From 794c33e57b92e8f639e6927e86744da4bb6f8dcb Mon Sep 17 00:00:00 2001 From: laf Date: Mon, 6 Oct 2014 17:19:04 +0100 Subject: [PATCH] Updated create token to auto-generate token --- html/forms/token-item-create.inc.php | 44 ++++++++++++++++++++++++++++ html/forms/token-item-remove.inc.php | 36 +++++++++++++++++++++++ html/pages/api-access.inc.php | 6 ++-- 3 files changed, 84 insertions(+), 2 deletions(-) create mode 100644 html/forms/token-item-create.inc.php create mode 100644 html/forms/token-item-remove.inc.php diff --git a/html/forms/token-item-create.inc.php b/html/forms/token-item-create.inc.php new file mode 100644 index 000000000..dc6da67c3 --- /dev/null +++ b/html/forms/token-item-create.inc.php @@ -0,0 +1,44 @@ + + * + * This program is free software: you can redistribute it and/or modify it + * under the terms of the GNU General Public License as published by the + * Free Software Foundation, either version 3 of the License, or (at your + * option) any later version. Please see LICENSE.txt at the top level of + * the source code distribution for details. + */ + +if(!is_numeric($_POST['user_id']) || !isset($_POST['token'])) +{ + echo('ERROR: error with data, please ensure a valid user and token have been specified.'); + exit; +} +elseif(strlen($_POST['token']) > 32) +{ + echo('ERROR: The token is more than 32 characters'); + exit; +} +elseif(strlen($_POST['token']) < 16) +{ + echo('ERROR: The token is less than 16 characters'); + exit; +} +else +{ + $create = dbInsert(array('user_id' => $_POST['user_id'], 'token_hash' => $_POST['token'], 'description' => $_POST['description']), 'api_tokens'); + if($create > '0') + { + echo('API token has been created'); + $_SESSION['api_token'] = TRUE; + exit; + } + else + { + echo('ERROR: An error occurred creating the API token'); + exit; + } +} diff --git a/html/forms/token-item-remove.inc.php b/html/forms/token-item-remove.inc.php new file mode 100644 index 000000000..1b4522f39 --- /dev/null +++ b/html/forms/token-item-remove.inc.php @@ -0,0 +1,36 @@ + + * + * This program is free software: you can redistribute it and/or modify it + * under the terms of the GNU General Public License as published by the + * Free Software Foundation, either version 3 of the License, or (at your + * option) any later version. Please see LICENSE.txt at the top level of + * the source code distribution for details. + */ + +if(!is_numeric($_POST['token_id'])) +{ + echo('error with data'); + exit; +} +else +{ + if($_POST['confirm'] == 'yes') + { + $delete = dbDelete('api_tokens', '`id` = ?', array($_POST['token_id'])); + if($delete > '0') + { + echo('API token has been removed'); + exit; + } + else + { + echo('An error occurred removing the API token'); + exit; + } + } +} diff --git a/html/pages/api-access.inc.php b/html/pages/api-access.inc.php index c5d3504c8..adfb69e3b 100644 --- a/html/pages/api-access.inc.php +++ b/html/pages/api-access.inc.php @@ -14,6 +14,9 @@ if ($_SESSION['userlevel'] == '10') { +if(empty($_POST['token'])) { + $_POST['token'] = bin2hex(openssl_random_pseudo_bytes(16)); +} ?>