bigbuffet-rw/app/soapbox/features/security/index.js

407 lines
13 KiB
JavaScript
Raw Normal View History

2020-06-05 12:25:26 -07:00
import React from 'react';
import { connect } from 'react-redux';
2020-06-05 14:24:07 -07:00
import { defineMessages, injectIntl, FormattedDate } from 'react-intl';
2020-06-05 12:25:26 -07:00
import ImmutablePureComponent from 'react-immutable-pure-component';
import PropTypes from 'prop-types';
2020-06-05 13:43:03 -07:00
import ImmutablePropTypes from 'react-immutable-proptypes';
2020-08-07 13:17:13 -07:00
import Button from 'soapbox/components/button';
import ShowablePassword from 'soapbox/components/showable_password';
2020-06-05 12:25:26 -07:00
import {
SimpleForm,
FieldsGroup,
TextInput,
} from 'soapbox/features/forms';
2020-06-05 13:43:03 -07:00
import {
changeEmail,
changePassword,
2020-07-20 13:23:38 -07:00
deleteAccount,
} from 'soapbox/actions/security';
2021-08-21 17:37:28 -07:00
import { fetchOAuthTokens, revokeOAuthTokenById } from 'soapbox/actions/security';
import snackbar from 'soapbox/actions/snackbar';
2022-01-07 12:26:19 -08:00
import { getSettings } from 'soapbox/actions/settings';
2022-01-10 14:01:24 -08:00
import { fetchMfa } from '../../actions/mfa';
import Column from '../ui/components/column';
2020-06-05 12:25:26 -07:00
/*
Security settings page for user account
Routed to /auth/edit
Includes following features:
- Change Email
- Change Password
- Sessions
- Deactivate Account
*/
2020-06-05 12:25:26 -07:00
const messages = defineMessages({
heading: { id: 'column.security', defaultMessage: 'Security' },
submit: { id: 'security.submit', defaultMessage: 'Save changes' },
2020-06-05 12:39:27 -07:00
updateEmailSuccess: { id: 'security.update_email.success', defaultMessage: 'Email successfully updated.' },
updateEmailFail: { id: 'security.update_email.fail', defaultMessage: 'Update email failed.' },
2020-06-05 13:14:27 -07:00
updatePasswordSuccess: { id: 'security.update_password.success', defaultMessage: 'Password successfully updated.' },
updatePasswordFail: { id: 'security.update_password.fail', defaultMessage: 'Update password failed.' },
2020-06-05 13:21:29 -07:00
emailFieldLabel: { id: 'security.fields.email.label', defaultMessage: 'Email address' },
passwordFieldLabel: { id: 'security.fields.password.label', defaultMessage: 'Password' },
oldPasswordFieldLabel: { id: 'security.fields.old_password.label', defaultMessage: 'Current password' },
newPasswordFieldLabel: { id: 'security.fields.new_password.label', defaultMessage: 'New password' },
confirmationFieldLabel: { id: 'security.fields.password_confirmation.label', defaultMessage: 'New password (again)' },
2020-06-05 14:24:07 -07:00
revoke: { id: 'security.tokens.revoke', defaultMessage: 'Revoke' },
emailHeader: { id: 'security.headers.update_email', defaultMessage: 'Change Email' },
passwordHeader: { id: 'security.headers.update_password', defaultMessage: 'Change Password' },
tokenHeader: { id: 'security.headers.tokens', defaultMessage: 'Sessions' },
2020-07-20 13:23:38 -07:00
deleteHeader: { id: 'security.headers.delete', defaultMessage: 'Delete Account' },
deleteText: { id: 'security.text.delete', defaultMessage: 'To delete your account, enter your password then click Delete Account. This is a permanent action that cannot be undone. Your account will be destroyed from this server, and a deletion request will be sent to other servers. It\'s not guaranteed that all servers will purge your account.' },
deleteSubmit: { id: 'security.submit.delete', defaultMessage: 'Delete Account' },
deleteAccountSuccess: { id: 'security.delete_account.success', defaultMessage: 'Account successfully deleted.' },
deleteAccountFail: { id: 'security.delete_account.fail', defaultMessage: 'Account deletion failed.' },
2020-08-07 13:17:13 -07:00
mfa: { id: 'security.mfa', defaultMessage: 'Set up 2-Factor Auth' },
mfa_setup_hint: { id: 'security.mfa_setup_hint', defaultMessage: 'Configure multi-factor authentication with OTP' },
mfa_enabled: { id: 'security.mfa_enabled', defaultMessage: 'You have multi-factor authentication set up with OTP.' },
disable_mfa: { id: 'security.disable_mfa', defaultMessage: 'Disable' },
mfaHeader: { id: 'security.mfa_header', defaultMessage: 'Authorization Methods' },
});
const mapStateToProps = state => ({
settings: getSettings(state),
tokens: state.getIn(['security', 'tokens']),
2022-01-07 12:26:19 -08:00
mfa: state.getIn(['security', 'mfa']),
2020-06-05 12:25:26 -07:00
});
2020-08-07 13:17:13 -07:00
export default @connect(mapStateToProps)
@injectIntl
2020-06-05 13:00:24 -07:00
class SecurityForm extends ImmutablePureComponent {
2020-06-05 12:25:26 -07:00
2020-06-05 14:24:07 -07:00
static propTypes = {
dispatch: PropTypes.func.isRequired,
intl: PropTypes.object.isRequired,
};
render() {
const { intl } = this.props;
return (
<Column icon='lock' heading={intl.formatMessage(messages.heading)}>
<ChangeEmailForm />
2020-06-05 13:14:27 -07:00
<ChangePasswordForm />
2020-08-07 13:17:13 -07:00
<SetUpMfa />
2020-06-05 13:43:03 -07:00
<AuthTokenList />
<DeactivateAccount />
</Column>
);
}
}
@connect()
@injectIntl
class ChangeEmailForm extends ImmutablePureComponent {
2020-06-05 12:25:26 -07:00
static propTypes = {
email: PropTypes.string,
dispatch: PropTypes.func.isRequired,
intl: PropTypes.object.isRequired,
};
2020-06-05 12:39:27 -07:00
state = {
email: '',
password: '',
2020-06-05 12:50:24 -07:00
isLoading: false,
2020-06-05 12:39:27 -07:00
}
2020-06-05 12:25:26 -07:00
handleInputChange = e => {
this.setState({ [e.target.name]: e.target.value });
}
handleSubmit = e => {
const { email, password } = this.state;
2020-06-05 12:39:27 -07:00
const { dispatch, intl } = this.props;
2020-06-05 12:50:24 -07:00
this.setState({ isLoading: true });
return dispatch(changeEmail(email, password)).then(() => {
2020-06-05 12:45:00 -07:00
this.setState({ email: '', password: '' }); // TODO: Maybe redirect user
dispatch(snackbar.success(intl.formatMessage(messages.updateEmailSuccess)));
2020-06-05 12:39:27 -07:00
}).catch(error => {
2020-06-05 12:45:00 -07:00
this.setState({ password: '' });
dispatch(snackbar.error(intl.formatMessage(messages.updateEmailFail)));
2020-06-05 12:50:24 -07:00
}).then(() => {
this.setState({ isLoading: false });
2020-06-05 12:39:27 -07:00
});
2020-06-05 12:25:26 -07:00
}
render() {
const { intl } = this.props;
return (
<SimpleForm onSubmit={this.handleSubmit}>
2020-06-05 14:24:07 -07:00
<h2>{intl.formatMessage(messages.emailHeader)}</h2>
<fieldset disabled={this.state.isLoading}>
<FieldsGroup>
<TextInput
2020-06-05 13:21:29 -07:00
label={intl.formatMessage(messages.emailFieldLabel)}
placeholder='me@example.com'
name='email'
onChange={this.handleInputChange}
value={this.state.email}
/>
<ShowablePassword
2020-06-05 13:21:29 -07:00
label={intl.formatMessage(messages.passwordFieldLabel)}
name='password'
onChange={this.handleInputChange}
value={this.state.password}
/>
<div className='actions'>
<button name='button' type='submit' className='btn button button-primary'>
{intl.formatMessage(messages.submit)}
</button>
</div>
</FieldsGroup>
</fieldset>
</SimpleForm>
2020-06-05 12:25:26 -07:00
);
}
}
2020-06-05 13:14:27 -07:00
@connect()
@injectIntl
class ChangePasswordForm extends ImmutablePureComponent {
static propTypes = {
dispatch: PropTypes.func.isRequired,
intl: PropTypes.object.isRequired,
};
state = {
oldPassword: '',
newPassword: '',
confirmation: '',
isLoading: false,
}
handleInputChange = e => {
this.setState({ [e.target.name]: e.target.value });
}
clearForm = () => {
this.setState({ oldPassword: '', newPassword: '', confirmation: '' });
}
handleSubmit = e => {
const { oldPassword, newPassword, confirmation } = this.state;
const { dispatch, intl } = this.props;
this.setState({ isLoading: true });
return dispatch(changePassword(oldPassword, newPassword, confirmation)).then(() => {
this.clearForm(); // TODO: Maybe redirect user
dispatch(snackbar.success(intl.formatMessage(messages.updatePasswordSuccess)));
2020-06-05 13:14:27 -07:00
}).catch(error => {
this.clearForm();
dispatch(snackbar.error(intl.formatMessage(messages.updatePasswordFail)));
2020-06-05 13:14:27 -07:00
}).then(() => {
this.setState({ isLoading: false });
});
}
render() {
const { intl } = this.props;
return (
<SimpleForm onSubmit={this.handleSubmit}>
2020-06-05 14:24:07 -07:00
<h2>{intl.formatMessage(messages.passwordHeader)}</h2>
2020-06-05 13:14:27 -07:00
<fieldset disabled={this.state.isLoading}>
<FieldsGroup>
<ShowablePassword
2020-06-05 13:21:29 -07:00
label={intl.formatMessage(messages.oldPasswordFieldLabel)}
2020-06-05 13:14:27 -07:00
name='oldPassword'
onChange={this.handleInputChange}
value={this.state.oldPassword}
/>
<ShowablePassword
2020-06-05 13:21:29 -07:00
label={intl.formatMessage(messages.newPasswordFieldLabel)}
2020-06-05 13:14:27 -07:00
name='newPassword'
onChange={this.handleInputChange}
value={this.state.newPassword}
/>
<ShowablePassword
2020-06-05 13:21:29 -07:00
label={intl.formatMessage(messages.confirmationFieldLabel)}
2020-06-05 13:14:27 -07:00
name='confirmation'
onChange={this.handleInputChange}
value={this.state.confirmation}
/>
<div className='actions'>
<button name='button' type='submit' className='btn button button-primary'>
{intl.formatMessage(messages.submit)}
</button>
</div>
</FieldsGroup>
</fieldset>
</SimpleForm>
);
}
}
2020-06-05 13:43:03 -07:00
2020-08-07 13:17:13 -07:00
@connect(mapStateToProps)
@injectIntl
class SetUpMfa extends ImmutablePureComponent {
static contextTypes = {
router: PropTypes.object,
};
static propTypes = {
intl: PropTypes.object.isRequired,
2022-01-07 12:26:19 -08:00
mfa: ImmutablePropTypes.map.isRequired,
2020-08-07 13:17:13 -07:00
};
handleMfaClick = e => {
this.context.router.history.push('../auth/mfa');
}
2022-01-07 12:26:19 -08:00
componentDidMount() {
this.props.dispatch(fetchMfa());
}
2020-08-07 13:17:13 -07:00
render() {
2022-01-07 12:26:19 -08:00
const { intl, mfa } = this.props;
2020-08-07 13:17:13 -07:00
return (
<SimpleForm>
<h2>{intl.formatMessage(messages.mfaHeader)}</h2>
2022-01-07 12:26:19 -08:00
{!mfa.getIn(['settings', 'totp']) ?
2020-08-07 13:17:13 -07:00
<div>
<p className='hint'>
{intl.formatMessage(messages.mfa_setup_hint)}
</p>
<Button className='button button-secondary set-up-mfa' text={intl.formatMessage(messages.mfa)} onClick={this.handleMfaClick} />
</div> :
<div>
<p className='hint'>
{intl.formatMessage(messages.mfa_enabled)}
</p>
<Button className='button button--destructive disable-mfa' text={intl.formatMessage(messages.disable_mfa)} onClick={this.handleMfaClick} />
</div>
}
</SimpleForm>
);
}
}
2020-06-05 13:43:03 -07:00
@connect(mapStateToProps)
@injectIntl
class AuthTokenList extends ImmutablePureComponent {
static propTypes = {
2020-06-05 14:24:07 -07:00
dispatch: PropTypes.func.isRequired,
intl: PropTypes.object.isRequired,
2020-06-05 13:43:03 -07:00
tokens: ImmutablePropTypes.list,
2020-06-05 14:24:07 -07:00
};
2020-06-05 13:43:03 -07:00
2020-06-05 13:54:09 -07:00
handleRevoke = id => {
return e => {
2021-08-21 17:37:28 -07:00
this.props.dispatch(revokeOAuthTokenById(id));
2020-06-05 13:54:09 -07:00
};
}
2020-06-05 13:43:03 -07:00
componentDidMount() {
this.props.dispatch(fetchOAuthTokens());
}
render() {
2020-06-05 14:24:07 -07:00
const { tokens, intl } = this.props;
if (tokens.isEmpty()) return null;
2020-06-05 13:43:03 -07:00
return (
<SimpleForm>
2020-06-05 14:24:07 -07:00
<h2>{intl.formatMessage(messages.tokenHeader)}</h2>
<div className='authtokens'>
{tokens.reverse().map((token, i) => (
<div key={i} className='authtoken'>
<div className='authtoken__app-name'>{token.get('app_name')}</div>
<div className='authtoken__valid-until'>
<FormattedDate
value={new Date(token.get('valid_until'))}
hour12={false}
year='numeric'
month='short'
day='2-digit'
hour='2-digit'
minute='2-digit'
/>
</div>
<div className='authtoken__revoke'>
<button onClick={this.handleRevoke(token.get('id'))}>
{this.props.intl.formatMessage(messages.revoke)}
</button>
</div>
2020-06-05 13:54:09 -07:00
</div>
2020-06-05 14:24:07 -07:00
))}
</div>
2020-06-05 13:43:03 -07:00
</SimpleForm>
);
}
}
@connect(mapStateToProps)
@injectIntl
class DeactivateAccount extends ImmutablePureComponent {
static propTypes = {
dispatch: PropTypes.func.isRequired,
intl: PropTypes.object.isRequired,
};
state = {
password: '',
isLoading: false,
}
handleInputChange = e => {
this.setState({ [e.target.name]: e.target.value });
}
handleSubmit = e => {
const { password } = this.state;
const { dispatch, intl } = this.props;
this.setState({ isLoading: true });
return dispatch(deleteAccount(intl, password)).then(() => {
//this.setState({ email: '', password: '' }); // TODO: Maybe redirect user
dispatch(snackbar.success(intl.formatMessage(messages.deleteAccountSuccess)));
}).catch(error => {
this.setState({ password: '' });
dispatch(snackbar.error(intl.formatMessage(messages.deleteAccountFail)));
}).then(() => {
this.setState({ isLoading: false });
});
}
render() {
const { intl } = this.props;
return (
<SimpleForm onSubmit={this.handleSubmit}>
2020-07-20 13:23:38 -07:00
<h2>{intl.formatMessage(messages.deleteHeader)}</h2>
<p className='hint'>
2020-07-20 13:23:38 -07:00
{intl.formatMessage(messages.deleteText)}
</p>
<fieldset disabled={this.state.isLoading}>
<FieldsGroup>
<ShowablePassword
label={intl.formatMessage(messages.passwordFieldLabel)}
name='password'
onChange={this.handleInputChange}
value={this.state.password}
/>
<div className='actions'>
<button name='button' type='submit' className='btn button button-primary'>
2020-07-20 13:23:38 -07:00
{intl.formatMessage(messages.deleteSubmit)}
</button>
</div>
</FieldsGroup>
</fieldset>
</SimpleForm>
);
}
}