From 9ef728d660bf109bd56adf144344fe326110add3 Mon Sep 17 00:00:00 2001 From: jerome mouneyrac Date: Fri, 8 Oct 2010 03:03:10 +0000 Subject: [PATCH] webservice MDL-24541 change wsdoc.php external authentication into a normal moodle page with require_login(), no form, documentation directly related to the token and display from the user security keys page (see MDL for more information) --- admin/settings/plugins.php | 6 +- admin/webservice/forms.php | 1 + lang/en/admin.php | 2 +- lang/en/webservice.php | 8 +- user/managetoken.php | 6 +- webservice/lib.php | 10 + webservice/renderer.php | 81 +++----- webservice/wsdoc.php | 366 +++++++------------------------------ 8 files changed, 110 insertions(+), 370 deletions(-) diff --git a/admin/settings/plugins.php b/admin/settings/plugins.php index 1beb39f58ea..14c6dd2ec74 100644 --- a/admin/settings/plugins.php +++ b/admin/settings/plugins.php @@ -331,9 +331,9 @@ if ($hassiteconfig) { if (empty($CFG->enablewebservices)) { $temp->add(new admin_setting_heading('webservicesaredisabled', '', get_string('disabledwarning', 'webservice'))); } - $url = new moodle_url('/webservice/wsdoc.php'); - $atag =html_writer::start_tag('a', array('href' => $url)).get_string('documentation', 'webservice').html_writer::end_tag('a'); - $temp->add(new admin_setting_configcheckbox('enablewsdocumentation', get_string('enablewsdocumentation', 'admin'), get_string('configenablewsdocumentation', 'admin', $atag), false)); + $wsdoclink = $OUTPUT->doc_link('How_to_get_a_security_key'); + $temp->add(new admin_setting_configcheckbox('enablewsdocumentation', get_string('enablewsdocumentation', + 'admin'), get_string('configenablewsdocumentation', 'admin', $wsdoclink), false)); $ADMIN->add('webservicesettings', $temp); /// links to protocol pages $webservices_available = get_plugin_list('webservice'); diff --git a/admin/webservice/forms.php b/admin/webservice/forms.php index 6296a917a75..377d8cfa725 100644 --- a/admin/webservice/forms.php +++ b/admin/webservice/forms.php @@ -66,6 +66,7 @@ class external_service_form extends moodleform { $mform->addElement('advcheckbox', 'enabled', get_string('enabled', 'webservice')); $mform->addElement('advcheckbox', 'restrictedusers', get_string('restrictedusers', 'webservice')); + $mform->addHelpButton('restrictedusers', 'restrictedusers', 'webservice'); /// needed to select automatically the 'No required capability" option $currentcapabilityexist = false; diff --git a/lang/en/admin.php b/lang/en/admin.php index 5731813def6..e182f0009d2 100755 --- a/lang/en/admin.php +++ b/lang/en/admin.php @@ -203,7 +203,7 @@ $string['configenablesafebrowserintegration'] = 'This adds the choice \'Require $string['configenablestats'] = 'If you choose \'yes\' here, Moodle\'s cronjob will process the logs and gather some statistics. Depending on the amount of traffic on your site, this can take awhile. If you enable this, you will be able to see some interesting graphs and statistics about each of your courses, or on a sitewide basis.'; $string['configenabletrusttext'] = 'By default Moodle will always thoroughly clean text that comes from users to remove any possible bad scripts, media etc that could be a security risk. The Trusted Content system is a way of giving particular users that you trust the ability to include these advanced features in their content without interference. To enable this system, you need to first enable this setting, and then grant the Trusted Content permission to a specific Moodle role. Texts created or uploaded by such users will be marked as trusted and will not be cleaned before display.'; $string['configenablewebservices'] = 'Web services enable other systems to log in to this Moodle and perform operations. For extra security this feature should be disabled unless you are really using it.'; -$string['configenablewsdocumentation'] = 'Enable auto-generation of web services documentation. A web service user can access to his own {$a} without login into Moodle. It display the documentation for the enabled protocols only.'; +$string['configenablewsdocumentation'] = 'Enable auto-generation of web services documentation. A user can access to his own documentation on his security keys page {$a}. It displays the documentation for the enabled protocols only.'; $string['configerrorlevel'] = 'Choose the amount of PHP warnings that you want to be displayed. Normal is usually the best choice.'; $string['configexcludeoldflashclients'] = 'Some versions of the Adobe Flash plugin are known to be vulnerable to attacks from malicious Flash content. You can specify a minimum supported version here, and Moodle will not show Flash files to users with lower versions. Instead they will see an alternate Flash file telling them how to upgrade. Leave this empty to disable all checks.'; $string['configexperimentalsplitrestore'] = 'If enabled, course backup files will be checked for XML errors and split into smaller parts for use in the restore process. This will result in improvements to restore robustness and execution times, particularly for medium to large course backups.'; diff --git a/lang/en/webservice.php b/lang/en/webservice.php index 3b23b378809..7d3fd227d70 100644 --- a/lang/en/webservice.php +++ b/lang/en/webservice.php @@ -57,6 +57,8 @@ $string['deleteservice'] = 'Delete the service: {$a->name} (id: {$a->id})'; $string['deleteserviceconfirm'] = 'Deleting a service will also delete the tokens related to this service. Do you really want to delete external service "{$a}"?'; $string['deletetokenconfirm'] = 'Do you really want to delete this web service token for {$a->user} on the service {$a->service}?'; $string['disabledwarning'] = 'All web service protocols are disabled. The "Enable web services" setting can be found in Advanced features.'; +$string['doc'] = 'Documentation'; +$string['docaccessrefused'] = 'You are not allowed to see the documentation for this token'; $string['documentation'] = 'web service documentation'; $string['editaservice'] = 'Edit service'; $string['editservice'] = 'Edit the service: {$a->name} (id: {$a->id})'; @@ -111,7 +113,7 @@ $string['manageprotocols'] = 'Manage protocols'; $string['managetokens'] = 'Manage tokens'; $string['missingcaps'] = 'Missing capabilities.'; $string['missingcaps_help'] = 'List of capabilities that the service functions require but that the user hasn\'t. You need to add these capabilities to this user in order to use the service. -

Note: in rare case some of these "required" capabilities could depend of a function use case. For example \'moodle_role_get_enrolled_users\' function requires \'moodle/site:viewparticipants\' capability only for a site-wide request.'; +Note: in some cases, some of these "required" capabilities could depend of a use case. For example: moodle_role_get_enrolled_users() function requires \'moodle/site:viewparticipants\' capability only for a site-wide request.'; $string['missingpassword'] = 'Missing password'; $string['missingusername'] = 'Missing username'; $string['nofunctions'] = 'This service has no functions.'; @@ -142,6 +144,8 @@ $string['restcode'] = 'REST'; $string['restexception'] = 'REST'; $string['restparam'] = 'REST (POST parameters)'; $string['restrictedusers'] = 'Authorised users only'; +$string['restrictedusers_help'] = 'If this settings is disabled, any users with the \'moodle/webservice:createtoken\' capability will be able to generate a token for this service in their \'Security keys\' page. +If this settings is enabled, you will choose which users can access this service. These users still need the \'moodle/webservice:createtoken\' capability to generate their own token in their \'Security keys\' page.'; $string['securitykey'] = 'Security key (token)'; $string['securitykeys'] = 'Security keys'; $string['selectauthorisedusers'] = 'Select authorised users'; @@ -188,7 +192,7 @@ $string['wsauthnotenabled'] = 'The web service authentication plugin is disabled $string['wsclientdoc'] = 'Moodle web service client documentation'; $string['wsdocumentation'] = 'Web service documentation'; $string['wsdocumentationdisable'] = 'Web service documentation is disabled.'; -$string['wsdocumentationintro'] = 'Following is a listing of web service functions available for the username {$a->username}.
To create a client we advise you to read the {$a->doclink}'; +$string['wsdocumentationintro'] = 'To create a client we advise you to read the {$a->doclink}'; $string['wsdocumentationlogin'] = 'or enter your web service username and password:'; $string['wspassword'] = 'Web service password'; $string['wsusername'] = 'Web service username'; diff --git a/user/managetoken.php b/user/managetoken.php index 21dd70d701b..46cb3330173 100644 --- a/user/managetoken.php +++ b/user/managetoken.php @@ -35,14 +35,13 @@ $PAGE->set_context($usercontext); $PAGE->set_url('/user/managetoken.php'); $PAGE->set_title(get_string('securitykeys', 'webservice')); $PAGE->set_heading(get_string('securitykeys', 'webservice')); -$PAGE->set_context(get_system_context()); $PAGE->set_pagelayout('standard'); $rsstokenboxhtml = $webservicetokenboxhtml = ''; /// Manage user web service tokens if ( !is_siteadmin($USER->id) && !empty($CFG->enablewebservices) - && has_capability('moodle/webservice:createtoken', get_system_context() )) { + && has_capability('moodle/webservice:createtoken', $usercontext )) { require($CFG->dirroot.'/webservice/lib.php'); $action = optional_param('action', '', PARAM_ACTION); @@ -67,7 +66,8 @@ if ( !is_siteadmin($USER->id) if (empty($resetconfirmation)) { $webservice->generate_user_ws_tokens($USER->id); //generate all token that need to be generated $tokens = $webservice->get_user_ws_tokens($USER->id); - $webservicetokenboxhtml = $wsrenderer->user_webservice_tokens_box($tokens, $USER->id); //display the box for web service token + $webservicetokenboxhtml = $wsrenderer->user_webservice_tokens_box($tokens, $USER->id, + $CFG->enablewsdocumentation); //display the box for web service token } } diff --git a/webservice/lib.php b/webservice/lib.php index f14f5aac39e..1b4f9f002e5 100644 --- a/webservice/lib.php +++ b/webservice/lib.php @@ -213,6 +213,16 @@ class webservice { return $token; } + /** + * Return a token for a given id + * @param integer $tokenid + * @return object token + */ + public function get_token_by_id($tokenid) { + global $DB; + return $DB->get_record('external_tokens', array('id' => $tokenid)); + } + /** * Delete a user token * @param int $tokenid diff --git a/webservice/renderer.php b/webservice/renderer.php index 0ea62894bc9..9b214528bb6 100644 --- a/webservice/renderer.php +++ b/webservice/renderer.php @@ -174,7 +174,7 @@ class core_webservice_renderer extends plugin_renderer_base { get_string('cancel'), 'get'); return $this->output->confirm(get_string('deletetokenconfirm', 'webservice', (object) array('user' => $token->firstname . " " - . $token->lastname, 'service' => $token->name)), + . $token->lastname, 'service' => $token->name)), $formcontinue, $formcancel); } @@ -257,7 +257,7 @@ class core_webservice_renderer extends plugin_renderer_base { get_string('cancel'), 'get'); $html = $this->output->confirm(get_string('resettokenconfirm', 'webservice', (object) array('user' => $token->firstname . " " . - $token->lastname, 'service' => $token->name)), + $token->lastname, 'service' => $token->name)), $formcontinue, $formcancel); return $html; } @@ -268,7 +268,7 @@ class core_webservice_renderer extends plugin_renderer_base { * @param int $userid * @return string html code */ - public function user_webservice_tokens_box($tokens, $userid) { + public function user_webservice_tokens_box($tokens, $userid, $documentation = false) { global $CFG; // display strings @@ -290,9 +290,13 @@ class core_webservice_renderer extends plugin_renderer_base { $table->width = '100%'; $table->data = array(); + if ($documentation) { + $table->head[] = get_string('doc', 'webservice'); + $table->align[] = 'center'; + } + if (!empty($tokens)) { foreach ($tokens as $token) { - //TODO: retrieve context if ($token->creatorid == $userid) { $reset = "wwwroot . "/user/managetoken.php?sesskey=" @@ -300,7 +304,7 @@ class core_webservice_renderer extends plugin_renderer_base { $reset .= get_string('reset') . ""; $creator = $token->firstname . " " . $token->lastname; } else { - //retrive administrator name + //retrieve administrator name require_once($CFG->dirroot . '/user/lib.php'); $creators = user_get_users_by_id(array($token->creatorid)); $admincreator = $creators[$token->creatorid]; @@ -318,7 +322,16 @@ class core_webservice_renderer extends plugin_renderer_base { $validuntil = date("F j, Y"); //TODO: language support (look for moodle function) } - $table->data[] = array($token->token, $token->name, $validuntil, $creatoratag, $reset); + $row = array($token->token, $token->name, $validuntil, $creatoratag, $reset); + + if ($documentation) { + $doclink = new moodle_url('/webservice/wsdoc.php', + array('id' => $token->id, 'sesskey' => sesskey())); + $row[] = html_writer::tag('a', get_string('doc', 'webservice'), + array('href' => $doclink)); + } + + $table->data[] = $row; } $return .= html_writer::table($table); } else { @@ -521,7 +534,7 @@ EOF; */ public function colored_box_with_pre_tag($title, $content, $rgb = 'FEEBE5') { //TODO: this tag removes xhtml strict error but cause warning - $coloredbox = html_writer::start_tag('ins', array()); + $coloredbox = html_writer::start_tag('ins', array()); $coloredbox .= html_writer::start_tag('div', array('style' => "border:solid 1px #DEDEDE;background:#" . $rgb . ";color:#222222;padding:4px;")); @@ -584,12 +597,15 @@ EOF; /** * This display all the documentation * @param array $functions contains all decription objects - * @param array $authparam keys are either 'username'/'password' or 'token' + * @param array $authparam keys contains 'tokenid' * @param boolean $printableformat true if we want to display the documentation in a printable format * @param array $activatedprotocol * @return string the html to diplay */ public function documentation_html($functions, $printableformat, $activatedprotocol, $authparams) { + + $documentationhtml = $this->output->heading(get_string('documentation', 'webservice')); + $br = html_writer::empty_tag('br', array()); $brakeline = <<username = $authparams['wsusername']; $docurl = new moodle_url('http://docs.moodle.org/en/Development:Creating_a_web_service_client'); $docinfo->doclink = html_writer::tag('a', get_string('wsclientdoc', 'webservice'), array('href' => $docurl)); - $documentationhtml = html_writer::start_tag('table', + $documentationhtml .= html_writer::start_tag('table', array('style' => "margin-left:auto; margin-right:auto;")); $documentationhtml .= html_writer::start_tag('tr', array()); $documentationhtml .= html_writer::start_tag('td', array()); @@ -778,50 +793,4 @@ EOF; return $documentationhtml; } - /** - * Return the login page html - * @param string $errormessage - the error message to display - * @return string the html to diplay - */ - public function login_page_html($errormessage) { - $br = html_writer::empty_tag('br', array()); - - $htmlloginpage = html_writer::start_tag('table', - array('style' => "margin-left:auto; margin-right:auto;")); - $htmlloginpage .= html_writer::start_tag('tr', array()); - $htmlloginpage .= html_writer::start_tag('td', array()); - - //login form - we cannot use moodle form as we don't have sessionkey - $target = new moodle_url('/webservice/wsdoc.php', array()); // Required - - $contents = get_string('entertoken', 'webservice'); - $contents .= $br . $br; - $contents .= html_writer::empty_tag('input', - array('type' => 'text', 'name' => 'token', 'style' => 'width: 30em;')); - - $contents .= $br . $br; - $contents .= get_string('wsdocumentationlogin', 'webservice'); - $contents .= $br . $br; - $contents .= html_writer::empty_tag('input', - array('type' => 'text', 'name' => 'wsusername', 'style' => 'width: 30em;', - 'value' => get_string('wsusername', 'webservice'))); - $contents .= $br . $br; - $contents .= html_writer::empty_tag('input', - array('type' => 'text', 'name' => 'wspassword', 'style' => 'width: 30em;', - 'value' => get_string('wspassword', 'webservice'))); - $contents .= $br . $br; - $contents .= html_writer::empty_tag('input', - array('type' => 'submit', 'name' => 'submit', - 'value' => get_string('wsdocumentation', 'webservice'))); - - $htmlloginpage .= html_writer::tag('form', "
$contents
", - array('method' => 'post', 'target' => $target)); - - $htmlloginpage .= html_writer::end_tag('td'); - $htmlloginpage .= html_writer::end_tag('tr'); - $htmlloginpage .= html_writer::end_tag('table'); - - return $htmlloginpage; - } - } diff --git a/webservice/wsdoc.php b/webservice/wsdoc.php index befcf0a5c78..db80f7a9456 100644 --- a/webservice/wsdoc.php +++ b/webservice/wsdoc.php @@ -1,4 +1,5 @@ dirroot . '/webservice/lib.php'); +require_login(); +require_sesskey(); -/** - * This class generate the web service documentation specific to one - * web service user - * @package webservice - * @copyright 2009 Moodle Pty Ltd (http://moodle.com) - * @author Jerome Mouneyrac - * @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later - */ -class webservice_documentation_generator { +$usercontext = get_context_instance(CONTEXT_USER, $USER->id); +$tokenid = required_param('id', PARAM_INT); - /** @property array all external function description*/ - protected $functions; +//PAGE settings +$PAGE->set_context($usercontext); +$PAGE->set_url('/user/wsdoc.php'); +$PAGE->set_title(get_string('documentation', 'webservice')); +$PAGE->set_heading(get_string('documentation', 'webservice')); +$PAGE->set_pagelayout('standard'); - /** @property string $username name of local user */ - protected $username = null; - - /** @property string $password password of the local user */ - protected $password = null; - - /** @property string $token token of the local user */ - protected $token = null; - - /** @property object $webserviceuser authenticated web service user */ - protected $webserviceuser = null; - - /** - * Contructor - */ - public function __construct() { - $this->functionsdescriptions = array(); - $this->functions = array(); - } - - /** - * Run the documentation generation - * @return void - */ - public function run() { - - // init all properties from the request data - $this->get_authentication_parameters(); - - // this sets up $this->webserviceuser - try { - $this->authenticate_user(); - } catch(moodle_exception $e) { - $errormessage = $e->debuginfo; - $displayloginpage = true; - } - - if (!empty($displayloginpage)){ - $this->display_login_page_html($errormessage); - } else { - // make a descriptions list of all function that user is allowed to excecute - $this->generate_documentation(); - - //finally display the documentation - $this->display_documentation_html(); - } - - die; - } - - -/////////////////////////// -/////// CLASS METHODS ///// -/////////////////////////// - - /** - * This method parses the $_REQUEST superglobal and looks for - * the following information: - * user authentication - username+password - * @return void - */ - protected function get_authentication_parameters() { - if (isset($_REQUEST['wsusername'])) { - $this->username = $_REQUEST['wsusername']; - } - if (isset($_REQUEST['wspassword'])) { - $this->password = $_REQUEST['wspassword']; - } - if (isset($_REQUEST['token'])) { - $this->token = $_REQUEST['token']; - } - } - - /** - * Generate the documentation specific to the auhenticated webservice user - * @return void - */ - protected function generate_documentation() { - global $DB; - - /// first of all get a complete list of services user is allowed to access - $params = array(); - $wscond1 = ''; - $wscond2 = ''; - - // make sure the function is listed in at least one service user is allowed to use - // allow access only if: - // 1/ entry in the external_services_users table if required - // 2/ validuntil not reached - // 3/ has capability if specified in service desc - // 4/ iprestriction - - $sql = "SELECT s.*, NULL AS iprestriction - FROM {external_services} s - JOIN {external_services_functions} sf ON (sf.externalserviceid = s.id AND s.restrictedusers = 0) - WHERE s.enabled = 1 $wscond1 - - UNION - - SELECT s.*, su.iprestriction - FROM {external_services} s - JOIN {external_services_functions} sf ON (sf.externalserviceid = s.id AND s.restrictedusers = 1) - JOIN {external_services_users} su ON (su.externalserviceid = s.id AND su.userid = :userid) - WHERE s.enabled = 1 AND su.validuntil IS NULL OR su.validuntil < :now $wscond2"; - - $params = array_merge($params, array('userid'=>$this->webserviceuser->id, 'now'=>time())); - - $serviceids = array(); - $rs = $DB->get_recordset_sql($sql, $params); - - // make sure user may access at least one service - $allowed = false; - foreach ($rs as $service) { - if (isset($serviceids[$service->id])) { - continue; - } - if ($service->requiredcapability and !has_capability($service->requiredcapability, $this->restricted_context)) { - continue; // cap required, sorry - } - $serviceids[$service->id] = $service->id; - } - $rs->close(); - - // now get the list of all functions - if ($serviceids) { - list($serviceids, $params) = $DB->get_in_or_equal($serviceids); - $sql = "SELECT f.* - FROM {external_functions} f - WHERE f.name IN (SELECT sf.functionname - FROM {external_services_functions} sf - WHERE sf.externalserviceid $serviceids)"; - $functions = $DB->get_records_sql($sql, $params); - } else { - $functions = array(); - } - - foreach ($functions as $function) { - $this->functions[$function->name] = external_function_info($function); - } - } - - /** - * Authenticate user using username+password - * This function sets up $this->webserviceuser. - * called into the Moodle header - * @return void - */ - protected function authenticate_user() { - global $CFG, $DB; - - if (!NO_MOODLE_COOKIES) { - throw new coding_exception('Cookies must be disabled!'); - } - - if (!$this->token) { - if (!is_enabled_auth('webservice')) { - throw new webservice_access_exception(get_string('wsauthnotenabled', 'webservice')); - } - - if (!$auth = get_auth_plugin('webservice')) { - throw new webservice_access_exception(get_string('wsauthmissing', 'webservice')); - } - - if (!$this->username) { - throw new webservice_access_exception(get_string('missingusername', 'webservice')); - } - - if (!$this->password) { - throw new webservice_access_exception(get_string('missingpassword', 'webservice')); - } - - if (!$auth->user_login_webservice($this->username, $this->password)) { - throw new webservice_access_exception(get_string('wrongusernamepassword', 'webservice')); - } - - $this->webserviceuser = $DB->get_record('user', array('username'=>$this->username, 'mnethostid'=>$CFG->mnet_localhost_id, 'deleted'=>0), '*', MUST_EXIST); - } else { - - if (!$token = $DB->get_record('external_tokens', array('token'=>$this->token, 'tokentype'=>EXTERNAL_TOKEN_PERMANENT))) { - // log failed login attempts - throw new webservice_access_exception(get_string('invalidtoken', 'webservice')); - } - - if ($token->validuntil and $token->validuntil < time()) { - throw new webservice_access_exception(get_string('invalidtimedtoken', 'webservice')); - } - - if ($token->iprestriction and !address_in_subnet(getremoteaddr(), $token->iprestriction)) { - throw new webservice_access_exception(get_string('invalidiptoken', 'webservice')); - } - - $this->webserviceuser = $DB->get_record('user', array('id'=>$token->userid, 'deleted'=>0), '*', MUST_EXIST); - - // log token access - $DB->set_field('external_tokens', 'lastaccess', time(), array('id'=>$token->id)); - } - - - - } - -//////////////////////////////////////////////// -///// DISPLAY METHODS ///// -//////////////////////////////////////////////// - - /** - * Generate and display the documentation - */ - protected function display_documentation_html() { - global $PAGE, $OUTPUT, $SITE, $CFG; - - $PAGE->set_context(get_context_instance(CONTEXT_SYSTEM)); - $PAGE->set_url('/webservice/wsdoc'); - $PAGE->set_docs_path(''); - $PAGE->set_title($SITE->fullname." ".get_string('wsdocumentation', 'webservice')); - $PAGE->set_heading($SITE->fullname." ".get_string('wsdocumentation', 'webservice')); - $PAGE->set_pagelayout('popup'); - $PAGE->set_pagetype('webservice-doc-generator'); - - echo $OUTPUT->header(); - - $activatedprotocol = array(); - $activatedprotocol['rest'] = webservice_protocol_is_enabled('rest'); - $activatedprotocol['xmlrpc'] = webservice_protocol_is_enabled('xmlrpc'); - $renderer = $PAGE->get_renderer('core', 'webservice'); - /// Check if we are in printable mode - $printableformat = false; - if (isset($_REQUEST['print'])) { - $printableformat = $_REQUEST['print']; - } - - $authparams = array(); - if (empty($this->token)) { - $authparams['wsusername'] = $this->username; - $authparams['wspassword'] = $this->password; - } else { - $authparams['wsusername'] = $this->webserviceuser->username; - $authparams['token'] = $this->token; - } - - echo $renderer->documentation_html($this->functions, $printableformat, $activatedprotocol, $authparams); - - /// trigger browser print operation - if (!empty($printableformat)) { - $PAGE->requires->js_function_call('window.print', array()); - } - - echo $OUTPUT->footer(); - - } - - /** - * Display login page to the web service documentation - * @global object $PAGE - * @global object $OUTPUT - * @global object $SITE - * @global object $CFG - * @param string $errormessage error message displayed if wrong login - */ - protected function display_login_page_html($errormessage) { - global $PAGE, $OUTPUT, $SITE, $CFG; - - $PAGE->set_context(get_context_instance(CONTEXT_SYSTEM)); - $PAGE->set_url('/webservice/wsdoc'); - $PAGE->set_docs_path(''); - $PAGE->set_title($SITE->fullname." ".get_string('wsdocumentation', 'webservice')); - $PAGE->set_heading($SITE->fullname." ".get_string('wsdocumentation', 'webservice')); - $PAGE->set_pagelayout('popup'); - $PAGE->set_pagetype('webservice-doc-generator-login'); - - echo $OUTPUT->header(); - - $renderer = $PAGE->get_renderer('core', 'webservice'); - echo $renderer->login_page_html($errormessage); - - echo $OUTPUT->footer(); - - } - -} - - -/////////////////////////// -/////// RUN THE SCRIPT //// -/////////////////////////// +//nav bar +$PAGE->navbar->ignore_active(true); +$PAGE->navbar->add(get_string('usercurrentsettings')); +$PAGE->navbar->add(get_string('securitykeys', 'webservice'), + new moodle_url('/user/managetoken.php', + array('id' => $tokenid, 'sesskey' => sesskey()))); +$PAGE->navbar->add(get_string('documentation', 'webservice')); +//check web service are enabled if (empty($CFG->enablewsdocumentation)) { echo get_string('wsdocumentationdisable', 'webservice'); die; } -//run the documentation generator -$generator = new webservice_documentation_generator(); -$generator->run(); -die; +//check that the current user is the token user +$webservice = new webservice(); +$token = $webservice->get_token_by_id($tokenid); +if (empty($token) or empty($token->userid) or empty($USER->id) + or ($token->userid != $USER->id)) { + throw new moodle_exception('docaccessrefused', 'webservice'); +} + +// get the list of all functions related to the token +$functions = $webservice->get_external_functions(array($token->externalserviceid)); + +// get all the function descriptions +$functiondescs = array(); +foreach ($functions as $function) { + $functiondescs[$function->name] = external_function_info($function); +} + +//get activated protocol +$activatedprotocol = array(); +$activatedprotocol['rest'] = webservice_protocol_is_enabled('rest'); +$activatedprotocol['xmlrpc'] = webservice_protocol_is_enabled('xmlrpc'); + +/// Check if we are in printable mode +$printableformat = false; +if (isset($_REQUEST['print'])) { + $printableformat = $_REQUEST['print']; +} + +/// OUTPUT +echo $OUTPUT->header(); + +$renderer = $PAGE->get_renderer('core', 'webservice'); +echo $renderer->documentation_html($functiondescs, + $printableformat, $activatedprotocol, array('id' => $tokenid)); + +/// trigger browser print operation +if (!empty($printableformat)) { + $PAGE->requires->js_function_call('window.print', array()); +} + +echo $OUTPUT->footer();