PageRenderTime 46ms CodeModel.GetById 16ms RepoModel.GetById 0ms app.codeStats 0ms

/modules/OAuthTokens/views/view.authorize.php

https://bitbucket.org/cviolette/sugarcrm
PHP | 98 lines | 50 code | 7 blank | 41 comment | 19 complexity | f8a69d966c7d3edd9b82e1cc408626f0 MD5 | raw file
Possible License(s): LGPL-2.1, MPL-2.0-no-copyleft-exception, BSD-3-Clause
  1. <?php
  2. if(!defined('sugarEntry') || !sugarEntry) die('Not A Valid Entry Point');
  3. /*********************************************************************************
  4. * SugarCRM Community Edition is a customer relationship management program developed by
  5. * SugarCRM, Inc. Copyright (C) 2004-2012 SugarCRM Inc.
  6. *
  7. * This program is free software; you can redistribute it and/or modify it under
  8. * the terms of the GNU Affero General Public License version 3 as published by the
  9. * Free Software Foundation with the addition of the following permission added
  10. * to Section 15 as permitted in Section 7(a): FOR ANY PART OF THE COVERED WORK
  11. * IN WHICH THE COPYRIGHT IS OWNED BY SUGARCRM, SUGARCRM DISCLAIMS THE WARRANTY
  12. * OF NON INFRINGEMENT OF THIRD PARTY RIGHTS.
  13. *
  14. * This program is distributed in the hope that it will be useful, but WITHOUT
  15. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
  16. * FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more
  17. * details.
  18. *
  19. * You should have received a copy of the GNU Affero General Public License along with
  20. * this program; if not, see http://www.gnu.org/licenses or write to the Free
  21. * Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
  22. * 02110-1301 USA.
  23. *
  24. * You can contact SugarCRM, Inc. headquarters at 10050 North Wolfe Road,
  25. * SW2-130, Cupertino, CA 95014, USA. or at email address contact@sugarcrm.com.
  26. *
  27. * The interactive user interfaces in modified source and object code versions
  28. * of this program must display Appropriate Legal Notices, as required under
  29. * Section 5 of the GNU Affero General Public License version 3.
  30. *
  31. * In accordance with Section 7(b) of the GNU Affero General Public License version 3,
  32. * these Appropriate Legal Notices must retain the display of the "Powered by
  33. * SugarCRM" logo. If the display of the logo is not reasonably feasible for
  34. * technical reasons, the Appropriate Legal Notices must display the words
  35. * "Powered by SugarCRM".
  36. ********************************************************************************/
  37. require_once 'include/SugarOAuthServer.php';
  38. class OauthTokensViewAuthorize extends SugarView
  39. {
  40. public function display()
  41. {
  42. if(!SugarOAuthServer::enabled()) {
  43. sugar_die($GLOBALS['mod_strings']['LBL_OAUTH_DISABLED']);
  44. }
  45. global $current_user;
  46. if(!isset($_REQUEST['token']) && isset($_REQUEST['oauth_token'])) {
  47. $_REQUEST['token'] = $_REQUEST['oauth_token'];
  48. }
  49. $sugar_smarty = new Sugar_Smarty();
  50. $sugar_smarty->assign('APP', $GLOBALS['app_strings']);
  51. $sugar_smarty->assign('MOD', $GLOBALS['mod_strings']);
  52. $sugar_smarty->assign('token', $_REQUEST['token']);
  53. $sugar_smarty->assign('sid', session_id());
  54. $token = OAuthToken::load($_REQUEST['token']);
  55. if(empty($token) || empty($token->consumer) || $token->tstate != OAuthToken::REQUEST || empty($token->consumer_obj)) {
  56. sugar_die('Invalid token');
  57. }
  58. if(empty($_REQUEST['confirm'])) {
  59. $sugar_smarty->assign('consumer', sprintf($GLOBALS['mod_strings']['LBL_OAUTH_CONSUMERREQ'], $token->consumer_obj->name));
  60. // SM: roles disabled for now
  61. // $roles = array('' => '');
  62. // $allroles = ACLRole::getAllRoles();
  63. // foreach($allroles as $role) {
  64. // $roles[$role->id] = $role->name;
  65. // }
  66. // $sugar_smarty->assign('roles', $roles);
  67. $hash = md5(rand());
  68. $_SESSION['oauth_hash'] = $hash;
  69. $sugar_smarty->assign('hash', $hash);
  70. echo $sugar_smarty->fetch('modules/OAuthTokens/tpl/authorize.tpl');
  71. } else {
  72. if($_REQUEST['sid'] != session_id() || $_SESSION['oauth_hash'] != $_REQUEST['hash']) {
  73. sugar_die('Invalid request');
  74. }
  75. $verify = $token->authorize(array("user" => $current_user->id));
  76. if(!empty($token->callback_url)){
  77. $redirect_url=$token->callback_url;
  78. if(strchr($redirect_url, "?") !== false) {
  79. $redirect_url .= '&';
  80. } else {
  81. $redirect_url .= '?';
  82. }
  83. $redirect_url .= "oauth_verifier=".$verify.'&oauth_token='.$_REQUEST['token'];
  84. SugarApplication::redirect($redirect_url);
  85. }
  86. $sugar_smarty->assign('VERIFY', $verify);
  87. $sugar_smarty->assign('token', '');
  88. echo $sugar_smarty->fetch('modules/OAuthTokens/tpl/authorized.tpl');
  89. }
  90. }
  91. }