Authored by Rock Zhang

限制对输入新密码页面的访问

@@ -209,7 +209,7 @@ class BackController extends AbstractAction @@ -209,7 +209,7 @@ class BackController extends AbstractAction
209 'phoneNum' => $phoneNum 209 'phoneNum' => $phoneNum
210 ); 210 );
211 211
212 - $this->_view->assign('title', 'YOHO!有货'); 212 + $this->setTitle('找回密码-通过手机号');
213 $this->_view->display('mobile-code', $data); 213 $this->_view->display('mobile-code', $data);
214 } 214 }
215 215
@@ -247,6 +247,11 @@ class BackController extends AbstractAction @@ -247,6 +247,11 @@ class BackController extends AbstractAction
247 // 邮箱验证码 247 // 邮箱验证码
248 $code = $this->get('code', ''); 248 $code = $this->get('code', '');
249 249
  250 + // 判断是否允许访问, 不允许则跳转到错误页面
  251 + if ((!$token || !Helpers::verifyMobile($phoneNum)) && !$code) {
  252 + $this->error();
  253 + }
  254 +
250 $data = array( 255 $data = array(
251 'backUrl' => '/signin.html', 256 'backUrl' => '/signin.html',
252 'headerText' => '找回密码', 257 'headerText' => '找回密码',
@@ -258,7 +263,7 @@ class BackController extends AbstractAction @@ -258,7 +263,7 @@ class BackController extends AbstractAction
258 'code' => $code 263 'code' => $code
259 ); 264 );
260 265
261 - $this->_view->assign('title', 'YOHO!有货'); 266 + $this->setTitle('找回密码-输入新密码');
262 $this->_view->display('new-password', $data); 267 $this->_view->display('new-password', $data);
263 } 268 }
264 269