# This patch file was generated by NetBeans IDE
# It uses platform neutral UTF-8 encoding and \n newlines.
# 2013.07.16
--- ldap_authentication.module
+++ ldap_authentication.module
@@ -341,10 +341,79 @@
 function ldap_authentication_form_user_profile_form_alter(&$form, $form_state) {
   ldap_servers_module_load_include('inc', 'ldap_authentication', 'ldap_authentication');
   _ldap_authentication_form_user_profile_form_alter($form, $form_state, 'user_login');
+  //Alter password validation. Uses LDAP instead of drupal.
+  //@see ldap_authentication_current_pass()
+  foreach ($form['#validate'] as $key => $validate) {
+    if ($validate == 'user_validate_current_pass' && $form['#user']->uid != 1) {
+      unset($form['#validate'][$key]);
+      $form['#validate'] = array_merge($form['#validate'], array('ldap_authentication_current_pass'));
+    }
+  }
+}
 
+/**
+ * Implements hook for user_validate_current_pass() in user.module
+ * 
+ * @param type $form
+ * @param type $form_state
+ */
+function ldap_authentication_current_pass(&$form, &$form_state) {
+  //Set True for debugging info!(Server names, found ldapObject(user), credentials sent to ldap) 
+  $ldap_debug = FALSE;
+  $account = $form['#user'];
+  foreach ($form_state['values']['current_pass_required_values'] as $key => $name) {
+    // This validation only works for required textfields (like mail) or
+    // form values like password_confirm that have their own validation
+    // that prevent them from being empty if they are changed.
+    if ((strlen(trim($form_state['values'][$key])) > 0) && ($form_state['values'][$key] != $account->$key)) {
+      $auth_conf = ldap_authentication_get_valid_conf();
+      //Check the password for all enabled LDAP-server(it may be more).
+      foreach ($auth_conf->enabledAuthenticationServers as $sid => $ldap_server) { 
+        //Debug
+        if($ldap_debug){
+           drupal_set_message("Checking LDAP-server(SID): ");
+           drupal_set_message(dprint_r($sid, TRUE)); 
 }
+        if (isset($account->data['ldap_user']['init']['dn'])) {
+          $dn = $account->data['ldap_user']['init']['dn'];
+        }
+        elseif (isset($account->ldap_user_current_dn['und'][0]['value'])){
+          $dn = $account->ldap_user_current_dn['und'][0]['value'];
+        }  
+        $parts = explode(',', $dn);
+        foreach ($parts as $part) {
+          $piece = explode('=', $part);
+          if ($piece[0] == 'uid') {
+            $uid = $piece[1];
+            break;
+          }       
+        }
+        $result = $ldap_server->search('', '(uid='. $uid .')', array('mail', 'dn', 'userPassword'));
+        //Choose md5 or SHA. The form your password in LDAP.
+        //$pass_from_form =  '{md5}'. base64_encode(pack('H*', md5($form_state['values']['current_pass']))); //md5
+        $pass_from_form = '{SHA}'. base64_encode(pack("H*", sha1($form_state['values']['current_pass']))); //SHA
+        $pass_from_ldap = $result[0]['userpassword'][0];
+        if ($pass_from_form != $pass_from_ldap) {
+          form_set_error('current_pass', t("Your current password is missing or incorrect. It's required to change the %name.", array('%name' => $name)));
+          form_set_error($key);
+          //Debug
+          if($ldap_debug){
+              drupal_set_message("ldapObject(user) found: ");
+              drupal_set_message(dprint_r($result, TRUE)); 
+              drupal_set_message("credentials sent to ldap: dn: ".$dn." pass: ".$pass_from_form);  
+          }
+        }
+        if ($pass_from_form != $pass_from_ldap) {  
+          // We only need to check the password until it pass on one LDAP-server(if there is more).
+          break;
+        }
+      }
+      // We only need to check the password for one field.
+      break;
+    }
+  }
+}
 
-
 /**
  * Implements hook_form_FORM_ID_alter(). for user_login
  */

