<?php
/************************************************************************/
/* ajax_set_user_password.php                                           */
/*----------------------------------------------------------------------*/
/* Ajax handler for $mailserver->SetUserPassword() which in turn calls  */
/* COM::SetUserPassword()                                               */
/*----------------------------------------------------------------------*/
/* Copyright (c) 2008-2009 Avaya Inc.                                   */
/************************************************************************/

// This script is stored out of the way in the ajax folder, but needs to
// act as if it were called from folder above (scripts) so that paths
// used in require_once files remain valid. Hence, chdir to the dir above.
chdir('..');

// Include mailserver module
require_once('inc/mailserver.php');

// Recreate $_SESSION variable
session_start();

// Record client's time for this request
$ajax_timestamp = 0;
if( isset( $_GET['timestamp'] ) )
{
  $l = strlen($_GET['timestamp']);
  if( $l > 3 )
  {
    $time_string = substr($_GET['timestamp'],0,$l-3);
    $ajax_timestamp = (int)$time_string;
  }
}

// Record page access (also writes session id)
GetEventLog()->LogAccess();

// Check that visitor should be here. Authenticate populates $user record.
$user = null;
$mailserver = null;
$reason = GetSessionHandler()->Authenticate( session_id(), $user );
if ( $reason != SessionHandler::AUTH_SUCCESS )
{
  $res = 'auth+++ajax_set_user_password+++'. $reason;
  GetSessionHandler()->DestroySession();
  GetEventLog()->WriteError( gettext('Authentication failed:') . ' ' . GetSessionHandler()->ErrorText($reason) );
  header('Content-Type: text/plain; charset="utf-8"');
  header('Content-Length: ' . strlen($res));
  echo $res;
  exit;
}
else
{
  // Connect to mail server
  $mailserver = GetMailserver();
  if( !$mailserver )
  {
    $res = 'error+++ajax_set_user_password+++' . gettext("Can't connect to mailserver.");
    GetEventLog()->WriteError( gettext("Can't connect to mailserver.") );
    header('Content-Type: text/plain; charset="utf-8"');
    header('Content-Length: ' . strlen($res));
    echo $res;
    exit;
  }

  // Keep session active
  $mailserver->UpdateLastAction( session_id(), $user->id, 0 );
}

//session_write_close();

// Initialise script output
$res = false;

// Get parameters from query string
if( !isset( $_POST['userId'] )
 || !isset( $_POST['opwd'] )
 || !isset( $_POST['pwd'] )
 || !isset( $_POST['mbId'] ) )
{
  $res = 'error+++ajax_set_user_password+++Request is missing parameters.';
  GetEventLog()->WriteError( gettext("Request is missing parameters.")
  . " userId=\"" . isset($_POST['userId']) . "\""
  . " opwd=\"" . isset($_POST['opwd']) . "\""
  . " pwd=\"" . isset($_POST['pwd']) . "\""
  . " mbId=\"" . isset($_POST['mbId']) . "\"" );
}
else
{
  $userid = Disinfect( $_POST['userId'] );
  $opwd = Disinfect( $_POST['opwd'] );
  $pwd = Disinfect( $_POST['pwd'] );
  $mbId = Disinfect( $_POST['mbId'] );

  try
  {
    if( !$mailserver->SetUserPassword(session_id(), $mbId, $userid, $pwd, $opwd) )
    {
      $res = 'error+++ajax_set_user_password+++'. gettext('Password could not be changed.');
    }

  }
  catch (Exception $e)
  {
    $res = false;
  }
}


// Output to the stream the resulting HTML
header('Content-Type: text/plain; charset="utf-8"');
header('Content-Length: ' . strlen($res));
echo $res;

?>
