File:  [LON-CAPA] / loncom / auth / lontokacc.pm
Revision 1.20: download - view: text, annotated - select for diffs
Fri Dec 18 15:23:03 2020 UTC (3 years, 4 months ago) by raeburn
Branches: MAIN
CVS tags: version_2_12_X, version_2_11_X, version_2_11_4_uiuc, version_2_11_4_msu, version_2_11_4, version_2_11_3_uiuc, version_2_11_3_msu, version_2_11_3, HEAD
- Retrieval of requestor's IP address centralized in lonnet::get_requestor_ip()
- Domain configuration to allow domain's LON-CAPA nodes to operate behind a
  WAF/Reverse Proxy using aliased hostname (CNAME).
- Web requests from other nodes bypass the WAF as their requests are made
  directly to the server hostname (A record); same for internal LON-CAPA
  connections for lonc -> lond.

    1: # The LearningOnline Network
    2: # Access Handler for User File Transfers
    3: #
    4: # $Id: lontokacc.pm,v 1.20 2020/12/18 15:23:03 raeburn Exp $
    5: #
    6: # Copyright Michigan State University Board of Trustees
    7: #
    8: # This file is part of the LearningOnline Network with CAPA (LON-CAPA).
    9: #
   10: # LON-CAPA is free software; you can redistribute it and/or modify
   11: # it under the terms of the GNU General Public License as published by
   12: # the Free Software Foundation; either version 2 of the License, or
   13: # (at your option) any later version.
   14: #
   15: # LON-CAPA is distributed in the hope that it will be useful,
   16: # but WITHOUT ANY WARRANTY; without even the implied warranty of
   17: # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
   18: # GNU General Public License for more details.
   19: #
   20: # You should have received a copy of the GNU General Public License
   21: # along with LON-CAPA; if not, write to the Free Software
   22: # Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
   23: #
   24: # /home/httpd/html/adm/gpl.txt
   25: #
   26: # http://www.lon-capa.org/
   27: #
   28: 
   29: package Apache::lontokacc;
   30: 
   31: use strict;
   32: use Apache::Constants qw(:common :remotehost);
   33: use Apache::lonnet();
   34: use Apache::File();
   35: use IO::Socket;
   36: 
   37: sub handler {
   38:     my $r = shift;
   39:     my $reqhost = &Apache::lonnet::get_requestor_ip($r,REMOTE_NOLOOKUP,1);
   40:     my @hostids= &Apache::lonnet::get_hosts_from_ip($reqhost);
   41:     if (!@hostids && $reqhost ne '127.0.0.1' ) {
   42: 	$r->log_reason("Unable to find a host for ".
   43: 		       $r->get_remote_host(REMOTE_NOLOOKUP));
   44: 	return FORBIDDEN;
   45:     }
   46:     if ($reqhost eq '127.0.0.1') {
   47:        return OK;
   48:     }
   49:     return OK;
   50: }
   51: 
   52: sub removefile {
   53:     my $r=shift;
   54:     if ($r->status==200) {
   55:         unlink($r->filename);
   56: 	#&Apache::lonnet::logthis('Unlinking '.$r->filename);
   57:     } else {
   58:         &Apache::lonnet::logthis('Failed to transfer '.$r->filename);
   59:     }
   60:     return OK;
   61: }
   62: 1;
   63: __END__
   64: 
   65: 
   66: 
   67: 
   68: 
   69: 
   70: 

FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>