MediaWiki REL1_33
ApiCheckToken.php
Go to the documentation of this file.
1<?php
24
29class ApiCheckToken extends ApiBase {
30
31 public function execute() {
33 $token = $params['token'];
34 $maxage = $params['maxtokenage'];
36
37 $res = [];
38
39 $tokenObj = ApiQueryTokens::getToken(
40 $this->getUser(), $this->getRequest()->getSession(), $salts[$params['type']]
41 );
42
43 if ( substr( $token, -strlen( urldecode( Token::SUFFIX ) ) ) === urldecode( Token::SUFFIX ) ) {
44 $this->addWarning( 'apiwarn-checktoken-percentencoding' );
45 }
46
47 if ( $tokenObj->match( $token, $maxage ) ) {
48 $res['result'] = 'valid';
49 } elseif ( $maxage !== null && $tokenObj->match( $token ) ) {
50 $res['result'] = 'expired';
51 } else {
52 $res['result'] = 'invalid';
53 }
54
55 $ts = Token::getTimestamp( $token );
56 if ( $ts !== null ) {
57 $mwts = new MWTimestamp();
58 $mwts->timestamp->setTimestamp( $ts );
59 $res['generated'] = $mwts->getTimestamp( TS_ISO_8601 );
60 }
61
62 $this->getResult()->addValue( null, $this->getModuleName(), $res );
63 }
64
65 public function getAllowedParams() {
66 return [
67 'type' => [
70 ],
71 'token' => [
72 ApiBase::PARAM_TYPE => 'string',
75 ],
76 'maxtokenage' => [
77 ApiBase::PARAM_TYPE => 'integer',
78 ],
79 ];
80 }
81
82 protected function getExamplesMessages() {
83 return [
84 'action=checktoken&type=csrf&token=123ABC'
85 => 'apihelp-checktoken-example-simple',
86 ];
87 }
88}
and that you know you can do these things To protect your we need to make restrictions that forbid anyone to deny you these rights or to ask you to surrender the rights These restrictions translate to certain responsibilities for you if you distribute copies of the or if you modify it For if you distribute copies of such a whether gratis or for a you must give the recipients all the rights that you have You must make sure that receive or can get the source code And you must show them these terms so they know their rights We protect your rights with two and(2) offer you this license which gives you legal permission to copy
This abstract class implements many basic API functions, and is the base of all API classes.
Definition ApiBase.php:37
const PARAM_REQUIRED
(boolean) Is the parameter required?
Definition ApiBase.php:111
const PARAM_TYPE
(string|string[]) Either an array of allowed value strings, or a string type as described below.
Definition ApiBase.php:87
const PARAM_SENSITIVE
(boolean) Is the parameter sensitive? Note 'password'-type fields are always sensitive regardless of ...
Definition ApiBase.php:193
getResult()
Get the result object.
Definition ApiBase.php:632
extractRequestParams( $options=[])
Using getAllowedParams(), this function makes an array of the values provided by the user,...
Definition ApiBase.php:743
addWarning( $msg, $code=null, $data=null)
Add a warning for this module.
Definition ApiBase.php:1909
getModuleName()
Get the name of the module being executed by this instance.
Definition ApiBase.php:512
getExamplesMessages()
Returns usage examples for this module.
getAllowedParams()
Returns an array of allowed parameters (parameter name) => (default value) or (parameter name) => (ar...
execute()
Evaluates the parameters, performs the requested query, and sets up the result.
static getTokenTypeSalts()
Get the salts for known token types.
static getToken(User $user, MediaWiki\Session\Session $session, $salt)
Get a token from a salt.
Library for creating and parsing MW-style timestamps.
Value object representing a CSRF token.
Definition Token.php:32
$res
Definition database.txt:21
$params