use Bugzilla::Error;
use Bugzilla::WebService::Constants qw(XMLRPC_CONTENT_TYPE_WHITELIST);
+use Bugzilla::WebService::Util qw(fix_credentials);
use Scalar::Util qw(tainted);
sub deserialize {
my $params = $som->paramsin;
# This allows positional parameters for Testopia.
$params = {} if ref $params ne 'HASH';
+
+ # Update the params to allow for several convenience key/values
+ # use for authentication
+ fix_credentials($params);
+
Bugzilla->input_params($params);
return $som;
}
# Username and password params are required
foreach my $param ("login", "password") {
- defined $params->{$param}
+ (!defined $params->{$param} && !defined $params->{'Bugzilla_' . $param})
|| ThrowCodeError('param_required', { param => $param });
}
- # Make sure the CGI user info class works if necessary.
- my $input_params = Bugzilla->input_params;
- $input_params->{'Bugzilla_login'} = $params->{login};
- $input_params->{'Bugzilla_password'} = $params->{password};
- $input_params->{'Bugzilla_restrictlogin'} = $params->{restrict_login};
-
my $user = Bugzilla->login();
my $result = { id => $self->type('int', $user->id) };
sub fix_credentials {
my ($params) = @_;
- # Allow user to pass in login=foo&password=bar as a convenience
- # even if not calling GET /login. We also do not delete them as
- # GET /login requires "login" and "password".
- if (exists $params->{'login'} && exists $params->{'password'}) {
- $params->{'Bugzilla_login'} = $params->{'login'};
- $params->{'Bugzilla_password'} = $params->{'password'};
- }
- # Allow user to pass token=12345678 as a convenience which becomes
- # "Bugzilla_token" which is what the auth code looks for.
- if (exists $params->{'token'}) {
- $params->{'Bugzilla_token'} = $params->{'token'};
- }
+
+ # Allow user to pass in login, password, restrict_login, and
+ # token as short-cuts to the longer versions.
+ $params->{'Bugzilla_login'} = delete $params->{'login'}
+ if exists $params->{'login'};
+ $params->{'Bugzilla_password'} = delete $params->{'password'}
+ if exists $params->{'password'};
+ $params->{'Bugzilla_restrictlogin'} = delete $params->{'restrict_login'}
+ if exists $params->{'restrict_login'};
+ $params->{'Bugzilla_token'} = delete $params->{'token'}
+ if exists $params->{'token'};
# Allow extensions to modify the credential data before login
Bugzilla::Hook::process('webservice_fix_credentials', { params => $params });