|
dolibarr 25.0.0-alpha
|
Class AiWriteConfirmation. More...

Public Member Functions | |
| __construct ($db) | |
| Constructor. | |
| issue ($user, $toolName, array $args, $preview) | |
| Issue a state for a pending write. | |
| consume ($user, $toolName, array $args, $state) | |
| Validate a state presented on the confirming call, and consume it. | |
| purge ($keepdays=30) | |
| Remove expired states that were never confirmed. | |
Public Attributes | |
| const | DEFAULT_TTL_MINUTES = 10 |
| Minutes a state stays valid, long enough to read a preview. | |
Private Member Functions | |
| signingSecret () | |
| Secret used to sign states. | |
| stateHash ($state, $secret) | |
| Keyed hash of a state, so the database never holds the state itself. | |
| argsHash (array $args) | |
| Stable hash of the arguments a state was issued for. | |
| ksortRecursive (array &$arr) | |
| Sort an array by key at every level, so argument order cannot change the hash. | |
Class AiWriteConfirmation.
A write tool does not execute on the first call: it answers with a preview and an opaque requestState, and executes only when the caller comes back with that state. The state is signed with an instance secret, expires, is single use and is bound to the arguments it was issued for, so a caller can neither forge a confirmation nor confirm one set of arguments and send another.
Definition at line 33 of file writeconfirmation.class.php.
| AiWriteConfirmation::__construct | ( | $db | ) |
Constructor.
Definition at line 55 of file writeconfirmation.class.php.
|
private |
Stable hash of the arguments a state was issued for.
| array<string,mixed> | $args Tool arguments. |
Definition at line 249 of file writeconfirmation.class.php.
References dol_hash(), and ksortRecursive().
Referenced by issue().
| AiWriteConfirmation::consume | ( | $user, | |
| $toolName, | |||
| array | $args, | ||
| $state ) |
Validate a state presented on the confirming call, and consume it.
Everything is checked before the write runs: the signature, that the state belongs to this user, this tool and these arguments, that it has not expired and that it was never used before.
| User | $user | User confirming. |
| string | $toolName | Tool being confirmed. |
| array<string,mixed> | $args Arguments presented now. | |
| string | $state | State the caller echoed back. |
Definition at line 128 of file writeconfirmation.class.php.
References $conf, dol_now(), dol_syslog(), signingSecret(), and stateHash().
| AiWriteConfirmation::issue | ( | $user, | |
| $toolName, | |||
| array | $args, | ||
| $preview ) |
Issue a state for a pending write.
| User | $user | User asking for the write. |
| string | $toolName | Tool that would run. |
| array<string,mixed> | $args Arguments it would run with. | |
| string | $preview | Human readable description of what would be written. |
Definition at line 69 of file writeconfirmation.class.php.
References $conf, argsHash(), DEFAULT_TTL_MINUTES, dol_hash(), dol_now(), dol_syslog(), dol_trunc(), getDolGlobalInt(), getUserRemoteIP(), purge(), signingSecret(), and stateHash().
|
private |
Sort an array by key at every level, so argument order cannot change the hash.
| array<string,mixed> | $arr Array to sort in place. |
Definition at line 264 of file writeconfirmation.class.php.
References ksortRecursive().
Referenced by argsHash(), and ksortRecursive().
| AiWriteConfirmation::purge | ( | $keepdays = 30 | ) |
Remove expired states that were never confirmed.
| int | $keepdays | Days of history to keep for audit. |
Definition at line 196 of file writeconfirmation.class.php.
References dol_now().
Referenced by issue().
|
private |
Secret used to sign states.
Derived from the instance id Dolibarr already uses for session prefixes, so there is nothing to generate and the value stays in conf.php rather than in the database. Empty when the installation predates it, in which case no state is issued at all.
Definition at line 219 of file writeconfirmation.class.php.
References dol_hash().
|
private |
Keyed hash of a state, so the database never holds the state itself.
| string | $state | State handed to the caller. |
| string | $secret | Instance secret. |
Definition at line 238 of file writeconfirmation.class.php.
References dol_hash().