Version 4.7.8
This commit is contained in:
1 parent
7b7404e741
commit
fd22d99e69
688 files changed
+19814
-10890
No files matched your search
@@ -44,13 +44,6 @@ class _GraphQL extends Api
|
||||
/* Check our IP address isn't banned */
|
||||
$this->_checkIpAddressIsAllowed();
|
||||
|
||||
/* If this is a pre-flight request, acknowldge it */
|
||||
// @todo review this approach
|
||||
if( $_SERVER['REQUEST_METHOD'] === 'OPTIONS' )
|
||||
{
|
||||
$this->_respond( '', 200 );
|
||||
}
|
||||
|
||||
/* Authenticate */
|
||||
$client = NULL;
|
||||
$this->_setRawCredentials();
|
||||
@@ -60,23 +53,34 @@ class _GraphQL extends Api
|
||||
{
|
||||
$this->_setAccessToken();
|
||||
$client = \IPS\Api\OAuthClient::load( $this->accessToken['client_id'] );
|
||||
|
||||
if( $client->api_access == 'rest' )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'NO_GRAPHQL_ACCESS', '3S426_graphql/1', 403 );
|
||||
}
|
||||
\IPS\Member::$loggedInMember = \IPS\Member::load( $this->accessToken['member_id'] );
|
||||
}
|
||||
else
|
||||
{
|
||||
$client = \IPS\Api\OAuthClient::load( $this->rawApiKey );
|
||||
|
||||
/* Check that the API key has access to the GraphQL API */
|
||||
if( $client->api_access == 'rest' )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'NO_GRAPHQL_ACCESS', '3S426_graphql/1', 403 );
|
||||
}
|
||||
\IPS\Member::$loggedInMember = new \IPS\Member;
|
||||
}
|
||||
}
|
||||
catch ( \OutOfRangeException $e )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'INVALID_API_KEY', '3S290/7', 401 );
|
||||
throw new \IPS\Api\Exception( 'INVALID_API_KEY', '3S290_graphql/7', 401 );
|
||||
}
|
||||
|
||||
/* Check that the OAuth client has access to the GraphQL API */
|
||||
if ( !$client->graphql )
|
||||
if( $client->api_access === 'rest' )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'NO_GRAPHQL_ACCESS', '2S291/3', 403 );
|
||||
throw new \IPS\Api\Exception( 'NO_GRAPHQL_ACCESS', '2S291_graphql/3', 403 );
|
||||
}
|
||||
}
|
||||
catch ( \IPS\Api\Exception $e )
|
||||
@@ -85,7 +89,7 @@ class _GraphQL extends Api
|
||||
$response = json_encode( array( 'errors' => array( array( 'message' => $e->getMessage(), 'id' => $e->exceptionCode ) ) ), JSON_PRETTY_PRINT );
|
||||
|
||||
/* Do we need to log this? */
|
||||
if ( \in_array( $e->exceptionCode, array( '2S290/8', '2S290/B', '3S290/7', '3S290/9' ) ) )
|
||||
if ( \in_array( $e->exceptionCode, array( '2S290_graphql/8', '2S290_graphql/B', '3S290_graphql/7', '3S290_graphql/9' ) ) )
|
||||
{
|
||||
$this->_log( $response, $e->getCode(), \in_array( $e->exceptionCode, array( '3S290/7', '3S290/9', '3S290/B' ) ) );
|
||||
}
|
||||
@@ -106,11 +110,22 @@ class _GraphQL extends Api
|
||||
{
|
||||
/* Work out the query (can either use a JSON-encoded or form-encoded) body */
|
||||
$query = NULL;
|
||||
$variables = NULL;
|
||||
$variables = [];
|
||||
if( \IPS\Request::i()->query )
|
||||
{
|
||||
$query = \IPS\Request::i()->query;
|
||||
$variables = ( isset( \IPS\Request::i()->variables ) AND \is_array( \IPS\Request::i()->variables ) ) ? \IPS\Request::i()->variables : [];
|
||||
|
||||
if( isset( \IPS\Request::i()->variables ) )
|
||||
{
|
||||
if( \is_array( \IPS\Request::i()->variables ) )
|
||||
{
|
||||
$variables = \IPS\Request::i()->variables;
|
||||
}
|
||||
else
|
||||
{
|
||||
$variables = json_decode( \IPS\Request::i()->variables, TRUE );
|
||||
}
|
||||
}
|
||||
}
|
||||
elseif ( $json = json_decode( file_get_contents('php://input'), TRUE ) )
|
||||
{
|
||||
|
||||
Reference in new issue
Block a user