29require
'../../main.inc.php';
37require_once DOL_DOCUMENT_ROOT.
'/core/lib/functions2.lib.php';
38require_once DOL_DOCUMENT_ROOT.
'/core/lib/usergroups.lib.php';
41$langs->loadLangs(array(
'admin',
'users',
'errors'));
46$action =
GETPOST(
'action',
'aZ09');
48if (empty($id) && $action !=
'add' && $action !=
'create') {
53if ($user->socid > 0) {
54 $socid = $user->socid;
56$feature2 = (($socid && $user->hasRight(
"user",
"self",
"write")) ?
'' :
'user');
59$toselect =
GETPOST(
'toselect',
'array');
60$tokenid =
GETPOST(
'tokenid',
'aZ09');
61$confirm =
GETPOST(
'confirm',
'alpha');
62$module =
GETPOST(
'module',
'alpha');
64$cancel =
GETPOST(
'cancel',
'alpha');
65$backtopage =
GETPOST(
'backtopage',
'alpha');
68$sql =
"SELECT oat.rowid as token_id, oat.tokenstring as token, oat.entity, oat.state as rights, oat.datec as date_creation, oat.tms as date_modification";
72$sql .=
" FROM ".MAIN_DB_PREFIX.
"oauth_token as oat";
74 $sql .=
" JOIN ".$db->prefix().
"entity as e ON oat.entity = e.rowid";
76$sql .=
" WHERE oat.rowid = ".((int) $tokenid);
77$sql .=
" AND oat.fk_user = ".((int) $id);
78$sql .=
" AND oat.service = 'dolibarr_rest_api'";
80$resql =
$db->query($sql);
92$token =
$db->fetch_object($resql);
93if (!empty($tokenid) && empty($token)) {
97$entity =
$conf->entity;
99$result =
restrictedArea($user,
'user', $id,
'user&user', $feature2);
102$canreaduser = ($user->admin || ($user->id ==
$id));
103$canedittoken = ($user->admin || (($user->id ==
$id) && $user->hasRight(
"user",
"self",
"write")));
114$parameters = array(
'id' => $socid);
115$reshook = $hookmanager->executeHooks(
'doActions', $parameters, $object, $action);
120if (empty($reshook)) {
121 if (empty($backtopage)) {
122 $backtopage =
'list.php?id='.$object->id;
126 if (!empty($backtopage)) {
127 header(
"Location: ".$backtopage);
133 if ($action ==
'add' && $canedittoken) {
134 $tokenstring =
GETPOST(
'api_key',
'alphanohtml');
137 $useridtoadd = ($user->admin && $userid > 0) ? $userid :
$id;
139 if (empty($tokenstring)) {
140 setEventMessages($langs->trans(
"ErrorFieldRequired", $langs->transnoentitiesnoconv(
"Token")),
null,
'errors');
145 if (empty($useridtoadd)) {
146 setEventMessages($langs->trans(
"ErrorFieldRequired", $langs->transnoentitiesnoconv(
"User")),
null,
'errors');
152 $nbtotalofrecords =
'';
153 $sqlforcount =
'SELECT COUNT(*) as nbtotalofrecords';
154 $sqlforcount .=
" FROM ".MAIN_DB_PREFIX.
"oauth_token as oat";
155 $sqlforcount .=
" WHERE tokenstring = '".$db->escape(
dolEncrypt($tokenstring,
'',
'',
'dolibarr')).
"'";
156 $sqlforcount .=
" AND service = 'dolibarr_rest_api'";
157 $resql =
$db->query($sqlforcount);
159 $objforcount =
$db->fetch_object($resql);
160 $nbtotalofrecords = $objforcount->nbtotalofrecords;
166 if (isset($nbtotalofrecords) && $nbtotalofrecords > 0) {
167 setEventMessages($langs->trans(
"ErrorFieldExist", $langs->transnoentitiesnoconv(
"Token")),
null,
'errors');
175 $sql =
"INSERT INTO ".MAIN_DB_PREFIX.
"oauth_token (service, tokenstring, state, fk_user, entity, datec)";
176 $sql .=
" VALUES ('dolibarr_rest_api', '".$db->escape(
dolEncrypt($tokenstring,
'',
'',
'dolibarr')).
"', 0, ".((int) $useridtoadd).
", ".((int) $entity).
", '".
$db->idate(
dol_now()).
"')";
177 $resql =
$db->query($sql);
192 $insertedtokenid =
$db->last_insert_id(MAIN_DB_PREFIX.
"oauth_token");
195 header(
"Location: " .
dolBuildUrl($_SERVER[
"PHP_SELF"], [
'id' => $useridtoadd,
'tokenid' => $insertedtokenid]));
198 } elseif ($action ==
'confirm_delete' && $confirm ==
'yes' && $canedittoken) {
200 $sql =
"DELETE FROM ".MAIN_DB_PREFIX.
"oauth_token";
201 $sql .=
" WHERE rowid = ".((int) $tokenid);
202 $sql .=
" AND fk_user = ".((int)
$object->id);
203 $sql .=
" AND service = 'dolibarr_rest_api'";
205 $resql =
$db->query($sql);
208 header(
'Location: list.php?id='.((
int)
$object->id));
223 $title = $person_name.
" - ".$langs->trans(
'ApiTokens');
225 $title = $langs->trans(
"NewToken");
229llxHeader(
'', $title, $help_url,
'', 0, 0,
'',
'',
'',
'mod-user page-card_param_ihm');
233if ($action ==
'delete') {
234 $formconfirm = $form->formconfirm($_SERVER[
"PHP_SELF"].
'?id='.
$object->id.
'&tokenid='.$token->token_id, $langs->trans(
'DeleteToken'), $langs->trans(
'ConfirmDeleteToken'),
'confirm_delete',
'', 0, 1);
239if ($action ==
'create') {
241 print
'<form action="'.$_SERVER[
"PHP_SELF"].
'?id='.
$object->id.
'" method="post">';
242 print
'<input type="hidden" name="token" value="'.newToken().
'">';
243 print
'<input type="hidden" name="action" value="add">';
244 print
'<input type="hidden" name="backtopage" value="'.$backtopage.
'">';
248 print
'<table class="border centpercent tableforfieldcreate">';
250 if ($user->admin && empty($id)) {
251 print
'<tr class="field_ref"><td class="titlefieldcreate fieldrequired">'.$langs->trans(
'User').
'</td>';
252 print
'<td class="valuefieldcreate">';
253 print $form->select_dolusers(
'',
'user', 1,
null, 0,
'',
'', (
string)
$object->entity, 0, 0,
'', 0,
'',
'minwidth200 maxwidth500');
256 print
'<tr class="field_ref"><td class="titlefieldcreate fieldrequired">'.$langs->trans(
'User').
'</td><td class="valuefieldcreate">'.($person_name ??
'').
'</td></tr>';
259 print
'<tr><td class="titlefieldcreate fieldrequired">'.$langs->trans(
"Token").
'</td>';
261 print
'<input class="minwidth300 maxwidth400 widthcentpercentminusx" minlength="12" maxlength="128" type="text" id="api_key" name="api_key" value="'.GETPOST(
'api_key',
'alphanohtml').
'" autocomplete="off">';
262 if (!empty(
$conf->use_javascript_ajax)) {
263 print
img_picto($langs->transnoentities(
'Generate'),
'refresh',
'id="generate_api_key" class="linkobject paddingleft"');
270 print
'<div class="center">';
271 print
'<input class="button" name="add" value="'.$langs->trans(
"Create").
'" type="submit">';
272 print
'<input class="button button-cancel" value="'.$langs->trans(
"Cancel").
'" name="cancel" type="submit">';
276} elseif ($id > 0 && !empty($token)) {
277 $arrayofselected = is_array($toselect) ? $toselect : array();
281 $title = $langs->trans(
"User");
287 $linkback =
'<a href="'.DOL_URL_ROOT.
'/user/api_token/list.php?id='.
$id.
'">'.$langs->trans(
"BackToTokenList").
'</a>';
288 $linkback .=
'<a href="'.DOL_URL_ROOT.
'/user/list.php">'.$langs->trans(
"BackToList").
'</a>';
290 $morehtmlref =
'<a href="'.DOL_URL_ROOT.
'/user/vcard.php?id='.
$object->id.
'&output=file&file='.urlencode(
dol_sanitizeFileName(
$object->getFullName($langs).
'.vcf')).
'" class="refid" rel="noopener">';
291 $morehtmlref .=
img_picto($langs->trans(
"Download").
' '.$langs->trans(
"VCard"),
'vcard.png',
'class="valignmiddle marginleftonly paddingrightonly"');
292 $morehtmlref .=
'</a>';
294 $urltovirtualcard =
'/user/virtualcard.php?id='.((int)
$object->id);
295 $morehtmlref .=
dolButtonToOpenUrlInDialogPopup(
'publicvirtualcard', $langs->transnoentitiesnoconv(
"PublicVirtualCardUrl").
' - '.
$object->getFullName($langs),
img_picto($langs->trans(
"PublicVirtualCardUrl"),
'card',
'class="valignmiddle marginleftonly paddingrightonly"'), $urltovirtualcard,
'',
'nohover');
297 dol_banner_tab($object,
'api_token_card', $linkback, $user->admin,
'rowid',
'ref', $morehtmlref);
300 print
'<div class="fichecenter">';
301 print
'<div class="underbanner clearboth"></div>';
302 print
'<table class="border centpercent tableforfield">';
305 print
'<tr><td class="titlefield">'.$langs->trans(
"Login").
'</td>';
307 print
'<td class="error">';
308 print $langs->trans(
"LoginAccountDisableInDolibarr");
314 $addadmin .=
img_picto($langs->trans(
"SuperAdministratorDesc"),
"superadmin",
'class="paddingleft valignmiddle"');
315 } elseif (!empty(
$object->admin)) {
316 $addadmin .=
img_picto($langs->trans(
"AdministratorDesc"),
"admin",
'class="paddingleft valignmiddle"');
324 print
'<tr><td class="titlefield">'.$langs->trans(
"Token").
'</td>';
331 print
'<tr><td class="titlefield">'.$langs->trans(
"DateCreation").
'</td>';
338 print
'<tr><td class="titlefield">'.$langs->trans(
"DateModification").
'</td>';
345 print
'<div class="tabsAction">';
346 print
dolGetButtonAction($langs->trans(
'Delete'),
'',
'delete', $_SERVER[
"PHP_SELF"].
'?id='.
$object->id.
'&tokenid='.$token->token_id.
'&action=delete&token='.
newToken(),
'', $canedittoken);
355 print
'<!-- Rights section -->'.
"\n";
358 print
info_admin($langs->trans(
"WarningOnlyPermissionOfActivatedModules"));
361 print
'TODO If no ACL given, show message to say permissions are the one of user. If ACL set, show ACL active (common to user permission)and ACL no more active (not own by user)';
365 include_once DOL_DOCUMENT_ROOT.
'/core/lib/security2.lib.php';
$id
Support class for third parties, contacts, members, users or resources.
if(! $sortfield) if(! $sortorder) $object
llxFooter($comment='', $zone='private', $disabledoutputofmessages=0)
Empty footer.
if(!defined('NOREQUIRESOC')) if(!defined( 'NOREQUIRETRAN')) if(!defined('NOTOKENRENEWAL')) if(!defined( 'NOREQUIREMENU')) if(!defined('NOREQUIREHTML')) if(!defined( 'NOREQUIREAJAX')) llxHeader($head='', $title='', $help_url='', $target='', $disablejs=0, $disablehead=0, $arrayofjs='', $arrayofcss='', $morequerystring='', $morecssonbody='', $replacemainareaby='', $disablenofollow=0, $disablenoindex=0)
Empty header.
Class to manage Dolibarr users.
dol_now($mode='gmt')
Return date for now.
setEventMessages($mesg, $mesgs, $style='mesgs', $messagekey='', $noduplicate=0, $attop=0)
Set event messages in dol_events session object.
showValueWithClipboardCPButton($valuetocopy, $showonlyonhover=1, $texttoshow='')
Create a button to copy $valuetocopy in the clipboard (for copy and paste feature).
img_picto($titlealt, $picto, $moreatt='', $pictoisfullpath=0, $srconly=0, $notitle=0, $alt='', $morecss='', $marginleftonlyshort=2, $allowothertags=array())
Show picto whatever it's its name (generic function)
dol_get_fiche_head($links=array(), $active='', $title='', $notab=0, $picto='', $pictoisfullpath=0, $morehtmlright='', $morecss='', $limittoshow=0, $moretabssuffix='', $dragdropfile=0, $morecssdiv='')
Show tabs of a record.
dolButtonToOpenUrlInDialogPopup($name, $label, $buttonstring, $url, $disabled='', $morecss='classlink button bordertransp', $jsonopen='', $jsonclose='', $accesskey='')
Return HTML code to output a button to open a dialog popup box.
dolBuildUrl($url, $params=[], $addtoken=false, $anchor='')
Return path of url.
dol_get_fiche_end($notab=0)
Return tab footer of a card.
dol_sanitizeFileName($str, $newstr='_', $unaccent=1, $includequotes=0, $allowdash=0)
Clean a string to use it as a file name.
newToken()
Return the value of token currently saved into session with name 'newtoken'.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
dolGetButtonAction($label, $text='', $actionType='default', $url='', $id='', $userRight=1, $params=array())
Function dolGetButtonAction.
GETPOSTINT($paramname, $method=0, $nodefault=0)
Return the value of a $_GET or $_POST supervariable, converted into integer.
dol_print_date($time, $format='', $tzoutput='auto', $outputlangs=null, $encodetooutput=false, $decorate=0)
Output date in a string format according to outputlangs (or langs if not defined).
dol_print_error($db=null, $error='', $errors=null)
Displays error message system with all the information to facilitate the diagnosis and the escalation...
load_fiche_titre($title, $morehtmlright='', $picto='generic', $pictoisfullpath=0, $id='', $morecssontable='', $morehtmlcenter='', $morecssonpicto='widthpictotitle')
Load a title with picto.
isModEnabled($module)
Is Dolibarr module enabled.
info_admin($text, $infoonimgalt=0, $nodiv=0, $admin='1', $morecss='hideonsmartphone', $textfordropdown='', $picto='', $textonpictotooltip='', $cssfordropdown='info_admin')
Show information in HTML for admin users or standard users.
dolJSToSetRandomPassword($htmlname, $htmlnameofbutton='generate_token', $generic=1)
Output javascript to autoset a generated password using default module into a HTML element.
restrictedArea(User $user, $features, $object=0, $tableandshare='', $feature2='', $dbt_keyfield='fk_soc', $dbt_select='rowid', $isdraft=0, $nodie=0, $mode='')
Check permissions of a user to show a page and an object.
accessforbidden($message='', $printheader=1, $printfooter=1, $showonlymessage=0, $params=null)
Show a message to say access is forbidden and stop program.
dolDecrypt($chain, $key='', $patterntotest='')
Decode a string with a symmetric encryption.
dolEncrypt($chain, $key='', $ciphering='', $forceseed='', $obfuscationmode='dolcrypt')
Encode a string with a symmetric encryption.
user_prepare_head(User $object)
Prepare array with list of tabs.