text(),
100 'label-message' => 'changeemail-newemail',
102 'help-message' => 'changeemail-newemail-help',
109 protected function getDisplayFormat() {
113 protected function alterForm( HTMLForm
$form ) {
114 $form->setId( 'mw-changeemail-form' );
115 $form->setTableId( 'mw-changeemail-table' );
116 $form->setSubmitTextMsg( 'changeemail-submit' );
117 $form->addHiddenFields( $this->getRequest()->getValues( 'returnto', 'returntoquery' ) );
119 $form->addHeaderText( $this->msg( 'changeemail-header' )->parseAsBlock() );
122 public function onSubmit( array $data ) {
123 $status = $this->attemptChange( $this->getUser(), $data['NewEmail'] );
125 $this->status
= $status;
130 public function onSuccess() {
131 $request = $this->getRequest();
133 $returnto = $request->getVal( 'returnto' );
134 $titleObj = $returnto !== null ? Title
::newFromText( $returnto ) : null;
135 if ( !$titleObj instanceof Title
) {
136 $titleObj = Title
::newMainPage();
138 $query = $request->getVal( 'returntoquery' );
140 if ( $this->status
->value
=== true ) {
141 $this->getOutput()->redirect( $titleObj->getFullUrlForRedirect( $query ) );
142 } elseif ( $this->status
->value
=== 'eauth' ) {
143 # Notify user that a confirmation email has been sent...
144 $this->getOutput()->wrapWikiMsg( "<div class='error' style='clear: both;'>\n$1\n</div>",
145 'eauthentsent', $this->getUser()->getName() );
146 // just show the link to go back
147 $this->getOutput()->addReturnTo( $titleObj, wfCgiToArray( $query ) );
153 * @param string $newaddr
156 private function attemptChange( User
$user, $newaddr ) {
157 if ( $newaddr != '' && !Sanitizer
::validateEmail( $newaddr ) ) {
158 return Status
::newFatal( 'invalidemailaddress' );
161 if ( $newaddr === $user->getEmail() ) {
162 return Status
::newFatal( 'changeemail-nochange' );
165 // To prevent spam, rate limit adding a new address, but do
166 // not rate limit removing an address.
167 if ( $newaddr !== '' && $user->pingLimiter( 'changeemail' ) ) {
168 return Status
::newFatal( 'actionthrottledtext' );
171 $oldaddr = $user->getEmail();
172 $status = $user->setEmailWithConfirmation( $newaddr );
173 if ( !$status->isGood() ) {
177 LoggerFactory
::getInstance( 'authentication' )->info(
178 'Changing email address for {user} from {oldemail} to {newemail}', [
179 'user' => $user->getName(),
180 'oldemail' => $oldaddr,
181 'newemail' => $newaddr,
185 Hooks
::run( 'PrefsEmailAudit', [ $user, $oldaddr, $newaddr ] );
187 $user->saveSettings();
192 public function requiresUnblock() {
196 protected function getGroupName() {