| 12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273 |
- <?php
- /* Copyright (C) 2011-2015 Regis Houssin <regis.houssin@inodbox.com>
- *
- * This program is free software; you can redistribute it and/or modify
- * it under the terms of the GNU General Public License as published by
- * the Free Software Foundation; either version 3 of the License, or
- * (at your option) any later version.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- * GNU General Public License for more details.
- *
- * You should have received a copy of the GNU General Public License
- * along with this program. If not, see <https://www.gnu.org/licenses/>.
- */
- /**
- * \file htdocs/core/ajax/security.php
- * \brief This ajax component is used to generated hash keys for security purposes,
- * like the key to use into URL to protect them.
- */
- if (!defined('NOTOKENRENEWAL')) {
- define('NOTOKENRENEWAL', '1'); // Disables token renewal
- }
- if (!defined('NOREQUIREMENU')) {
- define('NOREQUIREMENU', '1');
- }
- if (!defined('NOREQUIREHTML')) {
- define('NOREQUIREHTML', '1');
- }
- if (!defined('NOREQUIREAJAX')) {
- define('NOREQUIREAJAX', '1');
- }
- if (!defined('NOREQUIRESOC')) {
- define('NOREQUIRESOC', '1');
- }
- // We need langs because the getRandomPassword may use the user language to define some rules of pass generation
- /*if (!defined('NOREQUIRETRAN')) {
- define('NOREQUIRETRAN', '1');
- }*/
- // Load Dolibarr environment
- require '../../main.inc.php';
- $action = GETPOST('action');
- // Security check
- // None. This is public component with no access and effect on data.
- /*
- * View
- */
- //top_htmlhead("", "", 1); // Replaced with top_httphead. An ajax page does not need html header.
- top_httphead();
- //print '<!-- Ajax page called with url '.dol_escape_htmltag($_SERVER["PHP_SELF"]).'?'.dol_escape_htmltag($_SERVER["QUERY_STRING"]).' -->'."\n";
- // Return a new generated password
- if ($action) {
- if ($action == 'getrandompassword') {
- require_once DOL_DOCUMENT_ROOT.'/core/lib/security2.lib.php';
- $generic = GETPOST('generic') ? true : false;
- echo getRandomPassword($generic);
- }
- } else {
- if (GETPOST('errorcode') == 'InvalidToken') {
- http_response_code(401);
- }
- }
|