Diff for /loncom/auth/loncacc.pm between versions 1.28 and 1.61

version 1.28, 2003/05/13 00:52:46 version 1.61, 2013/06/04 23:12:13
Line 1 Line 1
 # The LearningOnline Network  # The LearningOnline Network
 # Cookie Based Access Handler for Construction Area  # Cookie Based Access Handler for Authoring Spaces
 # (lonacc: 5/21/99,5/22,5/29,5/31 Gerd Kortemeyer)  # (lonacc: 5/21/99,5/22,5/29,5/31 Gerd Kortemeyer)
 #  #
 # $Id$  # $Id$
Line 26 Line 26
 #  #
 # http://www.lon-capa.org/  # http://www.lon-capa.org/
 #  #
 # YEAR=2000  
 # 6/15,16/11,22/11,  
 # YEAR=2001  
 # 01/06,01/11,6/1,9/25,9/28,11/22,12/25,12/26,  
 # 01/06/01,05/04,05/05,05/09 Gerd Kortemeyer  
 # YEAR=2002  
 # 1/4 Gerd Kortemeyer  
 ###  
   
 package Apache::loncacc;  =pod
   
 use strict;  
 use Apache::Constants qw(:common :http :methods REDIRECT);  
 use Apache::File;  
 use CGI::Cookie();  
 use Fcntl qw(:flock);  
   
 sub constructaccess {  
     my ($url,$ownerdomain)=@_;  
     my ($ownername)=($url=~/\/(?:\~|priv\/|home\/)(\w+)/);  
     unless (($ownername) && ($ownerdomain)) { return ''; }  
     # We do not allow editing of previous versions of files.  
     if ($url=~/\.(\d+)\.(\w+)$/) { return ''; }  
     if (($ownername eq $ENV{'user.name'}) &&  
         ($ownerdomain eq $ENV{'user.domain'})) {  
  return ($ownername,$ownerdomain);  
     }  
   
     my $capriv='user.priv.ca./'.  
                $ownerdomain.'/'.$ownername.'./'.  
        $ownerdomain.'/'.$ownername;  
     foreach (keys %ENV) {  
         if ($_ eq $capriv) {  
            return ($ownername,$ownerdomain);  
         }  
     }  
   
     return '';  
 }  
   
 sub handler {  
     my $r = shift;  
     my $requrl=$r->uri;  
     $ENV{'request.editurl'}=$requrl;  
     my %cookies=CGI::Cookie->parse($r->header_in('Cookie'));  
     my $lonid=$cookies{'lonID'};  
     my $cookie;  
     if ($lonid) {  
  my $handle=$lonid->value;  
         $handle=~s/\W//g;  
         my $lonidsdir=$r->dir_config('lonIDsDir');  
         if ((-e "$lonidsdir/$handle.id") && ($handle ne '')) {  
   
 # ------------------------------------------------------ Initialize Environment  
   
             &Apache::lonnet::transfer_profile_to_env($lonidsdir,$handle);  
   
 # -------------------------------------------------------------- Resource State  
   
             $ENV{'request.state'}    = "construct";  
             $ENV{'request.filename'} = $r->filename;  
   
             unless (&constructaccess($requrl,$r->dir_config('lonDefDomain'))) {  
                 $r->log_reason("Unauthorized $requrl", $r->filename);   
         return HTTP_NOT_ACCEPTABLE;  
             }  
 # Construction space needs Remote to work  
             if ($ENV{'environment.remote'} eq 'off') {  
         $r->content_type('text/html');  
                 $r->header_out(Location =>   
                     'http://'.$r->server->server_hostname.  
                     '/adm/remote?action=launch&url='.  
                     &Apache::lonnet::escape($requrl));  
                 return REDIRECT;  
             }  
   
 # -------------------------------------------------------- Load POST parameters  
   
     &Apache::loncommon::get_posted_cgi($r);  
   
             return OK;   
         } else {   
             $r->log_reason("Cookie $handle not valid", $r->filename)   
         };  
     }  
   
 # ----------------------------------------------- Store where they wanted to go  
   
     $ENV{'request.firsturl'}=$requrl;  
     return FORBIDDEN;  
 }  
   
 1;  
 __END__  
   
 =head1 NAME  =head1 NAME
   
 Apache::lonacc - Cookie Based Access Handler for Construction Area  Apache::lonacc - Cookie Based Access Handler for Authoring Spaces 
   
 =head1 SYNOPSIS  =head1 SYNOPSIS
   
Line 134  Invoked (for various locations) by /etc/ Line 42  Invoked (for various locations) by /etc/
 =head1 INTRODUCTION  =head1 INTRODUCTION
   
 This module enables cookie based authentication for construction area  This module enables cookie based authentication for construction area
 and is used to control access for three (essentially equivalent) URIs.  and is used to control access for the following two types of URI 
   (one for files, and one for directories):
   
  <LocationMatch "^/priv.*">   <LocationMatch "^/priv.*">
  <LocationMatch "^/\~.*">   <LocationMatch "^/priv.*/$">
  <LocationMatch "^/\~.*/$">  
   
 Whenever the client sends the cookie back to the server,   Whenever the client sends the cookie back to the server, 
 if the cookie is missing or invalid, the user is re-challenged  if the cookie is missing or invalid, the user is re-challenged
Line 163  store where they wanted to go (first url Line 71  store where they wanted to go (first url
   
 =back  =back
   
 =head1 OTHERSUBROUTINES  =cut
   
 =over 4  
   
 =item *  package Apache::loncacc;
   
 constructaccess($url,$ownerdomain) : See if the owner domain and name  use strict;
 in the URL match those in the expected environment.  If so, return   use Apache::Constants qw(:common :http :methods REDIRECT);
 two element list ($ownername,$ownerdomain).  Else, return null string.  use Fcntl qw(:flock);
   use Apache::lonlocal;
   use Apache::lonnet;
   use Apache::lonacc;
   use LONCAPA qw(:DEFAULT :match);
   
 =back  sub handler {
       my $r = shift;
       my $requrl=$r->uri;
       $env{'request.editurl'}=$requrl;
   
 =cut      my $handle =  &Apache::lonnet::check_for_valid_session($r);
       if ($handle ne '') {
   
   # ------------------------------------------------------ Initialize Environment
           my $lonidsdir=$r->dir_config('lonIDsDir');
    &Apache::lonnet::transfer_profile_to_env($lonidsdir,$handle);
   
   # --------------------------------------------------------- Initialize Language
    
    &Apache::lonlocal::get_language_handle($r);
   
   # -------------------------------------------------------------- Resource State
   
    $env{'request.state'}    = "construct";
    $env{'request.filename'} = $r->filename;
   
    my $allowed;
    my ($ownername,$ownerdom,$ownerhome) = 
               &Apache::lonnet::constructaccess($requrl,'setpriv');
           if (($ownername ne '') && ($ownerdom ne '') && ($ownerhome ne '')) {
               unless ($ownerhome eq 'no_host') {
                   my @hosts = &Apache::lonnet::current_machine_ids();
                   if (grep(/^\Q$ownerhome\E$/,@hosts)) {
                       $allowed = 1;
                   }
               }
           }
   
           unless ($allowed) {
       $r->log_reason("Unauthorized $requrl", $r->filename); 
       return HTTP_NOT_ACCEPTABLE;
    }
   
   # -------------------------------------------------------- Load POST parameters
   
    &Apache::lonacc::get_posted_cgi($r);
   
    return OK; 
       } else {
    $r->log_reason("Cookie $handle not valid", $r->filename) 
       }
   
   # ----------------------------------------------- Store where they wanted to go
   
       $env{'request.firsturl'}=$requrl;
       return FORBIDDEN;
   }
   
   1;
   __END__
   

Removed from v.1.28  
changed lines
  Added in v.1.61


FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>