Ignore:
Timestamp:
02/22/26 20:32:09 (7 months ago)
Author:
Klimentina Efremova <klimentina08642@…>
Branches:
finki-main, main
Children:
79fff4f
Parents:
591278c
Message:

Fixed admin logging in and force change password

File:
1 edited

Legend:

Unmodified
Added
Removed
  • interfejs/change-password.html

    r591278c r4dff800  
    2727        <p class="form-subtitle" id="password-message">Please set a new password</p>
    2828
     29        <div id="error-message" class="error-message" style="display: none; color: red; margin-bottom: 1rem; padding: 10px; background-color: #ffeeee; border-radius: 5px;"></div>
     30        <div id="success-message" class="success-message" style="display: none; color: green; margin-bottom: 1rem; padding: 10px; background-color: #eeffee; border-radius: 5px;"></div>
     31
    2932        <form id="change-password-form" class="form">
    30             <div class="form-group">
    31                 <label for="current-password">Current Password</label>
    32                 <input type="password" id="current-password" name="current-password" required>
    33             </div>
    34 
    3533            <div class="form-group">
    3634                <label for="new-password">New Password</label>
    … …  
    4543
    4644            <div class="form-group">
    47                 <button type="submit" class="btn-primary btn-full">Change Password</button>
     45                <button type="submit" class="btn-primary btn-full" id="submit-btn">Change Password</button>
    4846            </div>
    4947        </form>
    … …  
    7573        const urlParams = new URLSearchParams(window.location.search);
    7674        const isForced = urlParams.get('forced') === 'true';
     75        let userType = 'admin'; // Default
    7776
    7877        if (isForced) {
    … …  
    8281
    8382        const form = document.getElementById('change-password-form');
     83        const submitBtn = document.getElementById('submit-btn');
     84        const errorDiv = document.getElementById('error-message');
     85        const successDiv = document.getElementById('success-message');
     86
     87        // Check if user is authenticated for password change and get user type
     88        checkAuthStatus();
     89
    8490        form.addEventListener('submit', async (e) => {
    8591            e.preventDefault();
    8692
     93            // Clear previous messages
     94            errorDiv.style.display = 'none';
     95            successDiv.style.display = 'none';
     96
     97            // Disable submit button to prevent double submission
     98            submitBtn.disabled = true;
     99            submitBtn.textContent = 'Changing Password...';
     100
    87101            const newPassword = document.getElementById('new-password').value;
    88102            const confirmPassword = document.getElementById('confirm-password').value;
    89103
     104            // Client-side validation
     105            if (!newPassword || !confirmPassword) {
     106                showError('All fields are required');
     107                submitBtn.disabled = false;
     108                submitBtn.textContent = 'Change Password';
     109                return;
     110            }
     111
    90112            if (newPassword !== confirmPassword) {
    91                 alert('New passwords do not match');
     113                showError('New passwords do not match');
     114                submitBtn.disabled = false;
     115                submitBtn.textContent = 'Change Password';
    92116                return;
    93117            }
    94118
     119            // Validate password strength
     120            const passwordRegex = /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[@$!%*?&])[A-Za-z\d@$!%*?&]{8,}$/;
     121            if (!passwordRegex.test(newPassword)) {
     122                showError('Password must have at least 8 characters, including uppercase, lowercase, number and special character');
     123                submitBtn.disabled = false;
     124                submitBtn.textContent = 'Change Password';
     125                return;
     126            }
     127
    95128            const formData = {
    96                 currentPassword: document.getElementById('current-password').value,
    97129                newPassword: newPassword,
    98130                confirmPassword: confirmPassword
    … …  
    100132
    101133            try {
     134                console.log('Sending password change request...');
    102135                const response = await fetch('/api/force-change-password', {
    103136                    method: 'POST',
    104                     headers: { 'Content-Type': 'application/json' },
    105                     body: JSON.stringify(formData)
     137                    headers: {
     138                        'Content-Type': 'application/json'
     139                    },
     140                    body: JSON.stringify(formData),
     141                    credentials: 'include' // Important: include cookies
    106142                });
    107143
    108144                const data = await response.json();
     145                console.log('Response:', data);
    109146
    110147                if (data.success) {
    111                     alert('Password changed successfully!');
    112                     window.location.href = data.redirectTo || 'dashboard.html';
     148                    showSuccess('Password changed successfully! Redirecting...');
     149
     150                    // Clear form
     151                    form.reset();
     152
     153                    // Redirect after short delay
     154                    setTimeout(() => {
     155                        window.location.href = data.redirectTo || 'dashboard.html';
     156                    }, 1500);
    113157                } else {
    114                     alert(data.message || 'Failed to change password');
     158                    showError(data.message || 'Failed to change password');
     159                    submitBtn.disabled = false;
     160                    submitBtn.textContent = 'Change Password';
    115161                }
    116162            } catch (error) {
    117163                console.error('Password change error:', error);
    118                 alert('An error occurred');
     164                showError('Network error: ' + error.message);
     165                submitBtn.disabled = false;
     166                submitBtn.textContent = 'Change Password';
    119167            }
    120168        });
     169
     170        async function checkAuthStatus() {
     171            try {
     172                const response = await fetch('/api/user', {
     173                    credentials: 'include'
     174                });
     175                const data = await response.json();
     176
     177                if (!data.success) {
     178                    // Not authenticated, redirect to login
     179                    window.location.href = 'login.html';
     180                } else if (data.isTempSession) {
     181                    console.log('Valid temporary session for password change');
     182                    if (data.user && data.user.userType) {
     183                        userType = data.user.userType;
     184                    }
     185                } else {
     186                    // Already have full session, redirect to appropriate dashboard
     187                    if (data.user && data.user.userType) {
     188                        switch(data.user.userType) {
     189                            case 'admin':
     190                                window.location.href = 'admin.html';
     191                                break;
     192                            case 'store_owner':
     193                                window.location.href = 'store-owner.html';
     194                                break;
     195                            case 'store_employee':
     196                                window.location.href = 'store-employee.html';
     197                                break;
     198                            case 'client':
     199                                window.location.href = 'client-dashboard.html';
     200                                break;
     201                            default:
     202                                window.location.href = 'dashboard.html';
     203                        }
     204                    }
     205                }
     206            } catch (error) {
     207                console.error('Auth check error:', error);
     208            }
     209        }
     210
     211        function showError(message) {
     212            errorDiv.textContent = message;
     213            errorDiv.style.display = 'block';
     214            setTimeout(() => {
     215                errorDiv.style.display = 'none';
     216            }, 5000);
     217        }
     218
     219        function showSuccess(message) {
     220            successDiv.textContent = message;
     221            successDiv.style.display = 'block';
     222        }
    121223    });
    122224</script>
Note: See TracChangeset for help on using the changeset viewer.