oauth.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377
  1. <?php
  2. /* Copyright (C) 2015 Frederic France <frederic.france@free.fr>
  3. * Copyright (C) 2016 Raphaël Doursenaud <rdoursenaud@gpcsolutions.fr>
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation; either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. *
  18. */
  19. /**
  20. * \file htdocs/admin/oauth.php
  21. * \ingroup oauth
  22. * \brief Setup page to configure oauth access api
  23. */
  24. require '../main.inc.php';
  25. // required Class
  26. require_once DOL_DOCUMENT_ROOT.'/core/lib/admin.lib.php';
  27. // Define $urlwithroot
  28. $urlwithouturlroot=preg_replace('/'.preg_quote(DOL_URL_ROOT,'/').'$/i','',trim($dolibarr_main_url_root));
  29. $urlwithroot=$urlwithouturlroot.DOL_URL_ROOT; // This is to use external domain name found into config file
  30. //$urlwithroot=DOL_MAIN_URL_ROOT; // This is to use same domain name than current
  31. $langs->load("admin");
  32. $langs->load("oauth");
  33. // Security check
  34. if (!$user->admin)
  35. accessforbidden();
  36. $action = GETPOST('action', 'alpha');
  37. // Supported OAUTH (a provider is supported when a file xxx_oauthcallback.php is available into htdocs/core/modules/oauth)
  38. $supportedoauth2array=array('OAUTH_GOOGLE_NAME'=>'google');
  39. // API access parameters OAUTH
  40. $list = array (
  41. array(
  42. 'OAUTH_AMAZON_NAME',
  43. 'OAUTH_AMAZON_ID',
  44. 'OAUTH_AMAZON_SECRET',
  45. ),
  46. array(
  47. 'OAUTH_BITBUCKET_NAME',
  48. 'OAUTH_BITBUCKET_ID',
  49. 'OAUTH_BITBUCKET_SECRET',
  50. ),
  51. array(
  52. 'OAUTH_BITLY_NAME',
  53. 'OAUTH_BITLY_ID',
  54. 'OAUTH_BITLY_SECRET',
  55. ),
  56. array(
  57. 'OAUTH_BITRIX24_NAME',
  58. 'OAUTH_BITRIX24_ID',
  59. 'OAUTH_BITRIX24_SECRET',
  60. ),
  61. array(
  62. 'OAUTH_BOX_NAME',
  63. 'OAUTH_BOX_ID',
  64. 'OAUTH_BOX_SECRET',
  65. ),
  66. array(
  67. 'OAUTH_BUFFER_NAME',
  68. 'OAUTH_BUFFER_ID',
  69. 'OAUTH_BUFFER_SECRET',
  70. ),
  71. array(
  72. 'OAUTH_DAILYMOTION_NAME',
  73. 'OAUTH_DAILYMOTION_ID',
  74. 'OAUTH_DAILYMOTION_SECRET',
  75. ),
  76. array(
  77. 'OAUTH_DEVIANTART_NAME',
  78. 'OAUTH_DEVIANTART_ID',
  79. 'OAUTH_DEVIANTART_SECRET',
  80. ),
  81. array(
  82. 'OAUTH_DROPBOX_NAME',
  83. 'OAUTH_DROPBOX_ID',
  84. 'OAUTH_DROPBOX_SECRET',
  85. ),
  86. array(
  87. 'OAUTH_ETSY_NAME',
  88. 'OAUTH_ETSY_ID',
  89. 'OAUTH_ETSY_SECRET',
  90. ),
  91. array(
  92. 'OAUTH_EVEONLINE_NAME',
  93. 'OAUTH_EVEONLINE_ID',
  94. 'OAUTH_EVEONLINE_SECRET',
  95. ),
  96. array(
  97. 'OAUTH_FACEBOOK_NAME',
  98. 'OAUTH_FACEBOOK_ID',
  99. 'OAUTH_FACEBOOK_SECRET',
  100. ),
  101. array(
  102. 'OAUTH_FITBIT_NAME',
  103. 'OAUTH_FITBIT_ID',
  104. 'OAUTH_FITBIT_SECRET',
  105. ),
  106. array(
  107. 'OAUTH_FIVEHUNDREDPX_NAME',
  108. 'OAUTH_FIVEHUNDREDPX_ID',
  109. 'OAUTH_FIVEHUNDREDPX_SECRET',
  110. ),
  111. array(
  112. 'OAUTH_FLICKR_NAME',
  113. 'OAUTH_FLICKR_ID',
  114. 'OAUTH_FLICKR_SECRET',
  115. ),
  116. array(
  117. 'OAUTH_FOURSQUARE_NAME',
  118. 'OAUTH_FOURSQUARE_ID',
  119. 'OAUTH_FOURSQUARE_SECRET',
  120. ),
  121. array(
  122. 'OAUTH_GITHUB_NAME',
  123. 'OAUTH_GITHUB_ID',
  124. 'OAUTH_GITHUB_SECRET',
  125. ),
  126. array(
  127. 'OAUTH_GOOGLE_NAME',
  128. 'OAUTH_GOOGLE_ID',
  129. 'OAUTH_GOOGLE_SECRET',
  130. 'OAUTH_GOOGLE_DESC',
  131. ),
  132. array(
  133. 'OAUTH_HUBIC_NAME',
  134. 'OAUTH_HUBIC_ID',
  135. 'OAUTH_HUBIC_SECRET',
  136. ),
  137. array(
  138. 'OAUTH_INSTAGRAM_NAME',
  139. 'OAUTH_INSTAGRAM_ID',
  140. 'OAUTH_INSTAGRAM_SECRET',
  141. ),
  142. array(
  143. 'OAUTH_LINKEDIN_NAME',
  144. 'OAUTH_LINKEDIN_ID',
  145. 'OAUTH_LINKEDIN_SECRET',
  146. ),
  147. array(
  148. 'OAUTH_MAILCHIMP_NAME',
  149. 'OAUTH_MAILCHIMP_ID',
  150. 'OAUTH_MAILCHIMP_SECRET',
  151. ),
  152. array(
  153. 'OAUTH_MICROSOFT_NAME',
  154. 'OAUTH_MICROSOFT_ID',
  155. 'OAUTH_MICROSOFT_SECRET',
  156. ),
  157. array(
  158. 'OAUTH_NEST_NAME',
  159. 'OAUTH_NEST_ID',
  160. 'OAUTH_NEST_SECRET',
  161. ),
  162. array(
  163. 'OAUTH_NETATMO_NAME',
  164. 'OAUTH_NETATMO_ID',
  165. 'OAUTH_NETATMO_SECRET',
  166. ),
  167. array(
  168. 'OAUTH_PARROTFLOWERPOWER_NAME',
  169. 'OAUTH_PARROTFLOWERPOWER_ID',
  170. 'OAUTH_PARROTFLOWERPOWER_SECRET',
  171. ),
  172. array(
  173. 'OAUTH_PAYPAL_NAME',
  174. 'OAUTH_PAYPAL_ID',
  175. 'OAUTH_PAYPAL_SECRET',
  176. ),
  177. array(
  178. 'OAUTH_POCKET_NAME',
  179. 'OAUTH_POCKET_ID',
  180. 'OAUTH_POCKET_SECRET',
  181. ),
  182. array(
  183. 'OAUTH_QUICKBOOKS_NAME',
  184. 'OAUTH_QUICKBOOKS_ID',
  185. 'OAUTH_QUICKBOOKS_SECRET',
  186. ),
  187. array(
  188. 'OAUTH_REDDIT_NAME',
  189. 'OAUTH_REDDIT_ID',
  190. 'OAUTH_REDDIT_SECRET',
  191. ),
  192. array(
  193. 'OAUTH_REDMINE_NAME',
  194. 'OAUTH_REDMINE_ID',
  195. 'OAUTH_REDMINE_SECRET',
  196. ),
  197. array(
  198. 'OAUTH_RUNKEEPER_NAME',
  199. 'OAUTH_RUNKEEPER_ID',
  200. 'OAUTH_RUNKEEPER_SECRET',
  201. ),
  202. array(
  203. 'OAUTH_SCOOPIT_NAME',
  204. 'OAUTH_SCOOPIT_ID',
  205. 'OAUTH_SCOOPIT_SECRET',
  206. ),
  207. array(
  208. 'OAUTH_SOUNDCLOUD_NAME',
  209. 'OAUTH_SOUNDCLOUD_ID',
  210. 'OAUTH_SOUNDCLOUD_SECRET',
  211. ),
  212. array(
  213. 'OAUTH_SPOTIFY_NAME',
  214. 'OAUTH_SPOTIFY_ID',
  215. 'OAUTH_SPOTIFY_SECRET',
  216. ),
  217. array(
  218. 'OAUTH_STRAVA_NAME',
  219. 'OAUTH_STRAVA_ID',
  220. 'OAUTH_STRAVA_SECRET',
  221. ),
  222. array(
  223. 'OAUTH_TUMBLR_NAME',
  224. 'OAUTH_TUMBLR_ID',
  225. 'OAUTH_TUMBLR_SECRET',
  226. ),
  227. array(
  228. 'OAUTH_TWITTER_NAME',
  229. 'OAUTH_TWITTER_ID',
  230. 'OAUTH_TWITTER_SECRET',
  231. ),
  232. array(
  233. 'OAUTH_USTREAM_NAME',
  234. 'OAUTH_USTREAM_ID',
  235. 'OAUTH_USTREAM_SECRET',
  236. ),
  237. array(
  238. 'OAUTH_VIMEO_NAME',
  239. 'OAUTH_VIMEO_ID',
  240. 'OAUTH_VIMEO_SECRET',
  241. ),
  242. array(
  243. 'OAUTH_YAHOO_NAME',
  244. 'OAUTH_YAHOO_ID',
  245. 'OAUTH_YAHOO_SECRET',
  246. ),
  247. array(
  248. 'OAUTH_YAMMER_NAME',
  249. 'OAUTH_YAMMER_ID',
  250. 'OAUTH_YAMMER_SECRET',
  251. ),
  252. );
  253. /*
  254. * Actions
  255. */
  256. if ($action == 'update')
  257. {
  258. $error = 0;
  259. foreach ($list as $constname) {
  260. $constvalue = GETPOST($constname[1], 'alpha');
  261. if (!dolibarr_set_const($db, $constname[1], $constvalue, 'chaine', 0, '', $conf->entity))
  262. $error++;
  263. $constvalue = GETPOST($constname[2], 'alpha');
  264. if (!dolibarr_set_const($db, $constname[2], $constvalue, 'chaine', 0, '', $conf->entity))
  265. $error++;
  266. }
  267. if (! $error)
  268. {
  269. setEventMessages($langs->trans("SetupSaved"), null);
  270. } else {
  271. setEventMessages($langs->trans("Error"), null, 'errors');
  272. }
  273. }
  274. /*
  275. * View
  276. */
  277. llxHeader();
  278. $form = new Form($db);
  279. $linkback='<a href="'.DOL_URL_ROOT.'/admin/modules.php">'.$langs->trans("BackToModuleList").'</a>';
  280. print load_fiche_titre($langs->trans('ConfigOAuth'),$linkback,'title_setup');
  281. print '<form action="'.$_SERVER["PHP_SELF"].'" method="post">';
  282. print '<input type="hidden" name="token" value="'.$_SESSION['newtoken'].'">';
  283. print '<input type="hidden" name="action" value="update">';
  284. /*
  285. * Parameters
  286. */
  287. dol_fiche_head(array(), '', '', 0, 'technic');
  288. print $langs->trans("ListOfSupportedOauthProviders").'<br><br>';
  289. print '<table class="noborder" width="100%">';
  290. $var = true;
  291. foreach ($list as $key)
  292. {
  293. $supported=0;
  294. if (in_array($key[0], array_keys($supportedoauth2array))) $supported=1;
  295. if (! $supported) continue; // show only supported
  296. print '<tr class="liste_titre">';
  297. // Api Name
  298. $label = $langs->trans($key[0]);
  299. print '<td>'.$label.'</td>';
  300. print '<td>';
  301. if (! empty($key[3])) print $langs->trans($key[3]);
  302. print '</td>';
  303. print '</tr>';
  304. if ($supported)
  305. {
  306. $redirect_uri=$urlwithroot.'/core/modules/oauth/'.$supportedoauth2array[$key[0]].'_oauthcallback.php';
  307. $var = !$var;
  308. print '<tr '.$bc[$var].' class="value">';
  309. print '<td>'.$langs->trans("UseTheFollowingUrlAsRedirectURI").'</td>';
  310. print '<td><input style="width: 80%" type"text" name="uri'.$key[0].'" value="'.$redirect_uri.'">';
  311. print '</td></tr>';
  312. }
  313. else
  314. {
  315. $var = !$var;
  316. print '<tr '.$bc[$var].' class="value">';
  317. print '<td>'.$langs->trans("UseTheFollowingUrlAsRedirectURI").'</td>';
  318. print '<td>'.$langs->trans("FeatureNotYetSupported").'</td>';
  319. print '</td></tr>';
  320. }
  321. // Api Id
  322. $var = !$var;
  323. print '<tr '.$bc[$var].' class="value">';
  324. print '<td><label for="'.$key[1].'">'.$langs->trans($key[1]).'</label></td>';
  325. print '<td><input type="text" size="100" id="'.$key[1].'" name="'.$key[1].'" value="'.$conf->global->{$key[1]}.'">';
  326. print '</td></tr>';
  327. // Api Secret
  328. $var = !$var;
  329. print '<tr '.$bc[$var].' class="value">';
  330. print '<td><label for="'.$key[2].'">'.$langs->trans($key[2]).'</label></td>';
  331. print '<td><input type="password" size="100" id="'.$key[2].'" name="'.$key[2].'" value="'.$conf->global->{$key[2]}.'">';
  332. print '</td></tr>';
  333. }
  334. print '</table>'."\n";
  335. dol_fiche_end();
  336. print '<div class="center"><input type="submit" class="button" value="'.$langs->trans('Modify').'" name="button"></div>';
  337. print '</form>';
  338. llxFooter();
  339. $db->close();