api_zapier.class.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387
  1. <?php
  2. /* Copyright (C) 2015 Jean-François Ferry <jfefe@aternatik.fr>
  3. * Copyright (C) 2019-2020 Frédéric France <frederic.france@netlogic.fr>
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation; either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <https://www.gnu.org/licenses/>.
  17. */
  18. /**
  19. * \file htdocs/zapier/class/api_zapier.class.php
  20. * \ingroup zapier
  21. * \brief File for API management of Zapier hooks.
  22. */
  23. use Luracast\Restler\RestException;
  24. require_once DOL_DOCUMENT_ROOT.'/zapier/class/hook.class.php';
  25. /**
  26. * API class for zapier hook
  27. *
  28. * @access protected
  29. * @class DolibarrApiAccess {@requires user,external}
  30. */
  31. class Zapier extends DolibarrApi
  32. {
  33. /**
  34. * @var array $FIELDS Mandatory fields, checked when create and update object
  35. */
  36. public static $FIELDS = array(
  37. 'url',
  38. );
  39. /**
  40. * @var Hook $hook {@type Hook}
  41. */
  42. public $hook;
  43. /**
  44. * Constructor
  45. *
  46. * @url GET /
  47. *
  48. */
  49. public function __construct()
  50. {
  51. global $db, $conf;
  52. $this->db = $db;
  53. $this->hook = new Hook($this->db);
  54. }
  55. /**
  56. * Get properties of a hook object
  57. *
  58. * Return an array with hook informations
  59. *
  60. * @param int $id ID of hook
  61. * @return Object Object with cleaned properties
  62. *
  63. * @url GET /hooks/{id}
  64. * @throws RestException
  65. */
  66. public function get($id)
  67. {
  68. if (!DolibarrApiAccess::$user->rights->zapier->read) {
  69. throw new RestException(401);
  70. }
  71. $result = $this->hook->fetch($id);
  72. if (!$result) {
  73. throw new RestException(404, 'Hook not found');
  74. }
  75. if (!DolibarrApi::_checkAccessToResource('hook', $this->hook->id)) {
  76. throw new RestException(401, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
  77. }
  78. return $this->_cleanObjectDatas($this->hook);
  79. }
  80. /**
  81. * Get list of possibles choices for module
  82. *
  83. * Return an array with hook informations
  84. *
  85. * @return array data
  86. *
  87. * @url GET /getmoduleschoices/
  88. * @throws RestException
  89. */
  90. public function getModulesChoices()
  91. {
  92. if (!DolibarrApiAccess::$user->rights->zapier->read) {
  93. throw new RestException(401);
  94. }
  95. $arraychoices = array(
  96. 'invoices' => 'Invoices',
  97. 'orders' => 'Orders',
  98. 'thirdparties' => 'Thirparties',
  99. 'contacts' => 'Contacts',
  100. 'users' => 'Users',
  101. );
  102. // $result = $this->hook->fetch($id);
  103. // if (! $result ) {
  104. // throw new RestException(404, 'Hook not found');
  105. // }
  106. // if (! DolibarrApi::_checkAccessToResource('hook', $this->hook->id)) {
  107. // throw new RestException(401, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
  108. // }
  109. return $arraychoices;
  110. }
  111. /**
  112. * List hooks
  113. *
  114. * Get a list of hooks
  115. *
  116. * @param string $sortfield Sort field
  117. * @param string $sortorder Sort order
  118. * @param int $limit Limit for list
  119. * @param int $page Page number
  120. * @param string $sqlfilters Other criteria to filter answers separated by a comma. Syntax example "(t.ref:like:'SO-%') and (t.date_creation:<:'20160101')"
  121. * @param string $properties Restrict the data returned to theses properties. Ignored if empty. Comma separated list of properties names
  122. * @return array Array of order objects
  123. *
  124. * @throws RestException
  125. *
  126. * @url GET /hooks/
  127. */
  128. public function index($sortfield = "t.rowid", $sortorder = 'ASC', $limit = 100, $page = 0, $sqlfilters = '', $properties = '')
  129. {
  130. global $db, $conf;
  131. if (!DolibarrApiAccess::$user->rights->zapier->read) {
  132. throw new RestException(401);
  133. }
  134. $obj_ret = array();
  135. $socid = DolibarrApiAccess::$user->socid ? DolibarrApiAccess::$user->socid : '';
  136. // Set to 1 if there is a field socid in table of object
  137. $restrictonsocid = 0;
  138. // If the internal user must only see his customers, force searching by him
  139. $search_sale = 0;
  140. if ($restrictonsocid && !DolibarrApiAccess::$user->rights->societe->client->voir && !$socid) {
  141. $search_sale = DolibarrApiAccess::$user->id;
  142. }
  143. $sql = "SELECT t.rowid";
  144. if ($restrictonsocid && (!DolibarrApiAccess::$user->rights->societe->client->voir && !$socid) || $search_sale > 0) {
  145. // We need these fields in order to filter by sale (including the case where the user can only see his prospects)
  146. $sql .= ", sc.fk_soc, sc.fk_user";
  147. }
  148. $sql .= " FROM ".MAIN_DB_PREFIX."hook_mytable as t";
  149. if ($restrictonsocid && (!DolibarrApiAccess::$user->rights->societe->client->voir && !$socid) || $search_sale > 0) {
  150. $sql .= ", ".MAIN_DB_PREFIX."societe_commerciaux as sc"; // We need this table joined to the select in order to filter by sale
  151. }
  152. $sql .= " WHERE 1 = 1";
  153. // Example of use $mode
  154. //if ($mode == 1) $sql.= " AND s.client IN (1, 3)";
  155. //if ($mode == 2) $sql.= " AND s.client IN (2, 3)";
  156. $tmpobject = new Hook($this->db);
  157. if ($tmpobject->ismultientitymanaged) {
  158. $sql .= ' AND t.entity IN ('.getEntity('hook').')';
  159. }
  160. if ($restrictonsocid && (!DolibarrApiAccess::$user->rights->societe->client->voir && !$socid) || $search_sale > 0) {
  161. $sql .= " AND t.fk_soc = sc.fk_soc";
  162. }
  163. if ($restrictonsocid && $socid) {
  164. $sql .= " AND t.fk_soc = ".((int) $socid);
  165. }
  166. if ($restrictonsocid && $search_sale > 0) {
  167. // Join for the needed table to filter by sale
  168. $sql .= " AND t.rowid = sc.fk_soc";
  169. }
  170. // Insert sale filter
  171. if ($restrictonsocid && $search_sale > 0) {
  172. $sql .= " AND sc.fk_user = ".((int) $search_sale);
  173. }
  174. if ($sqlfilters) {
  175. $errormessage = '';
  176. $sql .= forgeSQLFromUniversalSearchCriteria($sqlfilters, $errormessage);
  177. if ($errormessage) {
  178. throw new RestException(400, 'Error when validating parameter sqlfilters -> '.$errormessage);
  179. }
  180. }
  181. $sql .= $this->db->order($sortfield, $sortorder);
  182. if ($limit) {
  183. if ($page < 0) {
  184. $page = 0;
  185. }
  186. $offset = $limit * $page;
  187. $sql .= $this->db->plimit($limit + 1, $offset);
  188. }
  189. $result = $this->db->query($sql);
  190. $i = 0;
  191. if ($result) {
  192. $num = $this->db->num_rows($result);
  193. while ($i < $num) {
  194. $obj = $this->db->fetch_object($result);
  195. $hook_static = new Hook($this->db);
  196. if ($hook_static->fetch($obj->rowid)) {
  197. $obj_ret[] = $this->_filterObjectProperties($this->_cleanObjectDatas($hook_static), $properties);
  198. }
  199. $i++;
  200. }
  201. } else {
  202. throw new RestException(503, 'Error when retrieve hook list');
  203. }
  204. return $obj_ret;
  205. }
  206. /**
  207. * Create hook object
  208. *
  209. * @param array $request_data Request datas
  210. * @return array ID of hook
  211. *
  212. * @url POST /hook/
  213. */
  214. public function post($request_data = null)
  215. {
  216. if (!DolibarrApiAccess::$user->rights->zapier->write) {
  217. throw new RestException(401);
  218. }
  219. dol_syslog("API Zapier create hook receive : ".print_r($request_data, true), LOG_DEBUG);
  220. // Check mandatory fields
  221. $fields = array(
  222. 'url',
  223. );
  224. $result = $this->validate($request_data, $fields);
  225. foreach ($request_data as $field => $value) {
  226. if ($field === 'caller') {
  227. // Add a mention of caller so on trigger called after action, we can filter to avoid a loop if we try to sync back again whith the caller
  228. $this->hook->context['caller'] = $request_data['caller'];
  229. continue;
  230. }
  231. $this->hook->$field = $value;
  232. }
  233. $this->hook->fk_user = DolibarrApiAccess::$user->id;
  234. // we create the hook into database
  235. if (!$this->hook->create(DolibarrApiAccess::$user)) {
  236. throw new RestException(500, "Error creating Hook", array_merge(array($this->hook->error), $this->hook->errors));
  237. }
  238. return array(
  239. 'id' => $this->hook->id,
  240. );
  241. }
  242. // /**
  243. // * Update hook
  244. // *
  245. // * @param int $id Id of hook to update
  246. // * @param array $request_data Datas
  247. // * @return int
  248. // *
  249. // * @url PUT /hooks/{id}
  250. // */
  251. /*public function put($id, $request_data = null)
  252. {
  253. if (! DolibarrApiAccess::$user->rights->zapier->write) {
  254. throw new RestException(401);
  255. }
  256. $result = $this->hook->fetch($id);
  257. if( ! $result ) {
  258. throw new RestException(404, 'Hook not found');
  259. }
  260. if( ! DolibarrApi::_checkAccessToResource('hook', $this->hook->id)) {
  261. throw new RestException(401, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
  262. }
  263. foreach($request_data as $field => $value) {
  264. if ($field == 'id') {
  265. continue;
  266. }
  267. $this->hook->$field = $value;
  268. }
  269. if ($this->hook->update($id, DolibarrApiAccess::$user) > 0) {
  270. return $this->get($id);
  271. } else {
  272. throw new RestException(500, $this->hook->error);
  273. }
  274. }*/
  275. /**
  276. * Delete hook
  277. *
  278. * @param int $id Hook ID
  279. * @return array
  280. *
  281. * @url DELETE /hook/{id}
  282. */
  283. public function delete($id)
  284. {
  285. if (!DolibarrApiAccess::$user->rights->zapier->delete) {
  286. throw new RestException(401);
  287. }
  288. $result = $this->hook->fetch($id);
  289. if (!$result) {
  290. throw new RestException(404, 'Hook not found');
  291. }
  292. if (!DolibarrApi::_checkAccessToResource('hook', $this->hook->id)) {
  293. throw new RestException(401, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
  294. }
  295. if (!$this->hook->delete(DolibarrApiAccess::$user)) {
  296. throw new RestException(500, 'Error when deleting Hook : '.$this->hook->error);
  297. }
  298. return array(
  299. 'success' => array(
  300. 'code' => 200,
  301. 'message' => 'Hook deleted'
  302. )
  303. );
  304. }
  305. // phpcs:disable PEAR.NamingConventions.ValidFunctionName.PublicUnderscore
  306. /**
  307. * Clean sensible object datas
  308. *
  309. * @param Object $object Object to clean
  310. * @return Object Object with cleaned properties
  311. */
  312. public function _cleanObjectDatas($object)
  313. {
  314. // phpcs:disable
  315. $object = parent::_cleanObjectDatas($object);
  316. return $object;
  317. }
  318. /**
  319. * Validate fields before create or update object
  320. *
  321. * @param array $data Array of data to validate
  322. * @param array $fields Array of fields needed
  323. * @return array
  324. *
  325. * @throws RestException
  326. */
  327. private function validate($data, $fields)
  328. {
  329. $hook = array();
  330. foreach ($fields as $field) {
  331. if (!isset($data[$field])) {
  332. throw new RestException(400, $field." field missing");
  333. }
  334. $hook[$field] = $data[$field];
  335. }
  336. return $hook;
  337. }
  338. }