Module: Msf::WebServices::CredentialServlet

Defined in:
lib/msf/core/web_services/servlet/credential_servlet.rb

Class Method Summary collapse

Class Method Details

.api_path ⇒ Object



3
4
5
# File 'lib/msf/core/web_services/servlet/credential_servlet.rb', line 3

def self.api_path
  '/api/v1/credentials'
end

.api_path_with_id ⇒ Object



7
8
9
# File 'lib/msf/core/web_services/servlet/credential_servlet.rb', line 7

def self.api_path_with_id
  "#{self.api_path}/?:id?"
end

.create_credential ⇒ Object



46
47
48
49
50
51
52
53
54
55
56
# File 'lib/msf/core/web_services/servlet/credential_servlet.rb', line 46

def self.create_credential
  lambda {
    warden.authenticate!
    job = lambda { |opts|
      opts[:origin_type] = opts[:origin_type].to_sym if opts[:origin_type]
      opts[:private_type] = opts[:private_type].to_sym if opts[:private_type]
      get_db.create_credential(opts)
    }
    exec_report_job(request, &job)
  }
end

.delete_credentials ⇒ Object



74
75
76
77
78
79
80
81
82
83
84
85
# File 'lib/msf/core/web_services/servlet/credential_servlet.rb', line 74

def self.delete_credentials
  lambda {
    warden.authenticate!
    begin
      opts = parse_json_request(request, false)
      data = get_db.delete_credentials(opts)
      set_json_data_response(response: data)
    rescue => e
      print_error_and_create_response(error: e, message: 'There was an error deleting the credential:', code: 500)
    end
  }
end

.get_credentials ⇒ Object



23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
# File 'lib/msf/core/web_services/servlet/credential_servlet.rb', line 23

def self.get_credentials
  lambda {
    warden.authenticate!
    begin
      sanitized_params = sanitize_params(params, env['rack.request.query_hash'])
      data = get_db.creds(sanitized_params)
      includes = [:logins, :public, :private, :realm]
      # Need to append the human attribute into the private sub-object before converting to json
      # This is normally pulled from a class method from the MetasploitCredential class
      response = []
      data.each do |cred|
        json = cred.as_json(include: includes).merge(private_class: cred.private.class.to_s)
        response << json
      end
      data = data.first if is_single_object?(data, sanitized_params)
      response = format_cred_json(data)
      set_json_data_response(response: response)
    rescue => e
      print_error_and_create_response(error: e, message: 'There was an error retrieving credentials:', code: 500)
    end
  }
end

.registered(app) ⇒ Object



11
12
13
14
15
16
17
# File 'lib/msf/core/web_services/servlet/credential_servlet.rb', line 11

def self.registered(app)
  app.get self.api_path, &get_credentials
  app.get self.api_path_with_id, &get_credentials
  app.post self.api_path, &create_credential
  app.put self.api_path_with_id, &update_credential
  app.delete self.api_path, &delete_credentials
end

.update_credential ⇒ Object



58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
# File 'lib/msf/core/web_services/servlet/credential_servlet.rb', line 58

def self.update_credential
  lambda {
    warden.authenticate!
    begin
      opts = parse_json_request(request, false)
      tmp_params = sanitize_params(params)
      opts[:id] = tmp_params[:id] if tmp_params[:id]
      data = get_db.update_credential(opts)
      response = format_cred_json(data)
      set_json_data_response(response: response.first)
    rescue => e
      print_error_and_create_response(error: e, message: 'There was an error updating the credential:', code: 500)
    end
  }
end