1
0
قرینه از https://github.com/matomo-org/matomo.git synced 2025-08-21 22:47:43 +00:00
Files
matomo/plugins/UsersManager/UserUpdater.php
Stefan Giehl 158e45a5a9 Use #[\SensitiveParameter] php attribute to hide sensitive parameters from strack traces (#23324)
* Use #[\SensitiveParameter] php attribute to hide sensitive parameters from strack traces

* also hide database config parameters

* also hide 2fa codes and secrets

* hide some more parameters

* add attribute to remaining sensitive parameters

* update matomo-org/matomo-coding-standards
2025-05-30 14:24:53 +02:00

59 خطوط
1.8 KiB
PHP

<?php
/**
* Matomo - free/libre analytics platform
*
* @link https://matomo.org
* @license https://www.gnu.org/licenses/gpl-3.0.html GPL v3 or later
*/
namespace Piwik\Plugins\UsersManager;
use Piwik\API\Request;
class UserUpdater
{
/**
* Use this method if you have to update the user without having the ability to ask the user for a password confirmation
* @param $userLogin
* @param bool $password
* @param bool $email
* @param bool $_isPasswordHashed
* @throws \Exception
*/
public function updateUserWithoutCurrentPassword(
$userLogin,
#[\SensitiveParameter]
$password = false,
$email = false,
$_isPasswordHashed = false
) {
API::$UPDATE_USER_REQUIRE_PASSWORD_CONFIRMATION = false;
try {
Request::processRequest('UsersManager.updateUser', [
'userLogin' => $userLogin,
'password' => $password,
'email' => $email,
'_isPasswordHashed' => $_isPasswordHashed,
], $default = []);
API::$UPDATE_USER_REQUIRE_PASSWORD_CONFIRMATION = true;
} catch (\Exception $e) {
API::$UPDATE_USER_REQUIRE_PASSWORD_CONFIRMATION = true;
throw $e;
}
}
public function setSuperUserAccessWithoutCurrentPassword($userLogin, $hasSuperUserAccess)
{
API::$SET_SUPERUSER_ACCESS_REQUIRE_PASSWORD_CONFIRMATION = false;
try {
Request::processRequest('UsersManager.setSuperUserAccess', [
'userLogin' => $userLogin,
'hasSuperUserAccess' => $hasSuperUserAccess,
], $default = []);
} finally {
API::$SET_SUPERUSER_ACCESS_REQUIRE_PASSWORD_CONFIRMATION = true;
}
}
}