forked from Koha-Community/Koha
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathapikeys.pl
executable file
·116 lines (96 loc) · 3.44 KB
/
apikeys.pl
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
#!/usr/bin/perl
# This file is part of Koha.
#
# Copyright 2015 BibLibre
#
# Koha is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 3 of the License, or
# (at your option) any later version.
#
# Koha is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with Koha; if not, see <http://www.gnu.org/licenses>.
use Modern::Perl;
use CGI;
use C4::Auth qw( get_template_and_user );
use C4::Output qw( output_and_exit output_html_with_http_headers );
use Koha::ApiKeys;
use Koha::Patrons;
my $cgi = CGI->new;
my ( $template, $loggedinuser, $cookie ) = get_template_and_user(
{ template_name => 'members/apikeys.tt',
query => $cgi,
type => 'intranet',
flagsrequired => { borrowers => 'edit_borrowers' },
}
);
my $patron;
my $patron_id = $cgi->param('patron_id') // '';
my $api_key = $cgi->param('key') // '';
$patron = Koha::Patrons->find($patron_id) if $patron_id;
if ( not defined $patron or
not C4::Context->preference('RESTOAuth2ClientCredentials') ) {
# patron_id invalid -> exit
print $cgi->redirect("/cgi-bin/koha/errors/404.pl"); # escape early
exit;
}
if( $patron_id != $loggedinuser && !C4::Context->IsSuperLibrarian() ) {
# not the owner of the account viewing/editing own API keys, nor superlibrarian -> exit
print $cgi->redirect("/cgi-bin/koha/errors/403.pl"); # escape early
exit;
}
my $op = $cgi->param('op') // '';
if ($op) {
if ( $op eq 'cud-generate' ) {
my $description = $cgi->param('description') // '';
my $api_key = Koha::ApiKey->new(
{ patron_id => $patron_id,
description => $description
}
);
$api_key->store;
$template->param(
fresh_api_key => $api_key,
api_keys => Koha::ApiKeys->search({ patron_id => $patron_id }),
);
}
if ( $op eq 'cud-delete' ) {
my $api_key_id = $cgi->param('key');
my $key = Koha::ApiKeys->find({ patron_id => $patron_id, client_id => $api_key_id });
if ($key) {
$key->delete;
}
print $cgi->redirect( '/cgi-bin/koha/members/apikeys.pl?patron_id=' . $patron_id );
exit;
}
if ( $op eq 'cud-revoke' ) {
my $api_key_id = $cgi->param('key');
my $key = Koha::ApiKeys->find({ patron_id => $patron_id, client_id => $api_key_id });
if ($key) {
$key->active(0);
$key->store;
}
print $cgi->redirect( '/cgi-bin/koha/members/apikeys.pl?patron_id=' . $patron_id );
exit;
}
if ( $op eq 'cud-activate' ) {
my $api_key_id = $cgi->param('key');
my $key = Koha::ApiKeys->find({ patron_id => $patron_id, client_id => $api_key_id });
if ($key) {
$key->active(1);
$key->store;
}
print $cgi->redirect( '/cgi-bin/koha/members/apikeys.pl?patron_id=' . $patron_id );
exit;
}
}
$template->param(
api_keys => Koha::ApiKeys->search({ patron_id => $patron_id }),
patron => $patron
);
output_html_with_http_headers $cgi, $cookie, $template->output;