mediawiki-extensions-OATHAuth/api/ApiQueryOATH.php
Bryan Davis 766e18bca1 Add a query meta api option to check for OATH
Add a new internal action=query&meta=oath Action API module that can be
used to check for OATH protection on a given user account. Using the
module requires a new 'oathauth-api-all' permission which is not granted
to any group by default. The permission is also added to the new
'oath' grant so that it can be used via OAuth and bot passwords.

Use of this API is security sensitive and should not be granted lightly.
Configuring a special 'oathauth' user group to grant the needed
'oathauth-api-all' permission is recommended.

This check is primarily useful as an internal network service in an
environment where MediaWiki and other applications are sharing the same
backing authentication store (e.g. LDAP) and the non-MediaWiki
applications would like to respect the OATH protections enabled on the
MediaWiki install.

Bug: T144712
Change-Id: I4884f6efdfa42db82c25eadb70c7aefa98c370e9
2016-10-07 12:10:18 -07:00

90 lines
2.5 KiB
PHP

<?php
/**
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License along
* with this program; if not, write to the Free Software Foundation, Inc.,
* 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
* http://www.gnu.org/copyleft/gpl.html
*/
/**
* Query module to check if a user has OATH authentication enabled.
*
* Usage requires the 'oathauth-api-all' grant which is not given to any group
* by default. Use of this API is security sensitive and should not be granted
* lightly. Configuring a special 'oathauth' user group is recommended.
*
* @ingroup API
* @ingroup Extensions
*/
class ApiQueryOATH extends ApiQueryBase {
public function __construct( $query, $moduleName ) {
parent::__construct( $query, $moduleName, 'oath' );
}
public function execute() {
$params = $this->extractRequestParams();
if ( $params['user'] === null ) {
$params['user'] = $this->getUser()->getName();
}
if ( !$this->getUser()->isAllowed( 'oathauth-api-all' ) ) {
$this->dieUsage(
'You do not have permission to check OATH status',
'permissiondenied'
);
}
$user = User::newFromName( $params['user'] );
if ( $user === false ) {
$this->dieUsageMsg( [ 'noname', $params['user'] ] );
}
$result = $this->getResult();
$data = [
'enabled' => false,
];
if ( !$user->isAnon() ) {
$oathUser = OATHAuthHooks::getOATHUserRepository()
->findByUser( $user );
$data['enabled'] = $oathUser && $oathUser->getKey() !== null;
}
$result->addValue( 'query', $this->getModuleName(), $data );
}
public function getCacheMode( $params ) {
return 'private';
}
public function isInternal() {
return true;
}
public function getAllowedParams() {
return [
'user' => [
ApiBase::PARAM_TYPE => 'user',
],
];
}
protected function getExamplesMessages() {
return [
'action=query&meta=oath'
=> 'apihelp-query+oath-example-1',
'action=query&meta=oath&oathuser=Example'
=> 'apihelp-query+oath-example-2',
];
}
}