// fix added form.tpl in AdminWebserviceController
git-svn-id: http://dev.prestashop.com/svn/v1/branches/1.5.x@10224 b9a71923-0436-4b27-9f14-aed3839534dd
This commit is contained in:
@@ -95,7 +95,7 @@
|
||||
{else}
|
||||
<input type="text"
|
||||
name="{$input.name}"
|
||||
id="{$input.name}"
|
||||
id="{if isset($input.id)}{$input.id}{else}{$input.name}{/if}"
|
||||
value="{$fields_value[$input.name]}"
|
||||
{if isset($input.size)}size="{$input.size}"{/if}
|
||||
{if isset($input.maxlength)}maxlength="{$input.maxlength}"{/if}
|
||||
|
||||
@@ -24,46 +24,93 @@
|
||||
* International Registered Trademark & Property of PrestaShop SA
|
||||
*}
|
||||
{extends file="helper/form/form.tpl"}
|
||||
{block name="defaultForm"}
|
||||
{$custom_form}
|
||||
<script type="text/javascript">
|
||||
|
||||
{block name="end_field_block"}
|
||||
{if $input.type == 'text' && $input.name == 'key'}
|
||||
<input type="button" value="{l s=' Generate! '}" class="button" onclick="gencode(32)" />
|
||||
{/if}
|
||||
</div>
|
||||
{/block}
|
||||
|
||||
{block name="start_field_block"}
|
||||
<div class="margin-form">
|
||||
{if $input.type == 'resources'}
|
||||
<p>{l s='Set the resource permissions for this key:'}</p>
|
||||
<table border="0" cellspacing="0" cellpadding="0" class="table accesses">
|
||||
<thead>
|
||||
<tr>
|
||||
<th class="center">{l s='Resource'}</th>
|
||||
<th width="30" class="center"></th>
|
||||
<th width="50" class="center">{l s='View (GET)'}</th>
|
||||
<th width="50" class="center">{l s='Modify (PUT)'}</th>
|
||||
<th width="50" class="center">{l s='Add (POST)'}</th>
|
||||
<th width="50" class="center">{l s='Delete (DELETE)'}</th>
|
||||
<th width="50" class="center">{l s='Fast view (HEAD)'}</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr class="all" style="vertical-align:middle">
|
||||
<th></th>
|
||||
<th></th>
|
||||
<th class="center"><input type="checkbox" class="all_get get " /></th>
|
||||
<th class="center"><input type="checkbox" class="all_put put " /></th>
|
||||
<th class="center"><input type="checkbox" class="all_post post " /></th>
|
||||
<th class="center"><input type="checkbox" class="all_delete delete" /></th>
|
||||
<th class="center"><input type="checkbox" class="all_head head" /></th>
|
||||
</tr>
|
||||
{foreach $ressources as $resource_name => $resource}
|
||||
<tr>
|
||||
<th class="center">{$resource_name}</th>
|
||||
<th class="center"><input type="checkbox" class="all"/></th>
|
||||
<td class="center"><input type="checkbox" {if isset($ressources[$resource_name]['forbidden_method']) && in_array('GET', $ressources[$resource_name]['forbidden_method'])}disabled="disabled"{/if} class="get" name="resources[{$resource_name}][GET]" {if isset($permissions[$resource_name]) && in_array('GET', $permissions[$resource_name])}checked="checked"{/if} /></td>
|
||||
<td class="center"><input type="checkbox" {if isset($ressources[$resource_name]['forbidden_method']) && in_array('PUT', $ressources[$resource_name]['forbidden_method'])}disabled="disabled"{/if} class="put" name="resources[{$resource_name}][PUT]" {if isset($permissions[$resource_name]) && in_array('PUT', $permissions[$resource_name])}checked="checked"{/if}/></td>
|
||||
<td class="center"><input type="checkbox" {if isset($ressources[$resource_name]['forbidden_method']) && in_array('POST', $ressources[$resource_name]['forbidden_method'])}disabled="disabled"{/if} class="post" name="resources[{$resource_name}][POST]" {if isset($permissions[$resource_name]) && in_array('POST', $permissions[$resource_name])}checked="checked"{/if}/></td>
|
||||
<td class="center"><input type="checkbox" {if isset($ressources[$resource_name]['forbidden_method']) && in_array('DELETE', $ressources[$resource_name]['forbidden_method'])}disabled="disabled"{/if} class="delete" name="resources[{$resource_name}][DELETE]" {if isset($permissions[$resource_name]) && in_array('DELETE', $permissions[$resource_name])}checked="checked"{/if}/></td>
|
||||
<td class="center"><input type="checkbox" {if isset($ressources[$resource_name]['forbidden_method']) && in_array('HEAD', $ressources[$resource_name]['forbidden_method'])}disabled="disabled"{/if} class="head" name="resources[{$resource_name}][HEAD]" {if isset($permissions[$resource_name]) && in_array('HEAD', $permissions[$resource_name])}checked="checked"{/if}/></td>
|
||||
</tr>
|
||||
{/foreach}
|
||||
</tbody>
|
||||
</table>
|
||||
{/if}
|
||||
{/block}
|
||||
|
||||
{block name="script"}
|
||||
$(function() {
|
||||
$('table.permissions input.all').click(function() {
|
||||
$('table.accesses input.all').click(function() {
|
||||
if($(this).is(':checked'))
|
||||
$(this).parent().parent().find('input.get:not(:checked), input.put:not(:checked), input.post:not(:checked), input.delete:not(:checked), input.head:not(:checked)').click();
|
||||
else
|
||||
$(this).parent().parent().find('input.get:checked, input.put:checked, input.post:checked, input.delete:checked, input.head:checked').click();
|
||||
});
|
||||
$('table.permissions .all_get').click(function() {
|
||||
$('table.accesses .all_get').click(function() {
|
||||
if($(this).is(':checked'))
|
||||
$(this).parent().parent().parent().find('input.get:not(:checked)').click();
|
||||
else
|
||||
$(this).parent().parent().parent().find('input.get:checked').click();
|
||||
});
|
||||
$('table.permissions .all_put').click(function() {
|
||||
$('table.accesses .all_put').click(function() {
|
||||
if($(this).is(':checked'))
|
||||
$(this).parent().parent().parent().find('input.put:not(:checked)').click();
|
||||
else
|
||||
$(this).parent().parent().parent().find('input.put:checked').click();
|
||||
});
|
||||
$('table.permissions .all_post').click(function() {
|
||||
$('table.accesses .all_post').click(function() {
|
||||
if($(this).is(':checked'))
|
||||
$(this).parent().parent().parent().find('input.post:not(:checked)').click();
|
||||
else
|
||||
$(this).parent().parent().parent().find('input.post:checked').click();
|
||||
});
|
||||
$('table.permissions .all_delete').click(function() {
|
||||
$('table.accesses .all_delete').click(function() {
|
||||
if($(this).is(':checked'))
|
||||
$(this).parent().parent().parent().find('input.delete:not(:checked)').click();
|
||||
else
|
||||
$(this).parent().parent().parent().find('input.delete:checked').click();
|
||||
});
|
||||
$('table.permissions .all_head').click(function() {
|
||||
$('table.accesses .all_head').click(function() {
|
||||
if($(this).is(':checked'))
|
||||
$(this).parent().parent().parent().find('input.head:not(:checked)').click();
|
||||
else
|
||||
$(this).parent().parent().parent().find('input.head:checked').click();
|
||||
});
|
||||
});
|
||||
</script>
|
||||
{/block}
|
||||
|
||||
@@ -629,7 +629,11 @@ class AdminControllerCore extends Controller
|
||||
$this->_errors[] = Tools::displayError('You do not have permission to add here.');
|
||||
}
|
||||
}
|
||||
|
||||
$this->_errors = array_unique($this->_errors);
|
||||
if (count($this->_errors) > 0);
|
||||
return;
|
||||
|
||||
return $object;
|
||||
}
|
||||
|
||||
|
||||
@@ -28,20 +28,20 @@
|
||||
class WebserviceKeyCore extends ObjectModel
|
||||
{
|
||||
/** @var string Key */
|
||||
public $key;
|
||||
public $key;
|
||||
|
||||
/** @var boolean Webservice Account statuts */
|
||||
public $active = true;
|
||||
public $active = true;
|
||||
|
||||
/** @var string Webservice Account description */
|
||||
public $description;
|
||||
public $description;
|
||||
|
||||
protected $fieldsRequired = array('key');
|
||||
protected $fieldsSize = array('key' => 32);
|
||||
protected $fieldsValidate = array('active' => 'isBool');
|
||||
protected $fieldsRequired = array('key');
|
||||
protected $fieldsSize = array('key' => 32);
|
||||
protected $fieldsValidate = array('active' => 'isBool');
|
||||
|
||||
protected $table = 'webservice_account';
|
||||
protected $identifier = 'id_webservice_account';
|
||||
protected $table = 'webservice_account';
|
||||
protected $identifier = 'id_webservice_account';
|
||||
|
||||
|
||||
public function add($autodate = true, $nullValues = false)
|
||||
@@ -51,7 +51,7 @@ class WebserviceKeyCore extends ObjectModel
|
||||
return parent::add($autodate = true, $nullValues = false);
|
||||
}
|
||||
|
||||
static public function keyExists($key)
|
||||
public static function keyExists($key)
|
||||
{
|
||||
return (!Db::getInstance(_PS_USE_SQL_SLAVE_)->executeS('SELECT `key`
|
||||
FROM '._DB_PREFIX_.'webservice_account
|
||||
@@ -63,29 +63,27 @@ class WebserviceKeyCore extends ObjectModel
|
||||
$this->validateFields();
|
||||
|
||||
$fields['key'] = pSQL($this->key);
|
||||
$fields['active'] = (int)($this->active);
|
||||
$fields['active'] = (int)$this->active;
|
||||
$fields['description'] = pSQL($this->description);
|
||||
return $fields;
|
||||
}
|
||||
|
||||
public function delete()
|
||||
{
|
||||
if (!parent::delete() OR $this->deleteAssociations() === false)
|
||||
if (!parent::delete() || $this->deleteAssociations() === false)
|
||||
return false;
|
||||
return true;
|
||||
}
|
||||
|
||||
public function deleteAssociations()
|
||||
{
|
||||
if (
|
||||
Db::getInstance()->execute('
|
||||
if (Db::getInstance()->execute('
|
||||
DELETE FROM `'._DB_PREFIX_.'webservice_permission`
|
||||
WHERE `id_webservice_account` = '.(int)($this->id)) === false
|
||||
WHERE `id_webservice_account` = '.(int)$this->id) === false
|
||||
||
|
||||
Db::getInstance()->execute('
|
||||
DELETE FROM `'._DB_PREFIX_.'webservice_permission`
|
||||
WHERE `id_webservice_account` = '.(int)($this->id)) === false
|
||||
)
|
||||
WHERE `id_webservice_account` = '.(int)$this->id) === false)
|
||||
return false;
|
||||
return true;
|
||||
}
|
||||
@@ -115,9 +113,7 @@ class WebserviceKeyCore extends ObjectModel
|
||||
if (!isset($result[0]))
|
||||
return null;
|
||||
else
|
||||
{
|
||||
return isset($result[0]['active']) && $result[0]['active'];
|
||||
}
|
||||
}
|
||||
|
||||
public static function getClassFromKey($auth_key)
|
||||
@@ -130,38 +126,36 @@ class WebserviceKeyCore extends ObjectModel
|
||||
if (!isset($result[0]))
|
||||
return null;
|
||||
else
|
||||
{
|
||||
return $result[0]['class'];
|
||||
}
|
||||
}
|
||||
|
||||
public static function setPermissionForAccount($idAccount, $permissionsToSet)
|
||||
public static function setPermissionForAccount($id_account, $permissions_to_set)
|
||||
{
|
||||
$ok = true;
|
||||
$sql = 'DELETE FROM `'._DB_PREFIX_.'webservice_permission` WHERE `id_webservice_account` = '.(int)($idAccount);
|
||||
$sql = 'DELETE FROM `'._DB_PREFIX_.'webservice_permission` WHERE `id_webservice_account` = '.(int)$id_account;
|
||||
if (!Db::getInstance()->execute($sql))
|
||||
$ok = false;
|
||||
if (isset($permissionsToSet))
|
||||
{
|
||||
if (isset($permissions_to_set))
|
||||
{
|
||||
$permissions = array();
|
||||
$resources = WebserviceRequest::getResources();
|
||||
$methods = array('GET', 'PUT', 'POST', 'DELETE', 'HEAD');
|
||||
foreach ($permissionsToSet as $resourceName => $resource_methods)
|
||||
if (in_array($resourceName, array_keys($resources)))
|
||||
foreach (array_keys($resource_methods) as $methodName)
|
||||
if (in_array($methodName, $methods))
|
||||
$permissions[] = array($methodName, $resourceName);
|
||||
$account = new WebserviceKey($idAccount);
|
||||
foreach ($permissions_to_set as $resource_name => $resource_methods)
|
||||
if (in_array($resource_name, array_keys($resources)))
|
||||
foreach (array_keys($resource_methods) as $method_name)
|
||||
if (in_array($method_name, $methods))
|
||||
$permissions[] = array($method_name, $resource_name);
|
||||
$account = new WebserviceKey($id_account);
|
||||
if ($account->deleteAssociations() && $permissions)
|
||||
{
|
||||
$sql = 'INSERT INTO `'._DB_PREFIX_.'webservice_permission` (`id_webservice_permission` ,`resource` ,`method` ,`id_webservice_account`) VALUES ';
|
||||
foreach ($permissions as $permission)
|
||||
$sql .= '(NULL , \''.pSQL($permission[1]).'\', \''.pSQL($permission[0]).'\', '.(int)($idAccount).'), ';
|
||||
$sql .= '(NULL , \''.pSQL($permission[1]).'\', \''.pSQL($permission[0]).'\', '.(int)$id_account.'), ';
|
||||
$sql = rtrim($sql, ', ');
|
||||
if (!Db::getInstance()->execute($sql))
|
||||
$ok = false;
|
||||
}
|
||||
}
|
||||
}
|
||||
return $ok;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
<?php
|
||||
/*
|
||||
* 2007-2011 PrestaShop
|
||||
* 2007-2011 PrestaShop
|
||||
*
|
||||
* NOTICE OF LICENSE
|
||||
*
|
||||
@@ -27,34 +27,49 @@
|
||||
|
||||
class AdminWebserviceControllerCore extends AdminController
|
||||
{
|
||||
// this will be filled later
|
||||
/** this will be filled later */
|
||||
public $fields_form = array('webservice form');
|
||||
|
||||
public function __construct()
|
||||
{
|
||||
$this->table = 'webservice_account';
|
||||
$this->className = 'WebserviceKey';
|
||||
$this->className = 'WebserviceKey';
|
||||
$this->lang = false;
|
||||
$this->edit = true;
|
||||
$this->delete = true;
|
||||
$this->id_lang_default = Configuration::get('PS_LANG_DEFAULT');
|
||||
|
||||
|
||||
$this->fieldsDisplay = array(
|
||||
'key' => array('title' => $this->l('Key'), 'align' => 'center', 'width' => 32),
|
||||
'active' => array('title' => $this->l('Enabled'), 'align' => 'center', 'active' => 'status', 'type' => 'bool', 'orderby' => false),
|
||||
'description' => array('title' => $this->l('Key description'), 'align' => 'center', 'orderby' => false)
|
||||
'key' => array(
|
||||
'title' => $this->l('Key'),
|
||||
'align' => 'center',
|
||||
'width' => 32
|
||||
),
|
||||
'active' => array(
|
||||
'title' => $this->l('Enabled'),
|
||||
'align' => 'center',
|
||||
'active' => 'status',
|
||||
'type' => 'bool',
|
||||
'orderby' => false
|
||||
),
|
||||
'description' => array(
|
||||
'title' => $this->l('Key description'),
|
||||
'align' => 'center',
|
||||
'orderby' => false
|
||||
)
|
||||
);
|
||||
|
||||
|
||||
if (file_exists(_PS_ROOT_DIR_.'/.htaccess'))
|
||||
$this->options = array(
|
||||
'general' => array(
|
||||
'title' => $this->l('Configuration'),
|
||||
'fields' => array(
|
||||
'PS_WEBSERVICE' => array('title' => $this->l('Enable PrestaShop Webservice:'),
|
||||
'PS_WEBSERVICE' => array('title' => $this->l('Enable PrestaShop Webservice:'),
|
||||
'desc' => $this->l('Before activating the webservice, you must be sure to: ').
|
||||
'<ol><li>'.$this->l('be certain URL rewrite is available on this server').
|
||||
'</li><li>'.$this->l('be certain that the 5 methods GET, POST, PUT, DELETE and HEAD are supported by this server').
|
||||
'</li></ol>',
|
||||
'<ol>
|
||||
<li>'.$this->l('be certain URL rewrite is available on this server').'</li>
|
||||
<li>'.$this->l('be certain that the 5 methods GET, POST, PUT, DELETE and HEAD are supported by this server').'</li>
|
||||
</ol>',
|
||||
'cast' => 'intval',
|
||||
'type' => 'bool'),
|
||||
),
|
||||
@@ -63,138 +78,97 @@ class AdminWebserviceControllerCore extends AdminController
|
||||
|
||||
parent::__construct();
|
||||
}
|
||||
|
||||
protected function afterAdd($object)
|
||||
{
|
||||
WebserviceKey::setPermissionForAccount($object->id, Tools::getValue('resources', array()));
|
||||
}
|
||||
|
||||
protected function afterUpdate($object)
|
||||
{
|
||||
WebserviceKey::setPermissionForAccount($object->id, Tools::getValue('resources', array()));
|
||||
}
|
||||
|
||||
public function checkForWarning()
|
||||
{
|
||||
if (!file_exists(_PS_ROOT_DIR_.'/.htaccess'))
|
||||
$this->warnings[] = $this->l('In order to enable the PrestaShop Webservice, please generate the .htaccess file via the "Generators" tab (in the "Tools" tab).');
|
||||
if (strpos($_SERVER['SERVER_SOFTWARE'], 'Apache') === false)
|
||||
$this->warnings[] = $this->l('To avoid operating problems, please use an Apache server.');
|
||||
{
|
||||
if (function_exists('apache_get_modules'))
|
||||
{
|
||||
$apache_modules = apache_get_modules();
|
||||
if (!in_array('mod_auth_basic', $apache_modules))
|
||||
$this->warnings[] = $this->l('Please activate the Apache module \'mod_auth_basic\' to allow authentication of PrestaShop webservice.');
|
||||
if (!in_array('mod_rewrite', $apache_modules))
|
||||
$this->warnings[] = $this->l('Please activate the Apache module \'mod_rewrite\' to allow using the PrestaShop webservice.');
|
||||
}
|
||||
else
|
||||
{
|
||||
$this->warnings[] = $this->l('We could not check if basic authentication and rewrite extensions are activated. Please manually check if they are activated in order to use the PrestaShop webservice.');
|
||||
}
|
||||
}
|
||||
if (!extension_loaded('SimpleXML'))
|
||||
$this->warnings[] = $this->l('Please activate the PHP extension \'SimpleXML\' to allow testing of PrestaShop webservice.');
|
||||
if (!configuration::get('PS_SSL_ENABLED'))
|
||||
$this->warnings[] = $this->l('If possible, it is preferable to use SSL (https) for webservice calls, as it avoids the security issues of type "man in the middle".');
|
||||
|
||||
|
||||
foreach ($this->_list as $k => $item)
|
||||
if ($item['is_module'] && $item['class_name'] && $item['module_name'] &&
|
||||
($instance = Module::getInstanceByName($item['module_name'])) &&
|
||||
!$instance->useNormalPermissionBehaviour())
|
||||
unset($this->_list[$k]);
|
||||
$this->initList();
|
||||
}
|
||||
|
||||
/** @todo : to fill $this->fields_form in order to generate
|
||||
* the form automatically..
|
||||
*
|
||||
*/
|
||||
public function initForm($isMainTab = true)
|
||||
public function initForm()
|
||||
{
|
||||
$content = '';
|
||||
$this->fields_form = array(
|
||||
'legend' => array(
|
||||
'title' => $this->l('Webservice Accounts:'),
|
||||
'image' => '../img/admin/access.png'
|
||||
),
|
||||
'input' => array(
|
||||
array(
|
||||
'type' => 'text',
|
||||
'label' => $this->l('Key:'),
|
||||
'name' => 'key',
|
||||
'id' => 'code',
|
||||
'size' => 32,
|
||||
'required' => true,
|
||||
'p' => $this->l('Webservice account key'),
|
||||
),
|
||||
array(
|
||||
'type' => 'textarea',
|
||||
'label' => $this->l('Key description:'),
|
||||
'name' => 'description',
|
||||
'rows' => 3,
|
||||
'cols' => 110,
|
||||
'p' => $this->l('Key description'),
|
||||
),
|
||||
array(
|
||||
'type' => 'radio',
|
||||
'label' => $this->l('Status:'),
|
||||
'name' => 'active',
|
||||
'required' => false,
|
||||
'class' => 't',
|
||||
'is_bool' => true,
|
||||
'values' => array(
|
||||
array(
|
||||
'id' => 'active_on',
|
||||
'value' => 1,
|
||||
'label' => $this->l('Enabled')
|
||||
),
|
||||
array(
|
||||
'id' => 'active_off',
|
||||
'value' => 0,
|
||||
'label' => $this->l('Disabled')
|
||||
)
|
||||
)
|
||||
),
|
||||
array(
|
||||
'type' => 'resources',
|
||||
'label' => $this->l('Permissions:'),
|
||||
'name' => 'resources',
|
||||
)
|
||||
)
|
||||
);
|
||||
|
||||
if (Shop::isFeatureActive())
|
||||
{
|
||||
$this->fields_form['input'][] = array(
|
||||
'type' => 'shop',
|
||||
'label' => $this->l('Shop association:'),
|
||||
'name' => 'checkBoxShopAsso',
|
||||
'values' => Shop::getTree()
|
||||
);
|
||||
}
|
||||
|
||||
$this->fields_form['submit'] = array(
|
||||
'title' => $this->l(' Save '),
|
||||
'class' => 'button'
|
||||
);
|
||||
|
||||
if (!($obj = $this->loadObject(true)))
|
||||
return;
|
||||
|
||||
$content = '
|
||||
<form action="'.self::$currentIndex.'&submitAdd'.$this->table.'=1&token='.$this->token.'" method="post" enctype="multipart/form-data">
|
||||
'.($obj->id ? '<input type="hidden" name="id_'.$this->table.'" value="'.$obj->id.'" />' : '').'
|
||||
<fieldset><legend><img src="../img/admin/access.png" />'.$this->l('Webservice Accounts').'</legend>
|
||||
<label>'.$this->l('Key:').'</label>
|
||||
<div class="margin-form">
|
||||
<input type="text" size="32" name="key" id="code" value="'.htmlentities(Tools::getValue('key', $obj->key), ENT_COMPAT, 'UTF-8').'" />
|
||||
<input type="button" value="'.$this->l(' Generate! ').'" class="button" onclick="gencode(32)" />
|
||||
<sup>*</sup>
|
||||
<p class="clear">'.$this->l('Webservice account key').'</p>
|
||||
</div>
|
||||
<label>'.$this->l('Key description').'</label>
|
||||
<div class="margin-form">
|
||||
<textarea rows="3" style="width:400px" name="description">'.htmlentities(Tools::getValue('description', $obj->description), ENT_COMPAT, 'UTF-8').'</textarea>
|
||||
<p class="clear">'.$this->l('Key description').'</p>
|
||||
</div>
|
||||
<label>'.$this->l('Status:').' </label>
|
||||
<div class="margin-form">
|
||||
<input type="radio" name="active" id="active_on" value="1" '.((!$obj->id OR Tools::getValue('active', $obj->active)) ? 'checked="checked" ' : '').'/>
|
||||
<label class="t" for="active_on"> <img src="../img/admin/enabled.gif" alt="'.$this->l('Enabled').'" title="'.$this->l('Enabled').'" /></label>
|
||||
<input type="radio" name="active" id="active_off" value="0" '.((!Tools::getValue('active', $obj->active) AND $obj->id) ? 'checked="checked" ' : '').'/>
|
||||
<label class="t" for="active_off"> <img src="../img/admin/disabled.gif" alt="'.$this->l('Disabled').'" title="'.$this->l('Disabled').'" /></label>
|
||||
</div>
|
||||
<label>'.$this->l('Permissions:').' </label>
|
||||
<div class="margin-form">
|
||||
<p>'.$this->l('Set the resource permissions for this key:').'</p>
|
||||
<table border="0" cellspacing="0" cellpadding="0" class="permissions">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>'.$this->l('Resource').'</th>
|
||||
<th width="30"></th>
|
||||
<th width="50">'.$this->l('View (GET)').'</th>
|
||||
<th width="50">'.$this->l('Modify (PUT)').'</th>
|
||||
<th width="50">'.$this->l('Add (POST)').'</th>
|
||||
<th width="50">'.$this->l('Delete (DELETE)').'</th>
|
||||
<th width="50">'.$this->l('Fast view (HEAD)').'</th>
|
||||
</tr>
|
||||
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr class="all" style="vertical-align:cen">
|
||||
<th></th>
|
||||
<th></th>
|
||||
<th><input type="checkbox" class="all_get get " /></th>
|
||||
<th><input type="checkbox" class="all_put put " /></th>
|
||||
<th><input type="checkbox" class="all_post post " /></th>
|
||||
<th><input type="checkbox" class="all_delete delete" /></th>
|
||||
<th><input type="checkbox" class="all_head head" /></th>
|
||||
</tr>
|
||||
';
|
||||
|
||||
$ressources = WebserviceRequest::getResources();
|
||||
$permissions = WebserviceKey::getPermissionForAccount($obj->key);
|
||||
foreach ($ressources as $resourceName => $resource)
|
||||
$content .= '
|
||||
<tr>
|
||||
<th>'.$resourceName.'</th>
|
||||
<th><input type="checkbox" class="all"/></th>
|
||||
<td><input type="checkbox" '.(isset($ressources[$resourceName]['forbidden_method']) && in_array('GET', $ressources[$resourceName]['forbidden_method']) ? 'disabled="disabled"' : '').' class="get" name="resources['.$resourceName.'][GET]" '.(isset($permissions[$resourceName]) && in_array('GET', $permissions[$resourceName]) ? 'checked="checked"' : '').' /></td>
|
||||
<td><input type="checkbox" '.(isset($ressources[$resourceName]['forbidden_method']) && in_array('PUT', $ressources[$resourceName]['forbidden_method']) ? 'disabled="disabled"' : '').' class="put" name="resources['.$resourceName.'][PUT]" '.(isset($permissions[$resourceName]) && in_array('PUT', $permissions[$resourceName]) ? 'checked="checked"' : '').'/></td>
|
||||
<td><input type="checkbox" '.(isset($ressources[$resourceName]['forbidden_method']) && in_array('POST', $ressources[$resourceName]['forbidden_method']) ? 'disabled="disabled"' : '').' class="post" name="resources['.$resourceName.'][POST]" '.(isset($permissions[$resourceName]) && in_array('POST', $permissions[$resourceName]) ? 'checked="checked"' : '').'/></td>
|
||||
<td><input type="checkbox" '.(isset($ressources[$resourceName]['forbidden_method']) && in_array('DELETE', $ressources[$resourceName]['forbidden_method']) ? 'disabled="disabled"' : '').' class="delete" name="resources['.$resourceName.'][DELETE]" '.(isset($permissions[$resourceName]) && in_array('DELETE', $permissions[$resourceName]) ? 'checked="checked"' : '').'/></td>
|
||||
<td><input type="checkbox" '.(isset($ressources[$resourceName]['forbidden_method']) && in_array('HEAD', $ressources[$resourceName]['forbidden_method']) ? 'disabled="disabled"' : '').' class="head" name="resources['.$resourceName.'][HEAD]" '.(isset($permissions[$resourceName]) && in_array('HEAD', $permissions[$resourceName]) ? 'checked="checked"' : '').'/></td>
|
||||
</tr>';
|
||||
$content .= '
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
<div class="margin-form">
|
||||
<input type="submit" value="'.$this->l(' Save ').'" name="submitAdd'.$this->table.'" class="button" />
|
||||
</div>
|
||||
<div class="small"><sup>*</sup> '.$this->l('Required field').'</div>
|
||||
</fieldset>
|
||||
</form>';
|
||||
$this->tpl_form_vars['custom_form'] = $content;
|
||||
|
||||
$this->tpl_form_vars = array(
|
||||
'ressources' => $ressources,
|
||||
'permissions' => $permissions
|
||||
);
|
||||
|
||||
return parent::initForm();
|
||||
}
|
||||
|
||||
public function initContent()
|
||||
{
|
||||
if ($this->display != 'add' && $this->display != 'edit')
|
||||
$this->checkForWarning();
|
||||
|
||||
parent::initContent();
|
||||
}
|
||||
|
||||
public function postProcess()
|
||||
{
|
||||
if (Tools::getValue('key') && strlen(Tools::getValue('key')) < 32)
|
||||
@@ -204,57 +178,49 @@ class AdminWebserviceControllerCore extends AdminController
|
||||
return parent::postProcess();
|
||||
}
|
||||
|
||||
public function initContent()
|
||||
protected function afterAdd($object)
|
||||
{
|
||||
$content = '';
|
||||
// Include other tab in current tab
|
||||
if ($this->includeSubTab('display', array('submitAdd2', 'add', 'update', 'view'))){}
|
||||
WebserviceKey::setPermissionForAccount($object->id, Tools::getValue('resources', array()));
|
||||
}
|
||||
|
||||
// Include current tab
|
||||
elseif ((Tools::getValue('submitAdd'.$this->table) AND sizeof($this->_errors)) OR isset($_GET['add'.$this->table]))
|
||||
protected function afterUpdate($object)
|
||||
{
|
||||
WebserviceKey::setPermissionForAccount($object->id, Tools::getValue('resources', array()));
|
||||
}
|
||||
|
||||
public function checkForWarning()
|
||||
{
|
||||
if (!file_exists(_PS_ROOT_DIR_.'/.htaccess'))
|
||||
$this->warnings[] = $this->l('In order to enable the PrestaShop Webservice,
|
||||
please generate the .htaccess file via the "Generators" tab (in the "Tools" tab).');
|
||||
if (strpos($_SERVER['SERVER_SOFTWARE'], 'Apache') === false)
|
||||
{
|
||||
if ($this->tabAccess['add'] === '1')
|
||||
$this->warnings[] = $this->l('To avoid operating problems, please use an Apache server.');
|
||||
if (function_exists('apache_get_modules'))
|
||||
{
|
||||
$this->display = 'add';
|
||||
// $content .= $this->initForm();
|
||||
if ($this->tabAccess['view'])
|
||||
$content .= '<br /><br /><a href="'.((Tools::getValue('back')) ? Tools::getValue('back') : self::$currentIndex.'&token='.$this->token).'"><img src="../img/admin/arrow2.gif" /> '.((Tools::getValue('back')) ? $this->l('Back') : $this->l('Back to list')).'</a><br />';
|
||||
$apache_modules = apache_get_modules();
|
||||
if (!in_array('mod_auth_basic', $apache_modules))
|
||||
$this->warnings[] = $this->l('Please activate the Apache module \'mod_auth_basic\' to allow authentication of PrestaShop webservice.');
|
||||
if (!in_array('mod_rewrite', $apache_modules))
|
||||
$this->warnings[] = $this->l('Please activate the Apache module \'mod_rewrite\' to allow using the PrestaShop webservice.');
|
||||
}
|
||||
else
|
||||
$content .= $this->l('You do not have permission to add here');
|
||||
$this->warnings[] = $this->l('We could not check if basic authentication and rewrite extensions are activated.
|
||||
Please manually check if they are activated in order to use the PrestaShop webservice.');
|
||||
}
|
||||
elseif (isset($_GET['update'.$this->table]))
|
||||
{
|
||||
if ($this->tabAccess['edit'] === '1' OR ($this->table == 'employee' AND $this->context->employee->id == Tools::getValue('id_employee')))
|
||||
{
|
||||
$content .= $this->initForm();
|
||||
if ($this->tabAccess['view'])
|
||||
$content .= '<br /><br /><a href="'.((Tools::getValue('back')) ? Tools::getValue('back') : self::$currentIndex.'&token='.$this->token).'"><img src="../img/admin/arrow2.gif" /> '.((Tools::getValue('back')) ? $this->l('Back') : $this->l('Back to list')).'</a><br />';
|
||||
}
|
||||
else
|
||||
$content .= $this->l('You do not have permission to edit here');
|
||||
}
|
||||
elseif (isset($_GET['view'.$this->table]))
|
||||
$this->{'view'.$this->table}();
|
||||
else
|
||||
{
|
||||
$this->checkForWarning();
|
||||
|
||||
/*
|
||||
$this->getList($this->context->language->id);
|
||||
$this->displayList();
|
||||
|
||||
$this->displayRequiredFields();
|
||||
$this->includeSubTab('display');
|
||||
$assos_shop = Shop::getAssoTables();
|
||||
if (isset($assos_shop[$this->table]) AND $assos_shop[$this->table]['type'] == 'shop')
|
||||
$this->displayAssoShop();
|
||||
elseif (isset($assos_shop[$this->table]) AND $assos_shop[$this->table]['type'] == 'group_shop')
|
||||
$this->displayAssoShop('group_shop');
|
||||
$this->displayOptionsList();
|
||||
*/
|
||||
}
|
||||
parent::initContent();
|
||||
if (!extension_loaded('SimpleXML'))
|
||||
$this->warnings[] = $this->l('Please activate the PHP extension \'SimpleXML\' to allow testing of PrestaShop webservice.');
|
||||
if (!configuration::get('PS_SSL_ENABLED'))
|
||||
$this->warnings[] = $this->l('If possible, it is preferable to use SSL (https) for webservice calls,
|
||||
as it avoids the security issues of type "man in the middle".');
|
||||
|
||||
foreach ($this->_list as $k => $item)
|
||||
if ($item['is_module'] && $item['class_name'] && $item['module_name'] &&
|
||||
($instance = Module::getInstanceByName($item['module_name'])) &&
|
||||
!$instance->useNormalPermissionBehaviour())
|
||||
unset($this->_list[$k]);
|
||||
|
||||
$this->initList();
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user