nextcloud/core/Controller/WipeController.php
Josh 1635ad13ff
fix(Wipe): Better handle missing tokens
Check for non-empty token string to avoid 500/internal server error due to `Argument #1 ($token) must be of type string, null given`

- Refactor slightly to streamline code
- Fix noted bug in both checkWipe() and wipeDone()

(initially reported in the community forum then reproduced)

Signed-off-by: Josh <josh.t.richards@gmail.com>
2024-07-01 10:53:50 -04:00

92 lines
2.2 KiB
PHP

<?php
declare(strict_types=1);
/**
* SPDX-FileCopyrightText: 2019 Nextcloud GmbH and Nextcloud contributors
* SPDX-License-Identifier: AGPL-3.0-or-later
*/
namespace OC\Core\Controller;
use OC\Authentication\Token\RemoteWipe;
use OCP\AppFramework\Controller;
use OCP\AppFramework\Http;
use OCP\AppFramework\Http\Attribute\FrontpageRoute;
use OCP\AppFramework\Http\JSONResponse;
use OCP\Authentication\Exceptions\InvalidTokenException;
use OCP\IRequest;
class WipeController extends Controller {
public function __construct(
string $appName,
IRequest $request,
private RemoteWipe $remoteWipe,
) {
parent::__construct($appName, $request);
}
/**
* @NoAdminRequired
* @NoCSRFRequired
* @PublicPage
*
* @AnonRateThrottle(limit=10, period=300)
*
* Check if the device should be wiped
*
* @param string $token App password
*
* @return JSONResponse<Http::STATUS_OK, array{wipe: bool}, array{}>|JSONResponse<Http::STATUS_NOT_FOUND, array<empty>, array{}>
*
* 200: Device should be wiped
* 404: Device should not be wiped
*/
#[FrontpageRoute(verb: 'POST', url: '/core/wipe/check')]
public function checkWipe(string $token = ''): JSONResponse {
if ($token !== '') {
try {
if ($this->remoteWipe->start($token)) {
return new JSONResponse([
'wipe' => true
]);
}
} catch (InvalidTokenException $e) {
// do nothing special, handled below
}
}
return new JSONResponse([], Http::STATUS_NOT_FOUND);
}
/**
* @NoAdminRequired
* @NoCSRFRequired
* @PublicPage
*
* @AnonRateThrottle(limit=10, period=300)
*
* Finish the wipe
*
* @param string $token App password
*
* @return JSONResponse<Http::STATUS_OK|Http::STATUS_NOT_FOUND, array<empty>, array{}>
*
* 200: Wipe finished successfully
* 404: Device should not be wiped
*/
#[FrontpageRoute(verb: 'POST', url: '/core/wipe/success')]
public function wipeDone(string $token = ''): JSONResponse {
if ($token !== '') {
try {
if ($this->remoteWipe->finish($token)) {
return new JSONResponse([]);
}
} catch (InvalidTokenException $e) {
// do nothing special, handled below
}
}
return new JSONResponse([], Http::STATUS_NOT_FOUND);
}
}