|
dolibarr 25.0.0-alpha
|
Set of function used for dolibarr security (not common functions). More...
Go to the source code of this file.
Functions | |
| dol_getwebuser ($mode) | |
| Return user/group account of web server. | |
| checkLoginPassEntity ($usertotest, $passwordtotest, $entitytotest, $authmode, $context='') | |
| Return a login if login/pass was successful. | |
| if(!function_exists( 'dol_loginfunction')) | makesalt ($type=CRYPT_SALT_LENGTH) |
| Initialise the salt for the crypt function. | |
| encodedecode_dbpassconf ($level=0) | |
| Encode or decode database password in config file. | |
| isPasswordGenerationNoneForbidden () | |
| Return if the 'none' password generation model (the one that applies no rule at all) is forbidden on this installation. | |
| getPasswordPatternMinLength () | |
| Return the lowest value allowed for the minimum length (first field of USER_PASSWORD_PATTERN) of the 'Perso' password generation model. | |
| getRandomPassword ($generic=false, $replaceambiguouschars=null, $length=32) | |
| Return a generated password using default module. | |
| dolJSToSetRandomPassword ($htmlname, $htmlnameofbutton='generate_token', $generic=1) | |
| Output javascript to autoset a generated password using default module into a HTML element. | |
| showEyeForField ($htmlname, $htmlnameofinput) | |
| Output the eye picto to show/hide a password HTML field. | |
Set of function used for dolibarr security (not common functions).
Warning, this file must not depends on other library files, except function.lib.php because it is used at low code level.
Definition in file security2.lib.php.
| checkLoginPassEntity | ( | $usertotest, | |
| $passwordtotest, | |||
| $entitytotest, | |||
| $authmode, | |||
| $context = '' ) |
Return a login if login/pass was successful.
| string | $usertotest | Login value to test |
| string | $passwordtotest | Password value to test |
| int | string | $entitytotest | Instance of data we must check |
| string[] | $authmode | Array list of selected authentication mode array('http', 'dolibarr', 'xxx'...) |
| 'api'|'dav'|'ws'|'' | $context Context checkLoginPassEntity was created for ('api', 'dav', 'ws', '') |
Show Dolibarr default login page. Part of this code is also duplicated into main.inc.php\top_htmlhead
| Translate | $langs | Lang object (must be initialized by a new). |
| Conf | $conf | Conf object |
| Societe | $mysoc | Company object |
Definition at line 59 of file security2.lib.php.
References $conf, $context, dol_buildpath(), dol_osencode(), and dol_syslog().
Referenced by check_authentication(), and Login\index().
| dol_getwebuser | ( | $mode | ) |
Return user/group account of web server.
| string | $mode | 'user' or 'group' |
Definition at line 37 of file security2.lib.php.
| dolJSToSetRandomPassword | ( | $htmlname, | |
| $htmlnameofbutton = 'generate_token', | |||
| $generic = 1 ) |
Output javascript to autoset a generated password using default module into a HTML element.
| string | $htmlname | HTML name of element to insert key into |
| string | $htmlnameofbutton | HTML name of button |
| int | $generic | 1=Return a generic pass, 0=Return a pass following setup rules |
Definition at line 612 of file security2.lib.php.
References $conf, and dol_escape_js().
Referenced by FormSetupItem\generateInputFieldSecureKey().
| encodedecode_dbpassconf | ( | $level = 0 | ) |
Encode or decode database password in config file.
| int | $level | Encode level: 0 no encoding, 1 encoding |
Definition at line 372 of file security2.lib.php.
References conf(), dol_decode(), dol_syslog(), dolDecrypt(), and dolEncrypt().
| getPasswordPatternMinLength | ( | ) |
Return the lowest value allowed for the minimum length (first field of USER_PASSWORD_PATTERN) of the 'Perso' password generation model.
When the 'none' model is forbidden on this installation (see isPasswordGenerationNoneForbidden()), the Perso model must not be tuned down to a weak value either, so a floor of 10 characters is enforced in the admin screen, when saving the pattern, and at generation/validation time.
Definition at line 497 of file security2.lib.php.
References isPasswordGenerationNoneForbidden().
Referenced by modGeneratePassPerso\__construct().
| getRandomPassword | ( | $generic = false, | |
| $replaceambiguouschars = null, | |||
| $length = 32 ) |
Return a generated password using default module.
| bool | $generic | true=Create a generic key (32 chars/numbers), false=Create a password using the configured password generation module. |
| ?array<string> | $replaceambiguouschars Discard ambiguous characters. For example: array('I'). | |
| int | $length | Length of random string (Used only if $generic is true) |
Definition at line 512 of file security2.lib.php.
References $conf, dol_syslog(), getDolGlobalString(), and ModeleGenPassword\loadAndInstantiate().
Referenced by modEventOrganization\__construct(), modPropale\__construct(), addFileIntoDatabaseIndex(), ActionsAdherentCardCommon\assign_values(), ActionsContactCardCommon\assign_values(), CommonObject\getLastMainDocLink(), CommonObject\indexFile(), openid_connect_create_user(), Documents\post(), Adherent\setPassword(), and User\setPassword().
| isPasswordGenerationNoneForbidden | ( | ) |
Return if the 'none' password generation model (the one that applies no rule at all) is forbidden on this installation.
It is locked by the conf.php variable $dolibarr_main_restrict_password_generation_none (exposed as $conf->file->restrict_password_generation_none), which can only be changed by editing the config file on the server. When forbidden, the model is hidden from the admin screen, cannot be selected, and any value already set to 'none' falls back to the 'standard' model at generation/validation time.
Definition at line 481 of file security2.lib.php.
References $conf.
Referenced by getPasswordPatternMinLength(), modGeneratePassNone\isEnabled(), and ModeleGenPassword\loadAndInstantiate().
| if(!function_exists('dol_loginfunction')) makesalt | ( | $type = CRYPT_SALT_LENGTH | ) |
Initialise the salt for the crypt function.
| int | $type | 2 =>Return a salt for DES encryption 12=>Return a salt for MD5 encryption Undefined=>Return a salt for default encryption |
Definition at line 335 of file security2.lib.php.
References dol_strlen(), and dol_syslog().
Referenced by MailmanSpip\add_to_spip().
| showEyeForField | ( | $htmlname, | |
| $htmlnameofinput ) |
Output the eye picto to show/hide a password HTML field.
| string | $htmlname | HTML name of element to insert key into |
| string | $htmlnameofinput | HTML id of input field |
Definition at line 651 of file security2.lib.php.