--- loncom/interface/loncreateuser.pm 2001/10/16 21:16:01 1.19 +++ loncom/interface/loncreateuser.pm 2002/02/08 19:40:42 1.24 @@ -1,6 +1,30 @@ -# The LearningOnline Network +# The LearningOnline Network with CAPA # Create a user # +# $Id: loncreateuser.pm,v 1.24 2002/02/08 19:40:42 matthew Exp $ +# +# Copyright Michigan State University Board of Trustees +# +# This file is part of the LearningOnline Network with CAPA (LON-CAPA). +# +# LON-CAPA is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# +# LON-CAPA is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with LON-CAPA; if not, write to the Free Software +# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA +# +# /home/httpd/html/adm/gpl.txt +# +# http://www.lon-capa.org/ +# # (Create a course # (My Desk # @@ -10,6 +34,7 @@ # 5/21/99,5/22,5/25,5/26,5/31,6/2,6/10,7/12,7/14, # 1/14/00,5/29,5/30,6/1,6/29,7/1,11/9 Gerd Kortemeyer) # +# YEAR=2001 # 3/1/1 Gerd Kortemeyer) # # 3/1 Gerd Kortemeyer) @@ -19,13 +44,144 @@ # 2/14,2/17,2/19,2/20,2/21,2/22,2/23,3/2,3/17,3/24,04/12 Gerd Kortemeyer # April Guy Albertelli # 05/10,10/16 Gerd Kortemeyer +# 11/12,11/13,11/15 Scott Harrison # +# $Id: loncreateuser.pm,v 1.24 2002/02/08 19:40:42 matthew Exp $ +### + package Apache::loncreateuser; use strict; use Apache::Constants qw(:common :http); use Apache::lonnet; +my $loginscript; # piece of javascript used in two separate instances +my $generalrule; +my $authformnop; +my $authformkrb; +my $authformint; +my $authformfsys; +my $authformloc; + +BEGIN { + $ENV{'SERVER_NAME'}=~/(\w+\.\w+)$/; + my $krbdefdom=$1; + $krbdefdom=~tr/a-z/A-Z/; + $authformnop=(<<END); +<p> +<input type=radio name=login value=nop checked='checked' +onClick="clicknop(this.form);"> +Do not change login data +</p> +END + $authformkrb=(<<END); +<p> +<input type=radio name=login value=krb onClick="clickkrb(this.form);"> +Kerberos authenticated with domain +<input type=text size=10 name=krbdom onChange="setkrb(this.form);"> +</p> +END + $authformint=(<<END); +<p> +<input type=radio name=login value=int onClick="clickint(this.form);"> +Internally authenticated (with initial password +<input type=text size=10 name=intpwd onChange="setint(this.form);">) +</p> +END + $authformfsys=(<<END); +<p> +<input type=radio name=login value=fsys onClick="clickfsys(this.form);"> +Filesystem authenticated (with initial password +<input type=text size=10 name=fsyspwd onChange="setfsys(this.form);">) +</p> +END + $authformloc=(<<END); +<p> +<input type=radio name=login value=loc onClick="clickloc(this.form);" /> +Local Authentication with argument +<input type=text size=10 name=locarg onChange="setloc(this.form);" /> +</p> +END + $loginscript=(<<ENDLOGINSCRIPT); +<script> +function setkrb(vf) { + if (vf.krbdom.value!='') { + vf.login[0].checked=true; + vf.krbdom.value=vf.krbdom.value.toUpperCase(); + vf.intpwd.value=''; + vf.fsyspwd.value=''; + vf.locarg.value=''; + } +} + +function setint(vf) { + if (vf.intpwd.value!='') { + vf.login[1].checked=true; + vf.krbdom.value=''; + vf.fsyspwd.value=''; + vf.locarg.value=''; + } +} + +function setfsys(vf) { + if (vf.fsyspwd.value!='') { + vf.login[2].checked=true; + vf.krbdom.value=''; + vf.intpwd.value=''; + vf.locarg.value=''; + } +} + +function setloc(vf) { + if (vf.locarg.value!='') { + vf.login[3].checked=true; + vf.krbdom.value=''; + vf.intpwd.value=''; + vf.fsyspwd.value=''; + } +} + +function clicknop(vf) { + vf.krbdom.value=''; + vf.intpwd.value=''; + vf.fsyspwd.value=''; + vf.locarg.value=''; +} + +function clickkrb(vf) { + vf.krbdom.value='$krbdefdom'; + vf.intpwd.value=''; + vf.fsyspwd.value=''; + vf.locarg.value=''; +} + +function clickint(vf) { + vf.krbdom.value=''; + vf.fsyspwd.value=''; + vf.locarg.value=''; +} + +function clickfsys(vf) { + vf.krbdom.value=''; + vf.intpwd.value=''; + vf.locarg.value=''; +} + +function clickloc(vf) { + vf.krbdom.value=''; + vf.intpwd.value=''; + vf.fsyspwd.value=''; +} +</script> +ENDLOGINSCRIPT + $generalrule=<<END; +<p> +<i>As a general rule, only authors or co-authors should be filesystem +authenticated (which allows access to the server filesystem).</i> +</p> +END +} + # =================================================================== Phase one sub phase_one { @@ -110,80 +266,35 @@ ENDENHEAD my $uhome=&Apache::lonnet::homeserver($ccuname,$ccdomain); my %incdomains; my %inccourses; - map { + foreach (%Apache::lonnet::hostdom) { $incdomains{$_}=1; - } values %Apache::lonnet::hostdom; - map { + } + foreach (keys(%ENV)) { if ($_=~/^user\.priv\.cm\.\/(\w+)\/(\w+)/) { $inccourses{$1.'_'.$2}=1; } - } %ENV; + } if ($uhome eq 'no_host') { $r->print(<<ENDNUSER); <h2>New user $ccuname at $ccdomain</h2> -<script> -function setkrb(vf) { - if (vf.krbdom.value!='') { - vf.login[0].checked=true; - vf.krbdom.value=vf.krbdom.value.toUpperCase(); - vf.intpwd.value=''; - vf.locarg.value=''; - } -} - -function setint(vf) { - if (vf.intpwd.value!='') { - vf.login[1].checked=true; - vf.krbdom.value=''; - vf.locarg.value=''; - } -} - -function setloc(vf) { - if (vf.locarg.value!='') { - vf.login[2].checked=true; - vf.krbdom.value=''; - vf.intpwd.value=''; - } -} - -function clickkrb(vf) { - vf.krbdom.value='$krbdefdom'; - vf.intpwd.value=''; - vf.locarg.value=''; -} - -function clickint(vf) { - vf.krbdom.value=''; - vf.locarg.value=''; -} - -function clickloc(vf) { - vf.krbdom.value=''; - vf.intpwd.value=''; -} -</script> -<input type=hidden name=makeuser value=1> +ENDNUSER + $r->print(<<ENDNUSER); +$loginscript +<input type='hidden' name='makeuser' value='1' /> <h3>Personal Data</h3> -First Name: <input type=text name=cfirst size=15><br> -Middle Name: <input type=text name=cmiddle size=15><br> -Last Name: <input type=text name=clast size=15><br> -Generation: <input type=text name=cgen size=5><p> +First Name: <input type='text' name='cfirst' size='15' /><br /> +Middle Name: <input type='text' name='cmiddle' size='15' /><br /> +Last Name: <input type='text' name='clast' size='15' /><br /> +Generation: <input type='text' name='cgen' size='5' /><p> -ID/Student Number: <input type=text name=cstid size=10><p> +ID/Student Number: <input type='text' name='cstid' size='10' /></p> <h3>Login Data</h3> -<input type=radio name=login value=krb onClick="clickkrb(this.form);"> -Kerberos authenticated with domain -<input type=text size=10 name=krbdom onChange="setkrb(this.form);"><p> -<input type=radio name=login value=int onClick="clickint(this.form);"> -Internally authenticated (with initial password -<input type=text size=10 name=intpwd onChange="setint(this.form);">) -<p> -<input type=radio name=login value=loc onClick="clickloc(this.form);" /> -Local Authentication with argument -<input type=text size=10 name=locarg onChange="setloc(this.form);" /> -</p> +$generalrule +$authformkrb +$authformint +$authformfsys +$authformloc ENDNUSER } else { $r->print('<h2>Existing user '.$ccuname.' at '.$ccdomain.'</h2>'); @@ -195,7 +306,7 @@ ENDNUSER $r->print('<h4>Revoke Existing Roles</h4>'. '<table border=2><tr><th>Revoke</th><th>Role</th><th>Extent</th>'. '<th>Start</th><th>End</th>'); - map { + foreach (split(/&/,$rolesdump)) { if ($_!~/^rolesdef\&/) { my ($area,$role)=split(/=/,$_); @@ -249,11 +360,103 @@ ENDNUSER ($tstart?localtime($tstart):' ').'</td><td>'. ($tend?localtime($tend):' ')."</td></tr>\n"); } - } split(/&/,$rolesdump); + } $r->print('</table>'); } + my $currentauth=&Apache::lonnet::queryauthenticate($ccuname,$ccdomain); + if ($currentauth=~/^krb4:/) { + $currentauth=~/^krb4:(.*)/; + my $krbdefdom2=$1; + $loginscript=~s/vf\.krbdom\.value='.*?';/vf.krbdom.value='$krbdefdom2';/; + } + # minor script hack here +# $loginscript=~s/login\[3\]/login\[4\]/; # loc +# $loginscript=~s/login\[2\]/login\[3\]/; # fsys +# $loginscript=~s/login\[1\]/login\[2\]/; # int +# $loginscript=~s/login\[0\]/login\[1\]/; # krb4 + + unless ($currentauth=~/^krb4:/ or + $currentauth=~/^unix:/ or + $currentauth=~/^internal:/ or + $currentauth=~/^localauth:/ + ) { + $r->print(<<END); +<hr /> +$loginscript +<font color='#ff0000'>ERROR:</font> +This user has an unrecognized authentication scheme ($currentauth). +Please specify login data below. +<h3>Login Data</h3> +$generalrule +$authformkrb +$authformint +$authformfsys +$authformloc +END + } + else { + my $authformcurrent=''; + my $authformother=''; + if ($currentauth=~/^krb4:/) { + $authformcurrent=$authformkrb; + $authformother=$authformint.$authformfsys.$authformloc; + # embarrassing script hack here + $loginscript=~s/login\[3\]/login\[4\]/; # loc + $loginscript=~s/login\[2\]/login\[3\]/; # fsys + $loginscript=~s/login\[1\]/login\[2\]/; # int + $loginscript=~s/login\[0\]/login\[1\]/; # krb4 + } + elsif ($currentauth=~/^internal:/) { + $authformcurrent=$authformint; + $authformother=$authformkrb.$authformfsys.$authformloc; + # embarrassing script hack here + $loginscript=~s/login\[3\]/login\[4\]/; # loc + $loginscript=~s/login\[2\]/login\[3\]/; # fsys + $loginscript=~s/login\[1\]/login\[1\]/; # int + $loginscript=~s/login\[0\]/login\[2\]/; # krb4 + } + elsif ($currentauth=~/^unix:/) { + $authformcurrent=$authformfsys; + $authformother=$authformkrb.$authformint.$authformloc; + # embarrassing script hack here + $loginscript=~s/login\[3\]/login\[4\]/; # loc + $loginscript=~s/login\[1\]/login\[3\]/; # int + $loginscript=~s/login\[2\]/login\[1\]/; # fsys + $loginscript=~s/login\[0\]/login\[2\]/; # krb4 + } + elsif ($currentauth=~/^localauth:/) { + $authformcurrent=$authformloc; + $authformother=$authformkrb.$authformint.$authformfsys; + # embarrassing script hack here + $loginscript=~s/login\[3\]/login\[loc\]/; # loc + $loginscript=~s/login\[2\]/login\[4\]/; # fsys + $loginscript=~s/login\[1\]/login\[3\]/; # int + $loginscript=~s/login\[0\]/login\[2\]/; # krb4 + $loginscript=~s/login\[loc\]/login\[1\]/; # loc + } + $authformcurrent=<<END; +<table border='1'> +<tr> +<td><font color='#ff0000'>* * * WARNING * * *</font></td> +<td><font color='#ff0000'>* * * WARNING * * *</font></td> +</tr> +<tr><td bgcolor='#cbbcbb'>$authformcurrent</td> +<td bgcolor='#cbbcbb'>Changing this value will overwrite existing authentication for the user; you should notify the user of this change.</td></tr> +</table> +END + $r->print(<<END); +<hr /> +$loginscript +<h3>Change Current Login Data</h3> +$generalrule +$authformnop +$authformcurrent +<h3>Enter New Login Data</h3> +$authformother +END + } } - $r->print('<hr><h3>Add Roles</h3>'); + $r->print('<hr /><h3>Add Roles</h3>'); # # Co-Author # @@ -285,9 +488,9 @@ ENDCOAUTH $r->print('<h4>Domain Level</h4>'. '<table border=2><tr><th>Activate</th><th>Role</th><th>Extent</th>'. '<th>Start</th><th>End</th></tr>'); - map { + foreach ( sort( keys(%incdomains))) { my $thisdomain=$_; - map { + foreach ('dc','li','dg','au') { if (&Apache::lonnet::allowed('c'.$_,$thisdomain)) { my $plrole=&Apache::lonnet::plaintext($_); $r->print(<<ENDDROW); @@ -304,8 +507,8 @@ ENDCOAUTH </tr> ENDDROW } - } ('dc','li','dg','au'); - } sort keys %incdomains; + } + } $r->print('</table>'); # # Course level @@ -313,7 +516,7 @@ ENDDROW $r->print('<h4>Course Level</h4>'. '<table border=2><tr><th>Activate</th><th>Role</th><th>Extent</th>'. '<th>Group/Section</th><th>Start</th><th>End</th></tr>'); - map { + foreach (sort( keys(%inccourses))) { my $thiscourse=$_; my $protectedcourse=$_; $thiscourse=~s:_:/:g; @@ -322,7 +525,7 @@ ENDDROW my $bgcol=$thiscourse; $bgcol=~s/[^8-9b-e]//g; $bgcol=substr($bgcol.$bgcol.$bgcol.'ffffff',0,6); - map { + foreach ('st','ta','ep','ad','in','cc') { if (&Apache::lonnet::allowed('c'.$_,$thiscourse)) { my $plrole=&Apache::lonnet::plaintext($_); $r->print(" @@ -344,8 +547,8 @@ ENDDROW </tr> ENDROW } - } ('st','ta','ep','ad','in','cc'); - } sort keys %inccourses; + } + } $r->print('</table>'); $r->print('<input type=submit value="Modify User">'); $r->print('</form></body></html>'); @@ -377,6 +580,9 @@ ENDTHREEHEAD } elsif ($ENV{'form.login'} eq 'int') { $amode='internal'; $genpwd=$ENV{'form.intpwd'}; + } elsif ($ENV{'form.login'} eq 'fsys') { + $amode='unix'; + $genpwd=$ENV{'form.fsyspwd'}; } elsif ($ENV{'form.login'} eq 'loc') { $amode='localauth'; $genpwd=$ENV{'form.locarg'}; @@ -398,9 +604,44 @@ ENDTHREEHEAD $r->print('Invalid username or domain'); } } + if (!$ENV{'form.makeuser'} and $ENV{'form.login'} ne 'nop') { + $r->print('<h3>Changing User Login Data</h3>'); + if (($ENV{'form.cuname'})&&($ENV{'form.cuname'}!~/\W/)&& + ($ENV{'form.cdomain'})&&($ENV{'form.cdomain'}!~/\W/)) { + my $amode=''; + my $genpwd=''; + if ($ENV{'form.login'} eq 'krb') { + $amode='krb4'; + $genpwd=$ENV{'form.krbdom'}; + } elsif ($ENV{'form.login'} eq 'int') { + $amode='internal'; + $genpwd=$ENV{'form.intpwd'}; + } elsif ($ENV{'form.login'} eq 'fsys') { + $amode='unix'; + $genpwd=$ENV{'form.fsyspwd'}; + } elsif ($ENV{'form.login'} eq 'loc') { + $amode='localauth'; + $genpwd=$ENV{'form.locarg'}; + if (!$genpwd) { $genpwd=" "; } + } + if (($amode) && ($genpwd)) { + $r->print('Modifying authentication: '. + &Apache::lonnet::modifyuserauth( + $ENV{'form.cdomain'},$ENV{'form.cuname'}, + $amode,$genpwd)); + $r->print('<br>Home server: '.&Apache::lonnet::homeserver + ($ENV{'form.cuname'},$ENV{'form.cdomain'})); + + } else { + $r->print('Invalid login mode or password'); + } + } else { + $r->print('Invalid username or domain'); + } + } my $now=time; $r->print('<h3>Modifying Roles</h3>'); - map { + foreach (keys (%ENV)) { if (($_=~/^form\.rev\:([^\_]+)\_([^\_]+)$/) && ($ENV{$_})) { $r->print('Revoking '.$2.' in '.$1.': '. &Apache::lonnet::assignrole($ENV{'form.cdomain'},$ENV{'form.cuname'}, @@ -417,8 +658,8 @@ ENDTHREEHEAD $ENV{'course.'.$cid.'.home'}).'<br>'); } } - } keys %ENV; - map { + } + foreach (keys(%ENV)) { if (($_=~/^form\.act\_([^\_]+)\_([^\_]+)\_([^\_]+)$/) && ($ENV{$_})) { my $url='/'.$1.'/'.$2; if ($ENV{'form.sec_'.$1.'_'.$2.'_'.$3}) { @@ -460,7 +701,7 @@ ENDTHREEHEAD &Apache::lonnet::assignrole($ENV{'form.cdomain'},$ENV{'form.cuname'}, $url,$2,$end,$start).'<br>'); } - } keys %ENV; + } $r->print('</body></html>'); }