2010-01-06 09:33:05 +00:00
|
|
|
<?php
|
|
|
|
|
|
|
|
// This file is part of Moodle - http://moodle.org/
|
|
|
|
//
|
|
|
|
// Moodle is free software: you can redistribute it and/or modify
|
|
|
|
// it under the terms of the GNU General Public License as published by
|
|
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
|
|
// (at your option) any later version.
|
|
|
|
//
|
|
|
|
// Moodle is distributed in the hope that it will be useful,
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
// GNU General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU General Public License
|
|
|
|
// along with Moodle. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Web services tokens admin UI
|
|
|
|
*
|
|
|
|
* @package webservice
|
|
|
|
* @author Jerome Mouneyrac
|
|
|
|
* @copyright 2009 Moodle Pty Ltd (http://moodle.com)
|
|
|
|
* @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
|
|
|
|
*/
|
|
|
|
require_once('../../config.php');
|
2010-07-27 03:53:55 +00:00
|
|
|
require_once($CFG->libdir . '/adminlib.php');
|
|
|
|
require_once($CFG->libdir . '/externallib.php');
|
2010-01-06 09:33:05 +00:00
|
|
|
|
2012-05-11 13:42:27 +08:00
|
|
|
$action = optional_param('action', '', PARAM_ALPHANUMEXT);
|
2010-01-20 07:20:03 +00:00
|
|
|
$tokenid = optional_param('tokenid', '', PARAM_SAFEDIR);
|
|
|
|
$confirm = optional_param('confirm', 0, PARAM_BOOL);
|
|
|
|
|
2010-01-11 08:23:39 +00:00
|
|
|
admin_externalpage_setup('addwebservicetoken');
|
|
|
|
|
2010-10-06 02:25:32 +00:00
|
|
|
//Deactivate the second 'Manage token' navigation node, and use the main 'Manage token' navigation node
|
|
|
|
$node = $PAGE->settingsnav->find('addwebservicetoken', navigation_node::TYPE_SETTING);
|
|
|
|
$newnode = $PAGE->settingsnav->find('webservicetokens', navigation_node::TYPE_SETTING);
|
|
|
|
if ($node && $newnode) {
|
|
|
|
$node->display = false;
|
|
|
|
$newnode->make_active();
|
|
|
|
}
|
|
|
|
|
2010-01-06 09:33:05 +00:00
|
|
|
|
2010-09-24 02:45:39 +00:00
|
|
|
$tokenlisturl = new moodle_url("/" . $CFG->admin . "/settings.php", array('section' => 'webservicetokens'));
|
2010-01-06 09:33:05 +00:00
|
|
|
|
2010-09-24 07:05:39 +00:00
|
|
|
require_once($CFG->dirroot . "/webservice/lib.php");
|
|
|
|
$webservicemanager = new webservice();
|
|
|
|
|
2010-01-06 09:33:05 +00:00
|
|
|
switch ($action) {
|
2010-07-27 03:53:55 +00:00
|
|
|
|
2010-01-06 09:33:05 +00:00
|
|
|
case 'create':
|
2020-01-21 13:21:58 +01:00
|
|
|
$mform = new \core_webservice\token_form(null, array('action' => 'create'));
|
2010-07-27 03:53:55 +00:00
|
|
|
$data = $mform->get_data();
|
2010-01-11 08:23:39 +00:00
|
|
|
if ($mform->is_cancelled()) {
|
2010-07-27 03:53:55 +00:00
|
|
|
redirect($tokenlisturl);
|
|
|
|
} else if ($data and confirm_sesskey()) {
|
|
|
|
ignore_user_abort(true);
|
2010-09-24 07:05:39 +00:00
|
|
|
|
|
|
|
//check the the user is allowed for the service
|
|
|
|
$selectedservice = $webservicemanager->get_external_service_by_id($data->service);
|
|
|
|
if ($selectedservice->restrictedusers) {
|
|
|
|
$restricteduser = $webservicemanager->get_ws_authorised_user($data->service, $data->user);
|
|
|
|
if (empty($restricteduser)) {
|
2010-09-24 07:06:47 +00:00
|
|
|
$allowuserurl = new moodle_url('/' . $CFG->admin . '/webservice/service_users.php',
|
2010-09-24 07:05:39 +00:00
|
|
|
array('id' => $selectedservice->id));
|
|
|
|
$allowuserlink = html_writer::tag('a', $selectedservice->name , array('href' => $allowuserurl));
|
|
|
|
$errormsg = $OUTPUT->notification(get_string('usernotallowed', 'webservice', $allowuserlink));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2011-11-14 12:09:40 +08:00
|
|
|
//check if the user is deleted. unconfirmed, suspended or guest
|
|
|
|
$user = $DB->get_record('user', array('id' => $data->user));
|
|
|
|
if ($user->id == $CFG->siteguest or $user->deleted or !$user->confirmed or $user->suspended) {
|
|
|
|
throw new moodle_exception('forbiddenwsuser', 'webservice');
|
|
|
|
}
|
|
|
|
|
2010-09-24 07:05:39 +00:00
|
|
|
//process the creation
|
|
|
|
if (empty($errormsg)) {
|
|
|
|
//TODO improvement: either move this function from externallib.php to webservice/lib.php
|
|
|
|
// either move most of webservicelib.php functions into externallib.php
|
|
|
|
// (create externalmanager class) MDL-23523
|
|
|
|
external_generate_token(EXTERNAL_TOKEN_PERMANENT, $data->service,
|
2012-07-23 14:33:02 +08:00
|
|
|
$data->user, context_system::instance(),
|
2010-09-24 07:05:39 +00:00
|
|
|
$data->validuntil, $data->iprestriction);
|
|
|
|
redirect($tokenlisturl);
|
|
|
|
}
|
2010-01-11 08:23:39 +00:00
|
|
|
}
|
|
|
|
|
2010-07-27 03:53:55 +00:00
|
|
|
//OUTPUT: create token form
|
2010-03-31 08:05:53 +00:00
|
|
|
echo $OUTPUT->header();
|
2010-01-11 08:23:39 +00:00
|
|
|
echo $OUTPUT->heading(get_string('createtoken', 'webservice'));
|
2010-09-24 07:05:39 +00:00
|
|
|
if (!empty($errormsg)) {
|
|
|
|
echo $errormsg;
|
|
|
|
}
|
2010-01-11 08:23:39 +00:00
|
|
|
$mform->display();
|
|
|
|
echo $OUTPUT->footer();
|
|
|
|
die;
|
2010-01-06 09:33:05 +00:00
|
|
|
break;
|
|
|
|
|
2011-06-05 19:34:12 +02:00
|
|
|
case 'delete':
|
2016-06-23 14:36:34 +02:00
|
|
|
$token = $webservicemanager->get_token_by_id_with_details($tokenid);
|
2010-07-27 03:53:55 +00:00
|
|
|
|
2017-07-03 16:21:33 +08:00
|
|
|
if ($token->creatorid != $USER->id) {
|
|
|
|
require_capability("moodle/webservice:managealltokens", context_system::instance());
|
|
|
|
}
|
|
|
|
|
2010-07-27 03:53:55 +00:00
|
|
|
//Delete the token
|
|
|
|
if ($confirm and confirm_sesskey()) {
|
|
|
|
$webservicemanager->delete_user_ws_token($token->id);
|
|
|
|
redirect($tokenlisturl);
|
2010-01-11 08:23:39 +00:00
|
|
|
}
|
2010-07-27 03:53:55 +00:00
|
|
|
|
|
|
|
////OUTPUT: display delete token confirmation box
|
|
|
|
echo $OUTPUT->header();
|
|
|
|
$renderer = $PAGE->get_renderer('core', 'webservice');
|
|
|
|
echo $renderer->admin_delete_token_confirmation($token);
|
|
|
|
echo $OUTPUT->footer();
|
|
|
|
die;
|
2010-01-06 09:33:05 +00:00
|
|
|
break;
|
|
|
|
|
|
|
|
default:
|
2010-07-27 03:53:55 +00:00
|
|
|
//wrong url access
|
|
|
|
redirect($tokenlisturl);
|
2010-01-06 09:33:05 +00:00
|
|
|
break;
|
|
|
|
}
|