]> git.defcon.no Git - hermes/blobdiff - api/phone.php
Changed from GET to POST on all parameter passing. Fixed a nasty bug in previous...
[hermes] / api / phone.php
index a47c4946ff9883924a16cf39bfd621adbf934c05..12ae05702da72152eda3fb9fc69acecb79d4ab37 100644 (file)
@@ -27,9 +27,9 @@ token_auth();
                        // Required GET parameters:
                        // user: authentication username, SIP-username without domain component
                        // domain: Domain/realm of the user. username + '@' + domain == SIP address.
-                       if ( array_key_exists( 'mac', $_GET) )
+                       if ( array_key_exists( 'mac', $_POST) )
                        {
-                               $mac = $_GET['mac'];
+                               $mac = $_POST['mac'];
                                $relations = get_phone_users ( $mac );
                                if ( $relations )
                                {
@@ -37,18 +37,18 @@ token_auth();
                                }
                                else print json_encode( array ( 'response' => 'failed', 'cause' => 'nonexistant', 'detail' => 'No results.'));
                        }
-                       else if ( ( array_key_exists( 'username', $_GET) && array_key_exists( 'domain', $_GET ) ) || array_key_exists('user', $_GET) )
+                       else if ( ( array_key_exists( 'username', $_POST) && array_key_exists( 'domain', $_POST ) ) || array_key_exists('user', $_POST) )
                        {
                                $username = "";
                                $domain = "";
-                               if ( array_key_exists('username', $_GET) )
+                               if ( array_key_exists('username', $_POST) )
                                {
-                                       $username = $_GET['username'];
-                                       $domain = $_GET['domain'];
+                                       $username = $_POST['username'];
+                                       $domain = $_POST['domain'];
                                }
                                else
                                {
-                                       $user = split_sipaddress($_GET['user']);
+                                       $user = split_sipaddress($_POST['user']);
                                        if ( !$user )
                                        {
                                                print json_encode ( array( 'response' => 'failed', 'cause' => 'invalid', 'detail' => 'Invalid SIP address') );
@@ -71,8 +71,8 @@ token_auth();
                case "/list":
                        // List all (distinct) phone MAC-adresses registered...
                        $search = null;
-                       if ( array_key_exists('search', $_GET ) )
-                               $search = $_GET['search'];
+                       if ( array_key_exists('search', $_POST ) )
+                               $search = $_POST['search'];
 
                        $phones = list_phones( $search );
                        print json_encode( array( 'response' => 'ok', 'list' => $phones ));
@@ -89,20 +89,20 @@ token_auth();
                                domain    A valid domain .. to form a registered user@domain combo :)
 
                        */
-                       if ( array_key_exists('mac', $_GET ) &&
-                               ( array_key_exists('user', $_GET) ||
-                                       ( array_key_exists('username', $_GET) && array_key_exists('domain', $_GET ))))
+                       if ( array_key_exists('mac', $_POST ) &&
+                               ( array_key_exists('user', $_POST) ||
+                                       ( array_key_exists('username', $_POST) && array_key_exists('domain', $_POST ))))
                        {
                                $username = "";
                                $domain = "";
-                               if ( array_key_exists('username', $_GET) )
+                               if ( array_key_exists('username', $_POST) )
                                {
-                                       $username = $_GET['username'];
-                                       $domain = $_GET['domain'];
+                                       $username = $_POST['username'];
+                                       $domain = $_POST['domain'];
                                }
                                else
                                {
-                                       $user = split_sipaddress($_GET['user']);
+                                       $user = split_sipaddress($_POST['user']);
                                        if ( !$user )
                                        {
                                                print json_encode ( array( 'response' => 'failed', 'cause' => 'invalid', 'detail' => 'Invalid SIP address') );
@@ -110,7 +110,7 @@ token_auth();
                                        }
                                        list ( $username, $domain ) = $user;
                                }
-                               $mac = clean_mac($_GET['mac']);
+                               $mac = clean_mac($_POST['mac']);
                                if ( !$mac )
                                {
                                        print json_encode ( array( 'response' => 'failed', 'cause' => 'invalid', 'detail' => 'No valid MAC address given.') );
@@ -159,20 +159,20 @@ token_auth();
                                domain    A valid domain .. to form a registered user@domain combo :)
 
                        */
-                       if ( array_key_exists('mac', $_GET ) &&
-                               ( array_key_exists('user', $_GET) ||
-                                       ( array_key_exists('username', $_GET) && array_key_exists('domain', $_GET ))))
+                       if ( array_key_exists('mac', $_POST ) &&
+                               ( array_key_exists('user', $_POST) ||
+                                       ( array_key_exists('username', $_POST) && array_key_exists('domain', $_POST ))))
                        {
                                $username = "";
                                $domain = "";
-                               if ( array_key_exists('username', $_GET) )
+                               if ( array_key_exists('username', $_POST) )
                                {
-                                       $username = $_GET['username'];
-                                       $domain = $_GET['domain'];
+                                       $username = $_POST['username'];
+                                       $domain = $_POST['domain'];
                                }
                                else
                                {
-                                       $user = split_sipaddress($_GET['user']);
+                                       $user = split_sipaddress($_POST['user']);
                                        if ( !$user )
                                        {
                                                print json_encode ( array( 'response' => 'failed', 'cause' => 'invalid', 'detail' => 'Invalid SIP address') );
@@ -180,7 +180,7 @@ token_auth();
                                        }
                                        list ( $username, $domain ) = $user;
                                }
-                               $mac = clean_mac($_GET['mac']);
+                               $mac = clean_mac($_POST['mac']);
                                if ( !$mac )
                                {
                                        print json_encode ( array( 'response' => 'failed', 'cause' => 'invalid', 'detail' => 'No valid MAC address given.') );