dolibarr /htdocs/core/lib/ws.lib.php

Language PHP Lines 91
MD5 Hash f1dd76317f9661731e66bf2010c84e0c
Repository https://github.com/asterix14/dolibarr.git View Raw File
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
<?php
/* Copyright (C) 2011 Laurent Destailleur  <eldy@users.sourceforge.net>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program. If not, see <http://www.gnu.org/licenses/>.
 * or see http://www.gnu.org/
 */

/**
 *  \file		htdocs/core/lib/ws.lib.php
 *  \ingroup	webservices
 *  \brief		Set of function for manipulating web services
 */


/**
 *  Check authentication array and set error, errorcode, errorlabel
 *
 *  @param	array	$authentication     Array with authentication informations ('login'=>,'password'=>,'entity'=>,'dolibarrkey'=>)
 *  @param 	int		&$error				Number of errors
 *  @param  string	&$errorcode			Error string code
 *  @param  string	&$errorlabel		Error string label
 *  @return	User						Return user object identified by login/pass/entity into authentication array
 */
function check_authentication($authentication,&$error,&$errorcode,&$errorlabel)
{
    global $db,$conf,$langs;
    global $dolibarr_main_authentication,$dolibarr_auto_user;

    $fuser=new User($db);

    if (! $error && ($authentication['dolibarrkey'] != $conf->global->WEBSERVICES_KEY))
    {
        $error++;
        $errorcode='BAD_VALUE_FOR_SECURITY_KEY'; $errorlabel='Value provided into dolibarrkey entry field does not match security key defined in Webservice module setup';
    }

    if (! $error && ! empty($authentication['entity']) && ! is_numeric($authentication['entity']))
    {
        $error++;
        $errorcode='BAD_PARAMETERS'; $errorlabel="Parameter entity must be empty (or filled with numeric id of instance if multicompany module is used).";
    }

    if (! $error)
    {
        $result=$fuser->fetch('',$authentication['login'],'',0);
        if ($result < 0)
        {
            $error++;
            $errorcode='ERROR_FETCH_USER'; $errorlabel='A technical error occurs during fetch of user';
        }
        else if ($result == 0)
        {
            $error++;
            $errorcode='BAD_CREDENTIALS'; $errorlabel='Bad value for login or password';
        }

    	// Validation of login
		if (! $error)
		{
        	// Authentication mode
        	if (empty($dolibarr_main_authentication)) $dolibarr_main_authentication='http,dolibarr';
        	// Authentication mode: forceuser
        	if ($dolibarr_main_authentication == 'forceuser' && empty($dolibarr_auto_user)) $dolibarr_auto_user='auto';
        	// Set authmode
        	$authmode=explode(',',$dolibarr_main_authentication);

			$login = checkLoginPassEntity($authentication['login'],$authentication['password'],$authentication['entity'],$authmode);
			if (empty($login))
			{
			    $error++;
                $errorcode='BAD_CREDENTIALS'; $errorlabel='Bad value for login or password';
			}
		}
    }

    return $fuser;
}

?>
Back to Top