--- loncom/auth/lonlogout.pm 2000/06/07 19:31:05 1.1
+++ loncom/auth/lonlogout.pm 2007/10/01 20:36:37 1.28
@@ -1,9 +1,30 @@
# The LearningOnline Network
# Logout Handler
-# (Cookie Based Access Handler
-# 5/21/99,5/22,5/29,5/31,6/15,16/11,22/11,
-# 01/06,01/13 Gerd Kortemeyer)
-# 05/31 Gerd Kortemeyer
+#
+# $Id: lonlogout.pm,v 1.28 2007/10/01 20:36:37 albertel Exp $
+#
+# Copyright Michigan State University Board of Trustees
+#
+# This file is part of the LearningOnline Network with CAPA (LON-CAPA).
+#
+# LON-CAPA is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 2 of the License, or
+# (at your option) any later version.
+#
+# LON-CAPA is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with LON-CAPA; if not, write to the Free Software
+# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
+#
+# /home/httpd/html/adm/gpl.txt
+#
+# http://www.lon-capa.org/
+#
package Apache::lonlogout;
@@ -11,52 +32,120 @@ use strict;
use Apache::Constants qw(:common);
use Apache::File;
use Apache::lonnet;
+use Apache::lonmenu;
use CGI::Cookie();
+use Apache::lonlocal;
sub handler {
my $r = shift;
+ #Check for cookie
my $requrl=$r->uri;
my %cookies=CGI::Cookie->parse($r->header_in('Cookie'));
my $lonid=$cookies{'lonID'};
my $cookie;
- if ($lonid) {
- my $handle=$lonid->value;
- $handle=~s/\W//g;
- my $lonidsdir=$r->dir_config('lonIDsDir');
- if ((-e "$lonidsdir/$handle.id") && ($handle ne '')) {
- my @profile;
- my %sessionhash;
- {
- my $idf=Apache::File->new("$lonidsdir/$handle.id");
- @profile=<$idf>;
+ if (!$lonid) {
+ return FORBIDDEN;
+ }
+
+ #check if cookie still valid
+ my $handle=&LONCAPA::clean_handle($lonid->value);
+ my $lonidsdir=$r->dir_config('lonIDsDir');
+ if ((!-e "$lonidsdir/$handle.id") || ($handle eq '')) {
+ $r->log_reason("Cookie $handle not valid", $r->filename);
+ return FORBIDDEN;
+ }
+
+ #we've got a valid user
+ my @profile;
+ &Apache::lonnet::transfer_profile_to_env($lonidsdir,$handle);
+ unlink("$lonidsdir/$handle.id");
+ my %temp=('logout' => time);
+ &Apache::lonnet::put('email_status',\%temp);
+ &Apache::lonnet::log($env{'user.domain'},
+ $env{'user.name'},
+ $env{'user.home'},
+ "Logout $ENV{'REMOTE_ADDR'}");
+
+ &Apache::loncommon::content_type($r,'text/html');
+
+ #expire the cookie
+ my $c = new CGI::Cookie(-name => 'lonID',
+ -value => '',
+ -expires => '-10y',);
+ $r->header_out('Set-cookie' => $c);
+
+ $r->send_http_header;
+ return OK if $r->header_only;
+# -------------------------------------------------------- Menu script and info
+
+ my $windowinfo=&Apache::lonmenu::close();
+ $windowinfo.=&Apache::lonnavmaps::close();
+# ---------------------------------------------------------------- Get handover
+ &Apache::loncommon::get_unprocessed_cgi($ENV{'QUERY_STRING'},['handover']);
+ my $switch='';
+ my $start_page='';
+ my $relogmessage='';
+ if ($env{'form.handover'}) {
+ $switch='';
+ $start_page=&Apache::loncommon::start_page('Switching Server ...',
+ $switch);
+ } else {
+ $start_page=&Apache::loncommon::start_page('Logged Out',undef,
+ {'no_inline_link' => 1,});
+ my %lt=&Apache::lonlocal::texthash('gb' => 'Goodbye',
+ 'cw' => 'close this window',
+ 'li' => 'log in again',
+ 'pe' => 'Please either',
+ 'or' => 'or');
+
+ $relogmessage.=(<$lt{'gb'}!
+ENDRELOG
+
+ if (!$env{'request.sso.norelogin'}) {
+ my $relogin_server;
+ if ($env{'request.sso.reloginserver'}) {
+ $relogin_server = $env{'request.sso.reloginserver'};
}
- my $envi;
- for ($envi=0;$envi<=$#profile;$envi++) {
- chomp($profile[$envi]);
- my ($envname,$envvalue)=split(/=/,$profile[$envi]);
- $sessionhash{$envname}=$envvalue;
- }
- unlink("$lonidsdir/$handle.id");
- &Apache::lonnet::log($sessionhash{'user.domain'},
- $sessionhash{'user.name'},
- $sessionhash{'user.home'},
- "Logout $ENV{'REMOTE_ADDR'}");
- $r->content_type('text/html');
- $r->send_http_header;
- return OK if $r->header_only;
- $r->print(<
-The LearningOnline Network with CAPA Logout
-Goodbye!
-