Search moodle.org's
Developer Documentation

See Release Notes

  • Bug fixes for general core bugs in 4.2.x will end 22 April 2024 (12 months).
  • Bug fixes for security issues in 4.2.x will end 7 October 2024 (18 months).
  • PHP version: minimum PHP 8.0.0 Note: minimum PHP version has increased since Moodle 4.1. PHP 8.1.x is supported too.

Differences Between: [Versions 310 and 402] [Versions 311 and 402] [Versions 39 and 402] [Versions 400 and 402] [Versions 401 and 402] [Versions 402 and 403]

   1  <?php
   2  // This file is part of Moodle - https://moodle.org/
   3  //
   4  // Moodle is free software: you can redistribute it and/or modify
   5  // it under the terms of the GNU General Public License as published by
   6  // the Free Software Foundation, either version 3 of the License, or
   7  // (at your option) any later version.
   8  //
   9  // Moodle is distributed in the hope that it will be useful,
  10  // but WITHOUT ANY WARRANTY; without even the implied warranty of
  11  // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
  12  // GNU General Public License for more details.
  13  //
  14  // You should have received a copy of the GNU General Public License
  15  // along with Moodle.  If not, see <http://www.gnu.org/licenses/>.
  16  
  17  /**
  18   * Web services / external tokens management UI.
  19   *
  20   * @package     core_webservice
  21   * @category    admin
  22   * @copyright   2009 Jerome Mouneyrac
  23   * @license     http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
  24   */
  25  
  26  require(__DIR__ . '/../../config.php');
  27  require_once($CFG->libdir . '/adminlib.php');
  28  require_once($CFG->dirroot . '/webservice/lib.php');
  29  
  30  $action = optional_param('action', '', PARAM_ALPHANUMEXT);
  31  $tokenid = optional_param('tokenid', '', PARAM_SAFEDIR);
  32  $confirm = optional_param('confirm', 0, PARAM_BOOL);
  33  $ftoken = optional_param('ftoken', '', PARAM_ALPHANUM);
  34  $fusers = optional_param_array('fusers', [], PARAM_INT);
  35  $fservices = optional_param_array('fservices', [], PARAM_INT);
  36  
  37  admin_externalpage_setup('webservicetokens');
  38  
  39  $PAGE->set_primary_active_tab('siteadminnode');
  40  $PAGE->navbar->add(get_string('managetokens', 'webservice'),
  41      new moodle_url('/admin/webservice/tokens.php'));
  42  
  43  if ($action === 'create') {
  44      $PAGE->navbar->add(get_string('createtoken', 'webservice'), $PAGE->url);
  45      $webservicemanager = new webservice();
  46      $mform = new \core_webservice\token_form(null, ['action' => 'create']);
  47      $data = $mform->get_data();
  48  
  49      if ($mform->is_cancelled()) {
  50          redirect($PAGE->url);
  51  
  52      } else if ($data) {
  53          ignore_user_abort(true);
  54  
  55          // Check the user is allowed for the service.
  56          $selectedservice = $webservicemanager->get_external_service_by_id($data->service);
  57  
  58          if ($selectedservice->restrictedusers) {
  59              $restricteduser = $webservicemanager->get_ws_authorised_user($data->service, $data->user);
  60  
  61              if (empty($restricteduser)) {
  62                  $errormsg = $OUTPUT->notification(get_string('usernotallowed', 'webservice', $selectedservice->name));
  63              }
  64          }
  65  
  66          $user = \core_user::get_user($data->user, '*', MUST_EXIST);
  67          \core_user::require_active_user($user);
  68  
  69          // Generate the token.
  70          if (empty($errormsg)) {
  71              \core_external\util::generate_token(
  72                  EXTERNAL_TOKEN_PERMANENT,
  73                  \core_external\util::get_service_by_id($data->service),
  74                  $data->user,
  75                  context_system::instance(),
  76                  $data->validuntil,
  77                  $data->iprestriction
  78              );
  79              redirect($PAGE->url);
  80          }
  81      }
  82  
  83      echo $OUTPUT->header();
  84      echo $OUTPUT->heading(get_string('createtoken', 'webservice'));
  85      if (!empty($errormsg)) {
  86          echo $errormsg;
  87      }
  88      $mform->display();
  89      echo $OUTPUT->footer();
  90      die();
  91  }
  92  
  93  if ($action === 'delete') {
  94      $PAGE->navbar->add(get_string('deletetoken', 'webservice'), $PAGE->url);
  95      $webservicemanager = new webservice();
  96      $token = $webservicemanager->get_token_by_id_with_details($tokenid);
  97  
  98      if ($token->creatorid != $USER->id) {
  99          require_capability('moodle/webservice:managealltokens', context_system::instance());
 100      }
 101  
 102      if ($confirm && confirm_sesskey()) {
 103          $webservicemanager->delete_user_ws_token($token->id);
 104          redirect($PAGE->url);
 105      }
 106  
 107      echo $OUTPUT->header();
 108  
 109      echo $OUTPUT->confirm(
 110          get_string('deletetokenconfirm', 'webservice', [
 111              'user' => $token->firstname . ' ' . $token->lastname,
 112              'service' => $token->name,
 113          ]),
 114          new single_button(new moodle_url('/admin/webservice/tokens.php', [
 115              'tokenid' => $token->id,
 116              'action' => 'delete',
 117              'confirm' => 1,
 118              'sesskey' => sesskey(),
 119          ]), get_string('delete')),
 120          $PAGE->url
 121      );
 122  
 123      echo $OUTPUT->footer();
 124      die();
 125  }
 126  
 127  // Pre-populate the form with the values that come as a part of the URL - typically when using the table_sql control
 128  // links.
 129  $filterdata = (object)[
 130      'token' => $ftoken,
 131      'users' => $fusers,
 132      'services' => $fservices,
 133  ];
 134  
 135  $filter = new \core_webservice\token_filter($PAGE->url, $filterdata);
 136  
 137  $filter->set_data($filterdata);
 138  
 139  if ($filter->is_submitted()) {
 140      $filterdata = $filter->get_data();
 141  
 142      if (isset($filterdata->resetbutton)) {
 143          redirect($PAGE->url);
 144      }
 145  }
 146  
 147  echo $OUTPUT->header();
 148  echo $OUTPUT->heading(get_string('managetokens', 'core_webservice'));
 149  
 150  echo html_writer::div($OUTPUT->render(new single_button(new moodle_url($PAGE->url, ['action' => 'create']),
 151      get_string('createtoken', 'core_webservice'), 'get', single_button::BUTTON_PRIMARY)), 'my-3');
 152  
 153  $filter->display();
 154  
 155  $table = new \core_webservice\token_table('webservicetokens', $filterdata);
 156  
 157  // In order to not lose the filter form values by clicking the table control links, make them part of the table's baseurl.
 158  $baseurl = new moodle_url($PAGE->url, ['ftoken' => $filterdata->token]);
 159  
 160  foreach ($filterdata->users as $i => $userid) {
 161      $baseurl->param("fusers[{$i}]", $userid);
 162  }
 163  
 164  foreach ($filterdata->services as $i => $serviceid) {
 165      $baseurl->param("fservices[{$i}]", $serviceid);
 166  }
 167  
 168  $table->define_baseurl($baseurl);
 169  
 170  $table->attributes['class'] = 'admintable generaltable';
 171  $table->out(30, false);
 172  
 173  echo $OUTPUT->footer();