1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
|
<?php declare(strict_types=1);
/*
** Zabbix
** Copyright (C) 2001-2022 Zabbix SIA
**
** This program is free software; you can redistribute it and/or modify
** it under the terms of the GNU General Public License as published by
** the Free Software Foundation; either version 2 of the License, or
** (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU General Public License for more details.
**
** You should have received a copy of the GNU General Public License
** along with this program; if not, write to the Free Software
** Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
**/
class CControllerTokenEdit extends CController {
protected function init() {
$this->disableSIDValidation();
}
protected function checkInput() {
$fields = [
'tokenid' => 'db token.tokenid',
'name' => 'db token.name',
'description' => 'db token.description',
'userid' => 'db users.userid',
'expires_state' => 'in 0,1',
'expires_at' => 'string',
'status' => 'db token.status|in '.ZBX_AUTH_TOKEN_ENABLED.','.ZBX_AUTH_TOKEN_DISABLED
];
$ret = $this->validateInput($fields);
if (!$ret) {
$this->setResponse(new CControllerResponseFatal());
}
return $ret;
}
protected function checkPermissions() {
if (CWebUser::isGuest()) {
return false;
}
return ($this->checkAccess(CRoleHelper::ACTIONS_MANAGE_API_TOKENS)
&& $this->checkAccess(CRoleHelper::UI_ADMINISTRATION_GENERAL)
);
}
protected function doAction() {
if ($this->hasInput('tokenid')) {
$tokens = API::Token()->get([
'output' => ['tokenid', 'userid', 'name', 'description', 'expires_at', 'status'],
'tokenids' => $this->getInput('tokenid')
]);
if (!$tokens) {
access_deny(ACCESS_DENY_PAGE);
}
$data = $tokens[0];
if ($data['expires_at'] != 0) {
$data['expires_at'] = date(DATE_TIME_FORMAT_SECONDS, (int) $data['expires_at']);
$data['expires_state'] = '1';
}
else {
$data['expires_at'] = null;
$data['expires_state'] = '0';
}
}
else {
$data = [
'tokenid' => 0,
'userid' => 0,
'name' => '',
'description' => '',
'expires_at' => null,
'expires_state' => '1',
'status' => ZBX_AUTH_TOKEN_ENABLED
];
}
$data['ms_user'] = [];
$this->getInputs($data, ['userid', 'name', 'description', 'expires_at', 'expires_state', 'status']);
if ($data['userid'] != 0) {
[$user] = (CWebUser::$data['userid'] != $data['userid'])
? API::User()->get([
'output' => ['username', 'name', 'surname'],
'userids' => $data['userid']
])
: [CWebUser::$data];
$data['ms_user'] = [['id' => $user['userid'], 'name' => getUserFullname($user)]];
}
$response = new CControllerResponseData($data);
$response->setTitle(_('API tokens'));
$this->setResponse($response);
}
}
|