* initial v0 creator * working json api for generic reports * add require login * move report swagger into plugin, and set new default layout of noop * require proper role and also use new util func * start to tidy authn * some work on cleaning up web authn * clean up the authN checks * fix bug * fix the auth for api * fixes to json handling * set swagger sort order * enable most reports for api endpoints * fix doc * add paramters to reports * add missed report * allow api_parameters in reports config * reorganise api * add vlan search * add port search * make sure to enable layout processing * add device search * add v1 to api paths * add Node Search * support api_responses * add device object search; fix spurious ports field in device result class * handle some plugins just returning undef if search fails * errors from api seamlessley * fix error in date range default * more sensible default for prefix * change order of endpoints in swagger-ui * all db row classes can now TO_JSON * add device_port api endpoint * add device ports endpoint * do not expand docs * add swagger ui json tree formatter * add all relations from Device table * add port relations * add nodes retrieve on device or vlan * rename to GetAPIKey * update config for previous commit
52 lines
1.2 KiB
Perl
52 lines
1.2 KiB
Perl
package App::Netdisco::Web::Password;
|
|
|
|
use Dancer ':syntax';
|
|
use Dancer::Plugin::DBIC;
|
|
use Dancer::Plugin::Auth::Extensible;
|
|
use Dancer::Plugin::Passphrase;
|
|
|
|
use Digest::MD5 ();
|
|
|
|
sub _make_password {
|
|
my $pass = (shift || passphrase->generate_random);
|
|
if (setting('safe_password_store')) {
|
|
return passphrase($pass)->generate;
|
|
}
|
|
else {
|
|
return Digest::MD5::md5_hex($pass),
|
|
}
|
|
}
|
|
|
|
sub _bail {
|
|
var('passchange_failed' => 1);
|
|
return template 'password.tt', {}, { layout => 'main' };
|
|
}
|
|
|
|
any ['get', 'post'] => '/password' => require_login sub {
|
|
my $old = param('old');
|
|
my $new = param('new');
|
|
my $confirm = param('confirm');
|
|
|
|
if (request->is_post) {
|
|
unless ($old and $new and $confirm and ($new eq $confirm)) {
|
|
return _bail();
|
|
}
|
|
|
|
my ($success, $realm) = authenticate_user(
|
|
session('logged_in_user'), $old
|
|
);
|
|
return _bail() if not $success;
|
|
|
|
my $user = schema('netdisco')->resultset('User')
|
|
->find({username => session('logged_in_user')});
|
|
return _bail() if not $user;
|
|
|
|
$user->update({password => _make_password($new)});
|
|
var('passchange_ok' => 1);
|
|
}
|
|
|
|
template 'password.tt', {}, { layout => 'main' };
|
|
};
|
|
|
|
true;
|