X-Git-Url: https://scripts.mit.edu/gitweb/autoinstallsdev/mediawiki.git/blobdiff_plain/d57edfddd6c01f0ed6b1a84019649cdf6cddd5f8..83d871ca0d985c6d586b323bf96161afb510ebf6:/includes/api/ApiQueryTokens.php diff --git a/includes/api/ApiQueryTokens.php b/includes/api/ApiQueryTokens.php new file mode 100644 index 00000000..0e46fd05 --- /dev/null +++ b/includes/api/ApiQueryTokens.php @@ -0,0 +1,136 @@ +extractRequestParams(); + $res = [ + ApiResult::META_TYPE => 'assoc', + ]; + + if ( $this->lacksSameOriginSecurity() ) { + $this->addWarning( [ 'apiwarn-tokens-origin' ] ); + return; + } + + $user = $this->getUser(); + $session = $this->getRequest()->getSession(); + $salts = self::getTokenTypeSalts(); + foreach ( $params['type'] as $type ) { + $res[$type . 'token'] = self::getToken( $user, $session, $salts[$type] )->toString(); + } + + $this->getResult()->addValue( 'query', $this->getModuleName(), $res ); + } + + /** + * Get the salts for known token types + * @return (string|array)[] Returning a string will use that as the salt + * for User::getEditTokenObject() to fetch the token, which will give a + * LoggedOutEditToken (always "+\\") for anonymous users. Returning an + * array will use it as parameters to MediaWiki\Session\Session::getToken(), + * which will always return a full token even for anonymous users. + */ + public static function getTokenTypeSalts() { + static $salts = null; + if ( !$salts ) { + $salts = [ + 'csrf' => '', + 'watch' => 'watch', + 'patrol' => 'patrol', + 'rollback' => 'rollback', + 'userrights' => 'userrights', + 'login' => [ '', 'login' ], + 'createaccount' => [ '', 'createaccount' ], + ]; + Hooks::run( 'ApiQueryTokensRegisterTypes', [ &$salts ] ); + ksort( $salts ); + } + + return $salts; + } + + /** + * Get a token from a salt + * @param User $user + * @param MediaWiki\Session\Session $session + * @param string|array $salt A string will be used as the salt for + * User::getEditTokenObject() to fetch the token, which will give a + * LoggedOutEditToken (always "+\\") for anonymous users. An array will + * be used as parameters to MediaWiki\Session\Session::getToken(), which + * will always return a full token even for anonymous users. An array will + * also persist the session. + * @return MediaWiki\Session\Token + */ + public static function getToken( User $user, MediaWiki\Session\Session $session, $salt ) { + if ( is_array( $salt ) ) { + $session->persist(); + return call_user_func_array( [ $session, 'getToken' ], $salt ); + } else { + return $user->getEditTokenObject( $salt, $session->getRequest() ); + } + } + + public function getAllowedParams() { + return [ + 'type' => [ + ApiBase::PARAM_DFLT => 'csrf', + ApiBase::PARAM_ISMULTI => true, + ApiBase::PARAM_TYPE => array_keys( self::getTokenTypeSalts() ), + ], + ]; + } + + protected function getExamplesMessages() { + return [ + 'action=query&meta=tokens' + => 'apihelp-query+tokens-example-simple', + 'action=query&meta=tokens&type=watch|patrol' + => 'apihelp-query+tokens-example-types', + ]; + } + + public function isReadMode() { + // So login tokens can be fetched on private wikis + return false; + } + + public function getCacheMode( $params ) { + return 'private'; + } + + public function getHelpUrls() { + return 'https://www.mediawiki.org/wiki/Special:MyLanguage/API:Tokens'; + } +}