Diff for /loncom/auth/loncacc.pm between versions 1.53 and 1.61

version 1.53, 2011/09/27 20:28:38 version 1.61, 2013/06/04 23:12:13
Line 1 Line 1
 # The LearningOnline Network  # The LearningOnline Network
 # Cookie Based Access Handler for Construction Area  # Cookie Based Access Handler for Authoring Spaces
 # (lonacc: 5/21/99,5/22,5/29,5/31 Gerd Kortemeyer)  # (lonacc: 5/21/99,5/22,5/29,5/31 Gerd Kortemeyer)
 #  #
 # $Id$  # $Id$
Line 31 Line 31
   
 =head1 NAME  =head1 NAME
   
 Apache::lonacc - Cookie Based Access Handler for Construction Area  Apache::lonacc - Cookie Based Access Handler for Authoring Spaces 
   
 =head1 SYNOPSIS  =head1 SYNOPSIS
   
Line 42  Invoked (for various locations) by /etc/ Line 42  Invoked (for various locations) by /etc/
 =head1 INTRODUCTION  =head1 INTRODUCTION
   
 This module enables cookie based authentication for construction area  This module enables cookie based authentication for construction area
 and is used to control access for three (essentially equivalent) URIs.  and is used to control access for the following two types of URI 
   (one for files, and one for directories):
   
  <LocationMatch "^/priv.*">   <LocationMatch "^/priv.*">
  <LocationMatch "^/\~.*">   <LocationMatch "^/priv.*/$">
  <LocationMatch "^/\~.*/$">  
   
 Whenever the client sends the cookie back to the server,   Whenever the client sends the cookie back to the server, 
 if the cookie is missing or invalid, the user is re-challenged  if the cookie is missing or invalid, the user is re-challenged
Line 71  store where they wanted to go (first url Line 71  store where they wanted to go (first url
   
 =back  =back
   
 =head1 OTHERSUBROUTINES  
   
 =over  
   
 =item constructaccess($url,$ownerdomain)  
   
 See if the owner domain and name  
 in the URL match those in the expected environment.  If so, return   
 two element list ($ownername,$ownerdomain).  Else, return null string.  
   
 =back  
   
 =cut  =cut
   
   
Line 96  use Apache::lonnet; Line 84  use Apache::lonnet;
 use Apache::lonacc;  use Apache::lonacc;
 use LONCAPA qw(:DEFAULT :match);  use LONCAPA qw(:DEFAULT :match);
   
 sub constructaccess {  
     my ($url,$ownerdomain,$setpriv)=@_;  
     my ($ownername)=($url=~/\/(?:\~|priv\/|home\/)($match_username)\//);  
     unless (($ownername) && ($ownerdomain)) { return ''; }  
     # We do not allow editing of previous versions of files.  
     if ($url=~/\.(\d+)\.(\w+)$/) { return ''; }  
     my @possibledomains = &Apache::lonnet::current_machine_domains();  
     if ($ownername eq $env{'user.name'}) {  
  foreach my $domain (@possibledomains) {  
     if ($domain eq $env{'user.domain'}) {  
  return ($ownername,$domain);  
     }  
  }  
     }  
       
     foreach my $domain (@possibledomains) {  
  if (exists($env{'user.priv.ca./'.$domain.'/'.$ownername.'./'}) ||  
     exists($env{'user.priv.aa./'.$domain.'/'.$ownername.'./'}) ) {  
     return ($ownername,$domain);  
  }  
     }  
   
     my $then=$env{'user.login.time'};  
     my $update==$env{'user.update.time'};  
     if (!$update) {  
         $update = $then;  
     }  
     my %dcroles = ();  
     if (&is_active_dc($ownerdomain,$update)) {  
         my %blocked=&Apache::lonnet::get('environment',['domcoord.author'],  
                                          $ownerdomain,$ownername);  
         unless ($blocked{'domcoord.author'} eq 'blocked') {  
             if (grep(/^$ownerdomain$/,@possibledomains)) {  
                 if ($setpriv) {  
                     my $refresh=$env{'user.refresh.time'};  
                     if (!$refresh) {  
                         $refresh = $update;  
                     }  
                     my $now = time;  
                     &Apache::lonnet::check_adhoc_privs($ownerdomain,$ownername,  
                                                        $update,$refresh,$now,'ca',  
                                                        'constructaccess');  
                 }  
                 return($ownername,$ownerdomain);  
             }  
         }  
     }  
     return '';  
 }  
   
 sub is_active_dc {  
     my ($ownerdomain,$update) = @_;  
     my $livedc;  
     if ($env{'user.adv'}) {  
         my $domrole = $env{'user.role.dc./'.$ownerdomain.'/'};  
         if ($domrole) {  
             my ($tstart,$tend)=split(/\./,$domrole);  
             $livedc = 1;  
             if ($tstart && $tstart>$update) { undef($livedc); }  
             if ($tend   && $tend  <$update) { undef($livedc); }  
         }  
     }  
     return $livedc;  
 }  
   
   
 sub handler {  sub handler {
     my $r = shift;      my $r = shift;
     my $requrl=$r->uri;      my $requrl=$r->uri;
Line 183  sub handler { Line 105  sub handler {
  $env{'request.state'}    = "construct";   $env{'request.state'}    = "construct";
  $env{'request.filename'} = $r->filename;   $env{'request.filename'} = $r->filename;
   
  unless (&constructaccess($requrl,$r->dir_config('lonDefDomain'),'setpriv')) {   my $allowed;
    my ($ownername,$ownerdom,$ownerhome) = 
               &Apache::lonnet::constructaccess($requrl,'setpriv');
           if (($ownername ne '') && ($ownerdom ne '') && ($ownerhome ne '')) {
               unless ($ownerhome eq 'no_host') {
                   my @hosts = &Apache::lonnet::current_machine_ids();
                   if (grep(/^\Q$ownerhome\E$/,@hosts)) {
                       $allowed = 1;
                   }
               }
           }
   
           unless ($allowed) {
     $r->log_reason("Unauthorized $requrl", $r->filename);       $r->log_reason("Unauthorized $requrl", $r->filename); 
     return HTTP_NOT_ACCEPTABLE;      return HTTP_NOT_ACCEPTABLE;
  }   }
Line 193  sub handler { Line 127  sub handler {
  &Apache::lonacc::get_posted_cgi($r);   &Apache::lonacc::get_posted_cgi($r);
   
  return OK;    return OK; 
     } else {       } else {
  $r->log_reason("Cookie $handle not valid", $r->filename)    $r->log_reason("Cookie $handle not valid", $r->filename) 
     }      }
   
Line 206  sub handler { Line 140  sub handler {
 1;  1;
 __END__  __END__
   
   
   
   
   
   
   
   

Removed from v.1.53  
changed lines
  Added in v.1.61


FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>