if (username != null) {
customer = customerDao.readCustomerByUsername(username);
}
checkCustomer(customer, response);
checkPassword(password, confirmPassword, response);
CustomerForgotPasswordSecurityToken fpst = checkPasswordResetToken(token, response);
if (! response.getHasErrors()) {
if (! customer.getId().equals(fpst.getCustomerId())) {
if (LOG.isWarnEnabled()) {
LOG.warn("Password reset attempt tried with mismatched customer and token " + customer.getId() + ", " + token);
}
response.addErrorCode("invalidToken");
}
}
if (! response.getHasErrors()) {
customer.setUnencodedPassword(password);
saveCustomer(customer);
fpst.setTokenUsedFlag(true);
customerForgotPasswordSecurityTokenDao.saveToken(fpst);
}
return response;
}