AuthManager: Commit transaction after auto-creating a user
[mediawiki.git] / includes / specials / SpecialCreateAccount.php
blobd01751e239d66743d9c3e8c788a1bccbb7121d3c
1 <?php
2 /**
3 * Implements Special:CreateAccount
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License, or
8 * (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
15 * You should have received a copy of the GNU General Public License along
16 * with this program; if not, write to the Free Software Foundation, Inc.,
17 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
18 * http://www.gnu.org/copyleft/gpl.html
20 * @file
21 * @ingroup SpecialPage
24 use MediaWiki\Auth\AuthManager;
25 use MediaWiki\Logger\LoggerFactory;
27 /**
28 * Implements Special:CreateAccount
30 * @ingroup SpecialPage
32 class SpecialCreateAccount extends LoginSignupSpecialPage {
33 protected static $allowedActions = [
34 AuthManager::ACTION_CREATE,
35 AuthManager::ACTION_CREATE_CONTINUE
38 protected static $messages = [
39 'authform-newtoken' => 'nocookiesfornew',
40 'authform-notoken' => 'sessionfailure',
41 'authform-wrongtoken' => 'sessionfailure',
44 public function __construct() {
45 parent::__construct( 'CreateAccount' );
48 public function doesWrites() {
49 return true;
52 public function isRestricted() {
53 return !User::groupHasPermission( '*', 'createaccount' );
56 public function userCanExecute( User $user ) {
57 return $user->isAllowed( 'createaccount' );
60 public function checkPermissions() {
61 parent::checkPermissions();
63 $user = $this->getUser();
64 $status = AuthManager::singleton()->checkAccountCreatePermissions( $user );
65 if ( !$status->isGood() ) {
66 throw new ErrorPageError( 'createacct-error', $status->getMessage() );
70 protected function getLoginSecurityLevel() {
71 return false;
74 protected function getDefaultAction( $subPage ) {
75 return AuthManager::ACTION_CREATE;
78 public function getDescription() {
79 return $this->msg( 'createaccount' )->text();
82 protected function isSignup() {
83 return true;
86 /**
87 * Run any hooks registered for logins, then display a message welcoming
88 * the user.
89 * @param bool $direct True if the action was successful just now; false if that happened
90 * pre-redirection (so this handler was called already)
91 * @param StatusValue|null $extraMessages
93 protected function successfulAction( $direct = false, $extraMessages = null ) {
94 $session = $this->getRequest()->getSession();
95 $user = $this->targetUser ?: $this->getUser();
97 if ( $direct ) {
98 # Only save preferences if the user is not creating an account for someone else.
99 if ( !$this->proxyAccountCreation ) {
100 Hooks::run( 'AddNewAccount', [ $user, false ] );
102 // If the user does not have a session cookie at this point, they probably need to
103 // do something to their browser.
104 if ( !$this->hasSessionCookie() ) {
105 $this->mainLoginForm( [ /*?*/ ], $session->getProvider()->whyNoSession() );
106 // TODO something more specific? This used to use nocookiesnew
107 // FIXME should redirect to login page instead?
108 return;
110 } else {
111 $byEmail = false; // FIXME no way to set this
113 Hooks::run( 'AddNewAccount', [ $user, $byEmail ] );
115 $out = $this->getOutput();
116 $out->setPageTitle( $this->msg( $byEmail ? 'accmailtitle' : 'accountcreated' ) );
117 if ( $byEmail ) {
118 $out->addWikiMsg( 'accmailtext', $user->getName(), $user->getEmail() );
119 } else {
120 $out->addWikiMsg( 'accountcreatedtext', $user->getName() );
122 $out->addReturnTo( $this->getPageTitle() );
123 return;
127 $this->clearToken();
129 # Run any hooks; display injected HTML
130 $injected_html = '';
131 $welcome_creation_msg = 'welcomecreation-msg';
132 Hooks::run( 'UserLoginComplete', [ &$user, &$injected_html ] );
135 * Let any extensions change what message is shown.
136 * @see https://www.mediawiki.org/wiki/Manual:Hooks/BeforeWelcomeCreation
137 * @since 1.18
139 Hooks::run( 'BeforeWelcomeCreation', [ &$welcome_creation_msg, &$injected_html ] );
141 $this->showSuccessPage( 'signup', $this->msg( 'welcomeuser', $this->getUser()->getName() ),
142 $welcome_creation_msg, $injected_html, $extraMessages );
145 protected function getToken() {
146 return $this->getRequest()->getSession()->getToken( '', 'createaccount' );
149 protected function clearToken() {
150 return $this->getRequest()->getSession()->resetToken( 'createaccount' );
153 protected function getTokenName() {
154 return 'wpCreateaccountToken';
157 protected function getGroupName() {
158 return 'login';
161 protected function logAuthResult( $success, $status = null ) {
162 LoggerFactory::getInstance( 'authmanager' )->info( 'Account creation attempt', [
163 'event' => 'accountcreation',
164 'successful' => $success,
165 'status' => $status,
166 ] );