aboutsummaryrefslogtreecommitdiff
path: root/app/Controllers/apiController.php
diff options
context:
space:
mode:
authorGravatar Marien Fressinaud <dev@marienfressinaud.fr> 2019-12-18 09:26:17 +0100
committerGravatar Marien Fressinaud <dev@marienfressinaud.fr> 2019-12-18 09:26:17 +0100
commit2b1f8e67f76672a5b1b0a1b0403d81dbee364c58 (patch)
treeab3142289e260111c686e740b9f4214453a0a84c /app/Controllers/apiController.php
parent90c7292326538522a5df97b3f0a847b8a28f759f (diff)
parent82851d2039f619f1b2558e06b04a9e47fceeea54 (diff)
Merge branch 'dev'
This is the end of the `dev` branch. Good bye old friend!
Diffstat (limited to 'app/Controllers/apiController.php')
-rw-r--r--app/Controllers/apiController.php47
1 files changed, 47 insertions, 0 deletions
diff --git a/app/Controllers/apiController.php b/app/Controllers/apiController.php
new file mode 100644
index 000000000..d096ba83f
--- /dev/null
+++ b/app/Controllers/apiController.php
@@ -0,0 +1,47 @@
+<?php
+
+/**
+ * This controller manage API-related features.
+ */
+class FreshRSS_api_Controller extends Minz_ActionController {
+ /**
+ * This action updates the user API password.
+ *
+ * Parameter is:
+ * - apiPasswordPlain: the new user password
+ */
+ public function updatePasswordAction() {
+ if (!FreshRSS_Auth::hasAccess()) {
+ Minz_Error::error(403);
+ }
+
+ $return_url = array('c' => 'user', 'a' => 'profile');
+
+ if (!Minz_Request::isPost()) {
+ Minz_Request::forward($return_url, true);
+ }
+
+ $apiPasswordPlain = Minz_Request::param('apiPasswordPlain', '', true);
+ if ($apiPasswordPlain == '') {
+ Minz_Request::forward($return_url, true);
+ }
+
+ $username = Minz_Session::param('currentUser');
+ $userConfig = FreshRSS_Context::$user_conf;
+
+ $apiPasswordHash = FreshRSS_password_Util::hash($apiPasswordPlain);
+ $userConfig->apiPasswordHash = $apiPasswordHash;
+
+ $feverKey = FreshRSS_fever_Util::updateKey($username, $apiPasswordPlain);
+ if (!$feverKey) {
+ Minz_Request::bad(_t('feedback.api.password.failed'), $return_url);
+ }
+
+ $userConfig->feverKey = $feverKey;
+ if ($userConfig->save()) {
+ Minz_Request::good(_t('feedback.api.password.updated'), $return_url);
+ } else {
+ Minz_Request::bad(_t('feedback.api.password.failed'), $return_url);
+ }
+ }
+}