# The LearningOnline Network
# User Authentication Module
# 5/21/99,5/22,5/25,5/26,5/27,5/29,6/2,6/11,6/14,6/15
# 16/11 Gerd Kortemeyer
package Apache::lonauth;
use Apache::Constants qw(:common);
use Apache::File;
use CGI qw(:standard);
use CGI::Cookie();
use Apache::lonnet();
# ------------------------------------------------------------ Successful login
sub success {
my ($r, $lowerurl, $username, $domain, $authhost) = @_;
my $lonids=$r->dir_config('lonIDsDir');
# See if old ID present, but overlooked
my $cookie;
if ($cookie=<$lonids/$username\_*\_$domain\_$authhost.id>) {
$cookie=~s/\.id//;
$cookie=~s/$lonids\///;
} else {
my $now=time;
$cookie="$username\_$now\_$domain\_$authhost";
{
my $idf=Apache::File->new(">$lonids/$cookie.id");
print $idf "username=$username\n";
print $idf "userdomain=$domain\n";
print $idf "userhome=$authhost\n";
}
}
$cookie="lonID=$cookie; path=/";
$r->send_cgi_header(<<ENDHEADER);
Content-type: text/html
Set-cookie: $cookie
ENDHEADER
$r->print(<<ENDSUCCESS);
<html>
<head>
<title>Successful Login to the LearningOnline Network</title>
</head>
<frameset rows="80,*" border=0>
<frame scrolling="no" name="loncontrol" src="/adm/menu">
<frame name="loncontent" src="$lowerurl">
</frameset>
</html>
ENDSUCCESS
}
# --------------------------------------------------------------- Failed login!
sub failed {
my ($r,$message) = @_;
$r->send_cgi_header(<<ENDFHEADER);
Content-type: text/html
ENDFHEADER
$r->print(<<ENDFAILED);
<html>
<head>
<title>Unsuccessful Login to the LearningOnline Network</title>
</head>
<html>
<body bgcolor="#FFFFFF">
<h1>Sorry ...</h1>
<h2>$message to use the Learning<i>Online</i> Network</h2>
</body>
</html>
ENDFAILED
}
# ---------------------------------------------------------------- Main handler
sub handler {
my $r = shift;
my $buffer;
$r->read($buffer,$r->header_in('Content-length'));
my @pairs=split(/&/,$buffer);
my $pair; my $name; my $value; my %FORM;
foreach $pair (@pairs) {
($name,$value) = split(/=/,$pair);
$FORM{$name}=$value;
}
if ((!$FORM{'uname'}) || (!$FORM{'upass'}) || (!$FORM{'udom'})) {
failed($r,'Username, password and domain need to be specified');
return OK;
}
$FORM{'uname'} =~ s/\W//g;
$FORM{'upass'} =~ s/\W//g;
$FORM{'udom'} =~ s/\W//g;
my $role = $r->dir_config('lonRole');
my $domain = $r->dir_config('lonDefDomain');
my $prodir = $r->dir_config('lonUsersDir');
# ---------------------------------------------------------------- Authenticate
my $authhost=Apache::lonnet::authenticate($FORM{'uname'},
$FORM{'upass'},
$FORM{'udom'});
# --------------------------------------------------------------------- Failed?
if ($authhost eq 'no_host') {
failed($r,'Username and/or password could not be authenticated');
return OK;
}
my %cookies=CGI::Cookie->parse($r->header_in('Cookie'));
my $lonurl=$cookies{'lonURL'};
if (!$lonurl) { failed($r,'Cookies need to be activated'); return OK; }
my $lowerurl=$lonurl->value;
success($r,$lowerurl,$FORM{'uname'},$FORM{'udom'},$authhost);
return OK;
}
1;
__END__
FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>