29require
'../../main.inc.php';
37require_once DOL_DOCUMENT_ROOT.
'/core/lib/functions2.lib.php';
38require_once DOL_DOCUMENT_ROOT.
'/core/lib/usergroups.lib.php';
41$langs->loadLangs(array(
'admin',
'users',
'errors'));
46$action =
GETPOST(
'action',
'aZ09');
48if (empty($id) && $action !=
'add' && $action !=
'create') {
53if ($user->socid > 0) {
54 $socid = $user->socid;
56$feature2 = (($socid && $user->hasRight(
"user",
"self",
"write")) ?
'' :
'user');
59$toselect =
GETPOST(
'toselect',
'array');
60$tokenid =
GETPOST(
'tokenid',
'aZ09');
61$confirm =
GETPOST(
'confirm',
'alpha');
64$cancel =
GETPOST(
'cancel',
'alpha');
65$backtopage =
GETPOST(
'backtopage',
'alpha');
68$sql =
"SELECT oat.rowid as token_id, oat.token, oat.entity, oat.state as rights, oat.datec as date_creation, oat.tms as date_modification";
72$sql .=
" FROM ".MAIN_DB_PREFIX.
"oauth_token as oat";
74 $sql .=
" JOIN ".$db->prefix().
"entity as e ON oat.entity = e.rowid";
76$sql .=
" WHERE oat.rowid = ".((int) $tokenid);
77$sql .=
" AND oat.fk_user = ".((int) $id);
78$sql .=
" AND oat.service = 'dolibarr_rest_api'";
80$resql = $db->query($sql);
92$token = $db->fetch_object($resql);
93if (!empty($tokenid) && empty($token)) {
97$entity =
$conf->entity;
99$result =
restrictedArea($user,
'user', $id,
'user&user', $feature2);
102$canreaduser = ($user->admin || ($user->id ==
$id));
103$canedittoken = ($user->admin || (($user->id ==
$id) && $user->hasRight(
"user",
"self",
"write")));
114$parameters = array(
'id' => $socid);
115$reshook = $hookmanager->executeHooks(
'doActions', $parameters, $object, $action);
117 setEventMessages($hookmanager->error, $hookmanager->errors,
'errors');
120if (empty($reshook)) {
121 if (empty($backtopage)) {
122 $backtopage =
'list.php?id='.$object->id;
126 if (!empty($backtopage)) {
127 header(
"Location: ".$backtopage);
133 if ($action ==
'add' && $canedittoken) {
134 $tokenstring =
GETPOST(
'api_key',
'alphanohtml');
137 $useridtoadd = ($user->admin && $userid > 0) ? $userid :
$id;
139 if (empty($tokenstring)) {
140 setEventMessages($langs->trans(
"ErrorFieldRequired", $langs->transnoentitiesnoconv(
"Token")),
null,
'errors');
145 if (empty($useridtoadd)) {
146 setEventMessages($langs->trans(
"ErrorFieldRequired", $langs->transnoentitiesnoconv(
"User")),
null,
'errors');
152 $nbtotalofrecords =
'';
153 $sqlforcount =
'SELECT COUNT(*) as nbtotalofrecords';
154 $sqlforcount .=
" FROM ".MAIN_DB_PREFIX.
"oauth_token as oat";
155 $sqlforcount .=
" WHERE token = '".$db->escape(
dolEncrypt($tokenstring,
'',
'',
'dolibarr')).
"'";
156 $sqlforcount .=
" AND service = 'dolibarr_rest_api'";
157 $resql = $db->query($sqlforcount);
159 $objforcount = $db->fetch_object($resql);
160 $nbtotalofrecords = $objforcount->nbtotalofrecords;
162 dol_print_error($db);
166 if (isset($nbtotalofrecords) && $nbtotalofrecords > 0) {
167 setEventMessages($langs->trans(
"ErrorFieldExist", $langs->transnoentitiesnoconv(
"Token")),
null,
'errors');
175 $sql =
"INSERT INTO ".MAIN_DB_PREFIX.
"oauth_token (service, token, state, fk_user, entity, datec)";
176 $sql .=
" VALUES ('dolibarr_rest_api', '".$db->escape(
dolEncrypt($tokenstring,
'',
'',
'dolibarr')).
"', 0, ".((int) $useridtoadd).
", ".((int) $entity).
", '".$db->idate(
dol_now()).
"')";
177 $resql = $db->query($sql);
189 dol_print_error($db);
192 $insertedtokenid = $db->last_insert_id(MAIN_DB_PREFIX.
"oauth_token");
195 header(
"Location: " .
dolBuildUrl($_SERVER[
"PHP_SELF"], [
'id' => $useridtoadd,
'tokenid' => $insertedtokenid]));
198 } elseif ($action ==
'confirm_delete' && $confirm ==
'yes' && $canedittoken) {
200 $sql =
"DELETE FROM ".MAIN_DB_PREFIX.
"oauth_token";
201 $sql .=
" WHERE rowid = ".((int) $tokenid);
202 $sql .=
" AND fk_user = ".((int)
$object->id);
203 $sql .=
" AND service = 'dolibarr_rest_api'";
205 $resql = $db->query($sql);
208 header(
'Location: list.php?id='.((
int)
$object->id));
211 dol_print_error($db);
223 $title = $person_name.
" - ".$langs->trans(
'ApiTokens');
225 $title = $langs->trans(
"NewToken");
229llxHeader(
'', $title, $help_url,
'', 0, 0,
'',
'',
'',
'mod-user page-card_param_ihm');
233if ($action ==
'delete') {
234 $formconfirm = $form->formconfirm($_SERVER[
"PHP_SELF"].
'?id='.
$object->id.
'&tokenid='.$token->token_id, $langs->trans(
'DeleteToken'), $langs->trans(
'ConfirmDeleteToken'),
'confirm_delete',
'', 0, 1);
239if ($action ==
'create') {
241 print
'<form action="'.$_SERVER[
"PHP_SELF"].
'?id='.
$object->id.
'" method="post">';
242 print
'<input type="hidden" name="token" value="'.newToken().
'">';
243 print
'<input type="hidden" name="action" value="add">';
244 print
'<input type="hidden" name="backtopage" value="'.$backtopage.
'">';
248 print
'<table class="border centpercent tableforfieldcreate">';
250 if ($user->admin && empty($id)) {
251 print
'<tr class="field_ref"><td class="titlefieldcreate fieldrequired">'.$langs->trans(
'User').
'</td>';
252 print
'<td class="valuefieldcreate">';
253 print $form->select_dolusers(
'',
'user', 1,
null, 0,
'',
'', (
string)
$object->entity, 0, 0,
'', 0,
'',
'minwidth200 maxwidth500');
256 print
'<tr class="field_ref"><td class="titlefieldcreate fieldrequired">'.$langs->trans(
'User').
'</td><td class="valuefieldcreate">'.($person_name ??
'').
'</td></tr>';
259 print
'<tr><td class="titlefieldcreate fieldrequired">'.$langs->trans(
"Token").
'</td>';
261 print
'<input class="minwidth300 maxwidth400 widthcentpercentminusx" minlength="12" maxlength="128" type="text" id="api_key" name="api_key" value="'.GETPOST(
'api_key',
'alphanohtml').
'" autocomplete="off">';
262 if (!empty(
$conf->use_javascript_ajax)) {
263 print img_picto($langs->transnoentities(
'Generate'),
'refresh',
'id="generate_api_key" class="linkobject paddingleft"');
270 print
'<div class="center">';
271 print
'<input class="button" name="add" value="'.$langs->trans(
"Create").
'" type="submit">';
272 print
'<input class="button button-cancel" value="'.$langs->trans(
"Cancel").
'" name="cancel" type="submit">';
276} elseif ($id > 0 && !empty($token)) {
277 $arrayofselected = is_array($toselect) ? $toselect : array();
281 $title = $langs->trans(
"User");
287 $linkback =
'<a href="'.DOL_URL_ROOT.
'/user/api_token/list.php?id='.
$id.
'">'.$langs->trans(
"BackToTokenList").
'</a>';
288 $linkback .=
'<a href="'.DOL_URL_ROOT.
'/user/list.php">'.$langs->trans(
"BackToList").
'</a>';
290 $morehtmlref =
'<a href="'.DOL_URL_ROOT.
'/user/vcard.php?id='.
$object->id.
'&output=file&file='.urlencode(
dol_sanitizeFileName(
$object->getFullName($langs).
'.vcf')).
'" class="refid" rel="noopener">';
291 $morehtmlref .= img_picto($langs->trans(
"Download").
' '.$langs->trans(
"VCard"),
'vcard.png',
'class="valignmiddle marginleftonly paddingrightonly"');
292 $morehtmlref .=
'</a>';
294 $urltovirtualcard =
'/user/virtualcard.php?id='.((int)
$object->id);
295 $morehtmlref .=
dolButtonToOpenUrlInDialogPopup(
'publicvirtualcard', $langs->transnoentitiesnoconv(
"PublicVirtualCardUrl").
' - '.
$object->getFullName($langs), img_picto($langs->trans(
"PublicVirtualCardUrl"),
'card',
'class="valignmiddle marginleftonly paddingrightonly"'), $urltovirtualcard,
'',
'nohover');
297 dol_banner_tab($object,
'api_token_card', $linkback, $user->admin,
'rowid',
'ref', $morehtmlref);
300 print
'<div class="fichecenter">';
301 print
'<div class="underbanner clearboth"></div>';
302 print
'<table class="border centpercent tableforfield">';
305 print
'<tr><td class="titlefield">'.$langs->trans(
"Login").
'</td>';
307 print
'<td class="error">';
308 print $langs->trans(
"LoginAccountDisableInDolibarr");
314 $addadmin .= img_picto($langs->trans(
"SuperAdministratorDesc"),
"superadmin",
'class="paddingleft valignmiddle"');
315 } elseif (!empty(
$object->admin)) {
316 $addadmin .= img_picto($langs->trans(
"AdministratorDesc"),
"admin",
'class="paddingleft valignmiddle"');
324 print
'<tr><td class="titlefield">'.$langs->trans(
"Token").
'</td>';
331 print
'<tr><td class="titlefield">'.$langs->trans(
"DateCreation").
'</td>';
333 print
dol_print_date($db->jdate($token->date_creation),
'dayhour');
338 print
'<tr><td class="titlefield">'.$langs->trans(
"DateModification").
'</td>';
340 print
dol_print_date($db->jdate($token->date_modification),
'dayhour');
345 print
'<div class="tabsAction">';
346 print dolGetButtonAction($langs->trans(
'Delete'), $langs->trans(
'Delete'),
'delete',
dolBuildUrl($_SERVER[
"PHP_SELF"], [
'id' =>
$object->id,
'tokenid' => $token->token_id,
'action' =>
'delete'],
true),
'', $canedittoken, array(
'attr' => array(
'class' =>
'reposition'))).
"\n";
355 print
'<!-- Rights section -->'.
"\n";
358 print
info_admin($langs->trans(
"WarningOnlyPermissionOfActivatedModules"));
361 print
'TODO If no ACL given, show message to say permissions are the one of user. If ACL set, show ACL active (common to user permission)and ACL no more active (not own by user)';
365 include_once DOL_DOCUMENT_ROOT.
'/core/lib/security2.lib.php';
$id
Support class for third parties, contacts, members, users or resources.
if(! $sortfield) if(! $sortorder) $object
llxFooter($comment='', $zone='private', $disabledoutputofmessages=0)
Empty footer.
if(!defined('NOREQUIRESOC')) if(!defined( 'NOREQUIRETRAN')) if(!defined('NOTOKENRENEWAL')) if(!defined( 'NOREQUIREMENU')) if(!defined('NOREQUIREHTML')) if(!defined( 'NOREQUIREAJAX')) llxHeader($head='', $title='', $help_url='', $target='', $disablejs=0, $disablehead=0, $arrayofjs='', $arrayofcss='', $morequerystring='', $morecssonbody='', $replacemainareaby='', $disablenofollow=0, $disablenoindex=0)
Empty header.
Class to manage Dolibarr users.
if(! $sortfield) if(! $sortorder) $module
dol_now($mode='gmt')
Return date for now.
dolBuildUrl($url, $params=[], $addtoken=false, $anchor='')
Return path of url.
dol_sanitizeFileName($str, $newstr='_', $unaccent=1, $includequotes=0, $allowdash=0)
Clean a string to use it as a file name.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
GETPOSTINT($paramname, $method=0, $nodefault=0)
Return the value of a $_GET or $_POST supervariable, converted into integer.
dol_print_date($time, $format='', $tzoutput='auto', $outputlangs=null, $encodetooutput=false, $decorate=0)
Output date in a string format according to outputlangs (or langs if not defined).
isModEnabled($module)
Is Dolibarr module enabled.
showValueWithClipboardCPButton($valuetocopy, $showonlyonhover=1, $texttoshow='')
Create a button to copy $valuetocopy in the clipboard (for copy and paste feature).
dol_get_fiche_head($links=array(), $active='', $title='', $notab=0, $picto='', $pictoisfullpath=0, $morehtmlright='', $morecss='', $limittoshow=0, $moretabssuffix='', $dragdropfile=0, $morecssdiv='')
Show tabs of a record.
dolButtonToOpenUrlInDialogPopup($name, $label, $buttonstring, $url, $disabled='', $morecss='classlink button bordertransp', $jsonopen='', $jsonclose='', $accesskey='')
Return HTML code to output a button to open a dialog popup box.
dol_get_fiche_end($notab=0)
Return tab footer of a card.
load_fiche_titre($title, $morehtmlright='', $picto='generic', $pictoisfullpath=0, $id='', $morecssontable='', $morehtmlcenter='', $morecssonpicto='widthpictotitle')
Load a title with picto.
info_admin($text, $infoonimgalt=0, $nodiv=0, $admin='1', $morecss='hideonsmartphone', $textfordropdown='', $picto='', $textonpictotooltip='', $cssfordropdown='info_admin')
Show information in HTML for admin users or standard users.
dolJSToSetRandomPassword($htmlname, $htmlnameofbutton='generate_token', $generic=1)
Output javascript to autoset a generated password using default module into a HTML element.
restrictedArea(User $user, $features, $object=0, $tableandshare='', $feature2='', $dbt_keyfield='fk_soc', $dbt_select='rowid', $isdraft=0, $nodie=0, $mode='')
Check permissions of a user to show a page and an object.
accessforbidden($message='', $printheader=1, $printfooter=1, $showonlymessage=0, $params=null)
Show a message to say access is forbidden and stop program.
dolDecrypt($chain, $key='', $patterntotest='')
Decode a string with a symmetric encryption.
dolEncrypt($chain, $key='', $ciphering='', $forceseed='', $obfuscationmode='dolcrypt')
Encode a string with a symmetric encryption.
user_prepare_head(User $object)
Prepare array with list of tabs.