File:
[LON-CAPA] /
loncom /
auth /
switchserver.pm
Revision
1.32:
download - view:
text,
annotated -
select for diffs
Sun Sep 29 00:49:24 2013 UTC (11 years, 1 month ago) by
raeburn
Branches:
MAIN
CVS tags:
version_2_11_0_RC3,
version_2_11_0_RC2,
version_2_11_0,
HEAD
- Bug 6675
- Case where $env{'REMOTE_ADDR'} as reported to server selected to host
user session, is different from $env{'REMOTE_ADDR'} as reported to
server which handled original authentication request.
- Domain configuration for a load balancing server can be set to one of
the following, if an IP mismatch is detected by /adm/migrateuser
during credentials checking after redirect via /adm/switchserver
(i) Session will be hosted on Load Balancer
(ii) Session will be hosted on offload server
for each of (a) SSO users from load balancer's domain, (b) non-SSO users
- Setting to host on load balancer will be ignored if switch server was called
by an author or co-author switching to server housing the authoring space.
# The LearningOnline Network
# Switch Servers Handler
#
# $Id: switchserver.pm,v 1.32 2013/09/29 00:49:24 raeburn Exp $
#
# Copyright Michigan State University Board of Trustees
#
# This file is part of the LearningOnline Network with CAPA (LON-CAPA).
#
# LON-CAPA is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# LON-CAPA is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with LON-CAPA; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
#
# /home/httpd/html/adm/gpl.txt
#
# http://www.lon-capa.org/
#
package Apache::switchserver;
use strict;
use Apache::Constants qw(:common);
use Apache::lonnet;
use Apache::lonmenu;
use CGI::Cookie();
use Apache::lonlocal;
use LONCAPA qw(:DEFAULT :match);
sub init_env {
my ($r) = @_;
if (-e $env{'user.environment'}) {
return $env{'user.environment'};
}
my $requrl=$r->uri;
my $handle= &Apache::lonnet::check_for_valid_session($r);
if ($handle ne '') {
return undef;
}
my $lonidsdir=$r->dir_config('lonIDsDir');
&Apache::lonnet::transfer_profile_to_env($lonidsdir,$handle);
return $r->dir_config('lonIDsDir')."/$handle.id";
}
sub do_redirect {
my ($r,$url,$only_body,$extra_text) = @_;
$r->send_http_header;
my $start_page =
&Apache::loncommon::start_page('Switching Server ...',undef,
{'redirect' => [0.5,$url],
'only_body' => $only_body,});
my $end_page = &Apache::loncommon::end_page();
$r->print($start_page.$extra_text.$end_page);
unless ($env{'user.name'} eq 'public' && ($env{'user.domain'} eq 'public')) {
$r->register_cleanup(\&flush_course_logs);
}
return OK;
}
sub flush_course_logs {
&Apache::lonnet::flushcourselogs();
return OK;
}
sub handler {
my ($r) = @_;
my $handle=&init_env($r);
if (!defined($handle)) { return FORBIDDEN; }
&Apache::loncommon::get_unprocessed_cgi($ENV{'QUERY_STRING'},
['otherserver','role','origurl','symb']);
my $switch_to=&Apache::lonnet::hostname($env{'form.otherserver'});
if (! $env{'form.otherserver'}) {
$env{'form.otherserver'} =
&Apache::lonnet::find_existing_session($env{'user.domain'},
$env{'user.name'});
if (! $env{'form.otherserver'}) {
$env{'form.otherserver'} =
&Apache::lonnet::spareserver(30000,undef,1);
}
$switch_to=&Apache::lonnet::hostname($env{'form.otherserver'});
}
if (!defined($switch_to)) { return FORBIDDEN; }
if ($env{'user.name'} eq 'public'
&& $env{'user.domain'} eq 'public') {
my $url = 'http://'.$switch_to.$r->uri;
return &do_redirect($r,$url,1)
}
my $skip_canhost_check = '';
if ($env{'form.role'}) {
if (!exists($env{'user.role.'.$env{'form.role'}})) {
return FORBIDDEN;
} else {
my $now = time;
my ($start,$end) = split(/\./,$env{'user.role.'.$env{'form.role'}});
if (($start && $start > $now) || ($end && $end < $now)) {
return FORBIDDEN;
} elsif ($env{'form.role'} eq 'au./'.$env{'user.domain'}.'/') {
if (&Apache::lonnet::homeserver($env{'user.name'},$env{'user.domain'}) eq $env{'form.otherserver'}) {
$skip_canhost_check = 1;
}
} elsif ($env{'form.role'} =~ m{^[ac]a\./($match_domain)/($match_username)$}) {
if (&Apache::lonnet::homeserver($2,$1) eq $env{'form.otherserver'}) {
$skip_canhost_check = 1;
}
}
}
}
unless ($skip_canhost_check) {
my $canhost = 1;
my $uprimary_id = &Apache::lonnet::domain($env{'user.domain'},'primary');
my $uint_dom = &Apache::lonnet::internet_dom($uprimary_id);
my @intdoms;
my $internet_names = &Apache::lonnet::get_internet_names($env{'form.otherserver'});
if (ref($internet_names) eq 'ARRAY') {
@intdoms = @{$internet_names};
}
unless ($uint_dom ne '' && grep(/^\Q$uint_dom\E$/,@intdoms)) {
my $serverhomeID = &Apache::lonnet::get_server_homeID($switch_to);
my $serverhomedom = &Apache::lonnet::host_domain($serverhomeID);
my %defdomdefaults = &Apache::lonnet::get_domain_defaults($serverhomedom);
my %udomdefaults = &Apache::lonnet::get_domain_defaults($env{'user.domain'});
my $remoterev = &Apache::lonnet::get_server_loncaparev($env{'user.domain'},$env{'form.otherserver'});
$canhost =
&Apache::lonnet::can_host_session($env{'user.domain'},
$env{'form.otherserver'},
$remoterev,
$udomdefaults{'remotesessions'},
$defdomdefaults{'hostedsessions'});
}
unless ($canhost) { return FORBIDDEN; }
}
#remove session env, and log event
unlink($handle);
my %temp=('switchserver' => time.':'.$env{'form.otherserver'},
$env{'form.role'});
&Apache::lonnet::put('email_status',\%temp);
&Apache::lonnet::log($env{'user.domain'},$env{'user.name'},
$env{'user.home'},
"Switch Server to $env{'form.otherserver'} with role $env{'form.role'} $ENV{'REMOTE_ADDR'}");
&Apache::loncommon::content_type($r,'text/html');
#expire the cookie
my $c = new CGI::Cookie(-name => 'lonID',
-value => '',
-expires => '-10y',);
$r->header_out('Set-cookie' => $c);
if ($r->header_only) {
$r->send_http_header;
return OK;
}
# -------------------------------------------------------- Menu script and info
# ---------------------------------------------------------------- Get handover
my ($is_balancer) = &Apache::lonnet::check_loadbalancing($env{'user.name'},$env{'user.domain'});
my %info=('ip' => $ENV{'REMOTE_ADDR'},
'domain' => $env{'user.domain'},
'username' => $env{'user.name'},
'role' => $env{'form.role'},
'server' => $r->dir_config('lonHostID'),
'balancer' => $is_balancer);
if ($env{'form.origurl'}) {
$info{'origurl'} = $env{'form.origurl'};
}
if ($env{'form.symb'}) {
$info{'symb'} = $env{'form.symb'};
}
if ($env{'request.sso.login'}) {
$info{'sso.login'} = $env{'request.sso.login'};
}
if ($env{'request.sso.reloginserver'}) {
$info{'sso.reloginserver'} = $env{'request.sso.reloginserver'};
}
my $token = &Apache::lonnet::tmpput(\%info,$env{'form.otherserver'});
my $url ='http://'.$switch_to.'/adm/login?'.
'domain='.$env{'user.domain'}.
'&username='.$env{'user.name'}.
'&token='.$token;
# --------------------------------------------------------------- Screen Output
return &do_redirect($r, $url, 0);
}
1;
__END__
FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>