Setting counter for AspNet Identity token

34 Views Asked by At

I am using this method for Reset Password

public ResetTokenResult DoPasswordResetTokenForChange(string userId, string token)
    {
        switch (UserManager.FindById(userId))
        {
            case null:
                return ResetTokenResult.UnknownUserId;

            case CatalystUser user when ! (user.PasswordInvalidatedByReset ?? false):
                return ResetTokenResult.TokenIsExpired;

            case CatalystUser user when ! ((user.PasswordResetTokenExpiration ?? DateTime.MinValue) > DateTime.UtcNow):
                return ResetTokenResult.TokenIsExpired;

            case CatalystUser user when UserManager.VerifyUserToken(user.Id, "ResetPassword", token):
                user.PasswordResetTokenExpiration = DateTime.UtcNow.AddDays(-1); // 1-time use. Invalidate now.UserManager.Update(user);
                return ResetTokenResult.Success;

            default:
                return ResetTokenResult.InvalidToken;

        }
  }

Controller which I am using this method

    [RequireHttpsWhenConfigured]
    public async Task<ActionResult> Index(PasswordChangePage currentPage, 
    string userId, string token, string returnUrl = "")
    {
        var model = new PasswordChangePageViewModel(currentPage);
        var isResetPasswordRequest = !string.IsNullOrEmpty(userId) && !string.IsNullOrEmpty(token);
        if (!isResetPasswordRequest)
        {
            if (!RequestContext.IsCurrentUserAuthorized()) 

                return Redirect(NavigationService.GetLoginLink());

            model.PasswordChangeModel = new PasswordChangeViewModel {ReturnUrl = returnUrl};
            model.ReturnUrl = returnUrl;
            return View("Index", model);
        }

        if (RequestContext.IsCurrentUserAuthorized())
        {
            SignInManager.AuthenticationManager.SignOut();
            return Redirect(Request.Url?.AbsoluteUri ?? "~/");
        }

        var loginLink = NavigationService.GetLoginLink();
        var result = UserAccountService.DoPasswordResetTokenForChange(userId,Base64ForUrlDecode(token));
        if ((result & ResetTokenResult.Failure) != ResetTokenResult.None)
        {
            model.ChangeCanProceed = false;
            model.ErrorMessage = GetMessageForTokenResult(result);
            model.LoginLink = loginLink;
        }
        else
        {
            model.PasswordChangeModel = new PasswordChangeViewModel { CurrentPassword = "null", IsResetPassword = true, UserId = userId, ResetPasswordToken = token };
            model.ReturnUrl = loginLink;
        }

        return View("Index", model);
    }

When users want to reset their password, they receive an email with a token link and everything works fine. As I know default ASPNET Identity token burns after 1 clicking to link. My question is what is the best way to implement logic, the token link will burn after 5 clickings to link which is sent to email.

0

There are 0 best solutions below