Files
netdisco/lib/App/Netdisco/Web/Password.pm
Oliver Gorwits dff26abc5c API implementation (#712)
* initial v0 creator

* working json api for generic reports

* add require login

* move report swagger into plugin, and set new default layout of noop

* require proper role and also use new util func

* start to tidy authn

* some work on cleaning up web authn

* clean up the authN checks

* fix bug

* fix the auth for api

* fixes to json handling

* set swagger sort order

* enable most reports for api endpoints

* fix doc

* add paramters to reports

* add missed report

* allow api_parameters in reports config

* reorganise api

* add vlan search

* add port search

* make sure to enable layout processing

* add device search

* add v1 to api paths

* add Node Search

* support api_responses

* add device object search; fix spurious ports field in device result class

* handle some plugins just returning undef if search fails

* errors from api seamlessley

* fix error in date range default

* more sensible default for prefix

* change order of endpoints in swagger-ui

* all db row classes can now TO_JSON

* add device_port api endpoint

* add device ports endpoint

* do not expand docs

* add swagger ui json tree formatter

* add all relations from Device table

* add port relations

* add nodes retrieve on device or vlan

* rename to GetAPIKey

* update config for previous commit
2020-04-15 21:15:52 +01:00

52 lines
1.2 KiB
Perl

package App::Netdisco::Web::Password;
use Dancer ':syntax';
use Dancer::Plugin::DBIC;
use Dancer::Plugin::Auth::Extensible;
use Dancer::Plugin::Passphrase;
use Digest::MD5 ();
sub _make_password {
my $pass = (shift || passphrase->generate_random);
if (setting('safe_password_store')) {
return passphrase($pass)->generate;
}
else {
return Digest::MD5::md5_hex($pass),
}
}
sub _bail {
var('passchange_failed' => 1);
return template 'password.tt', {}, { layout => 'main' };
}
any ['get', 'post'] => '/password' => require_login sub {
my $old = param('old');
my $new = param('new');
my $confirm = param('confirm');
if (request->is_post) {
unless ($old and $new and $confirm and ($new eq $confirm)) {
return _bail();
}
my ($success, $realm) = authenticate_user(
session('logged_in_user'), $old
);
return _bail() if not $success;
my $user = schema('netdisco')->resultset('User')
->find({username => session('logged_in_user')});
return _bail() if not $user;
$user->update({password => _make_password($new)});
var('passchange_ok' => 1);
}
template 'password.tt', {}, { layout => 'main' };
};
true;