- do_action('retreive_password', $user_login); // Misspelled and deprecated
- do_action('retrieve_password', $user_login);
-
- $allow = apply_filters('allow_password_reset', true, $user_data->ID);
-
- if ( ! $allow )
- return new WP_Error('no_password_reset', __('Password reset is not allowed for this user'));
- else if ( is_wp_error($allow) )
- return $allow;
-
- $key = $wpdb->get_var($wpdb->prepare("SELECT user_activation_key FROM $wpdb->users WHERE user_login = %s", $user_login));
- if ( empty($key) ) {
- // Generate something random for a key...
- $key = wp_generate_password(20, false);
- do_action('retrieve_password_key', $user_login, $key);
- // Now insert the new md5 key into the db
- $wpdb->query($wpdb->prepare("UPDATE $wpdb->users SET user_activation_key = %s WHERE user_login = %s", $key, $user_login));
- }
- $message = __('Someone has asked to reset the password for the following site and username.') . "\r\n\r\n";
- $message .= get_option('siteurl') . "\r\n\r\n";
- $message .= sprintf(__('Username: %s'), $user_login) . "\r\n\r\n";
- $message .= __('To reset your password visit the following address, otherwise just ignore this email and nothing will happen.') . "\r\n\r\n";
- $message .= site_url("wp-login.php?action=rp&key=$key", 'login') . "\r\n";
-
- if ( !wp_mail($user_email, sprintf(__('[%s] Password Reset'), get_option('blogname')), $message) )
- die('<p>' . __('The e-mail could not be sent.') . "<br />\n" . __('Possible reason: your host may have disabled the mail() function...') . '</p>');
-
- return true;
-}
-
-/**
- * reset_password() - Handles resetting the user's password
- *
- * {@internal Missing Long Description}}
- *
- * @uses $wpdb WordPress Database object
- *
- * @param string $key Hash to validate sending user's password
- * @return bool|WP_Error
- */
-function reset_password($key) {
- global $wpdb;
-
- $key = preg_replace('/[^a-z0-9]/i', '', $key);
-
- if ( empty( $key ) )
- return new WP_Error('invalid_key', __('Invalid key'));
-
- $user = $wpdb->get_row($wpdb->prepare("SELECT * FROM $wpdb->users WHERE user_activation_key = %s", $key));
- if ( empty( $user ) )
- return new WP_Error('invalid_key', __('Invalid key'));
-
- do_action('password_reset', $user);
-
- // Generate something random for a password...
- $new_pass = wp_generate_password();
- wp_set_password($new_pass, $user->ID);
- $message = sprintf(__('Username: %s'), $user->user_login) . "\r\n";
- $message .= sprintf(__('Password: %s'), $new_pass) . "\r\n";
- $message .= site_url('wp-login.php', 'login') . "\r\n";
-
- if ( !wp_mail($user->user_email, sprintf(__('[%s] Your new password'), get_option('blogname')), $message) )
- die('<p>' . __('The e-mail could not be sent.') . "<br />\n" . __('Possible reason: your host may have disabled the mail() function...') . '</p>');
-
- // send a copy of password change notification to the admin
- // but check to see if it's the admin whose password we're changing, and skip this
- if ( $user->user_email != get_option('admin_email') ) {
- $message = sprintf(__('Password Lost and Changed for user: %s'), $user->user_login) . "\r\n";
- wp_mail(get_option('admin_email'), sprintf(__('[%s] Password Lost/Changed'), get_option('blogname')), $message);