1: # The LearningOnline Network with CAPA
2: # Create a user
3: #
4: # $Id: loncreateuser.pm,v 1.159 2007/07/20 23:57:06 albertel Exp $
5: #
6: # Copyright Michigan State University Board of Trustees
7: #
8: # This file is part of the LearningOnline Network with CAPA (LON-CAPA).
9: #
10: # LON-CAPA is free software; you can redistribute it and/or modify
11: # it under the terms of the GNU General Public License as published by
12: # the Free Software Foundation; either version 2 of the License, or
13: # (at your option) any later version.
14: #
15: # LON-CAPA is distributed in the hope that it will be useful,
16: # but WITHOUT ANY WARRANTY; without even the implied warranty of
17: # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18: # GNU General Public License for more details.
19: #
20: # You should have received a copy of the GNU General Public License
21: # along with LON-CAPA; if not, write to the Free Software
22: # Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
23: #
24: # /home/httpd/html/adm/gpl.txt
25: #
26: # http://www.lon-capa.org/
27: #
28: ###
29:
30: package Apache::loncreateuser;
31:
32: =pod
33:
34: =head1 NAME
35:
36: Apache::loncreateuser - handler to create users and custom roles
37:
38: =head1 SYNOPSIS
39:
40: Apache::loncreateuser provides an Apache handler for creating users,
41: editing their login parameters, roles, and removing roles, and
42: also creating and assigning custom roles.
43:
44: =head1 OVERVIEW
45:
46: =head2 Custom Roles
47:
48: In LON-CAPA, roles are actually collections of privileges. "Teaching
49: Assistant", "Course Coordinator", and other such roles are really just
50: collection of privileges that are useful in many circumstances.
51:
52: Creating custom roles can be done by the Domain Coordinator through
53: the Create User functionality. That screen will show all privileges
54: that can be assigned to users. For a complete list of privileges,
55: please see C</home/httpd/lonTabs/rolesplain.tab>.
56:
57: Custom role definitions are stored in the C<roles.db> file of the role
58: author.
59:
60: =cut
61:
62: use strict;
63: use Apache::Constants qw(:common :http);
64: use Apache::lonnet;
65: use Apache::loncommon;
66: use Apache::lonlocal;
67: use Apache::longroup;
68: use LONCAPA qw(:DEFAULT :match);
69:
70: my $loginscript; # piece of javascript used in two separate instances
71: my $generalrule;
72: my $authformnop;
73: my $authformkrb;
74: my $authformint;
75: my $authformfsys;
76: my $authformloc;
77:
78: sub initialize_authen_forms {
79: my ($krbdefdom)=( $ENV{'SERVER_NAME'}=~/(\w+\.\w+)$/);
80: $krbdefdom= uc($krbdefdom);
81: my %param = ( formname => 'document.cu',
82: kerb_def_dom => $krbdefdom
83: );
84: # no longer static due to configurable kerberos defaults
85: # $loginscript = &Apache::loncommon::authform_header(%param);
86: $generalrule = &Apache::loncommon::authform_authorwarning(%param);
87: $authformnop = &Apache::loncommon::authform_nochange(%param);
88: # no longer static due to configurable kerberos defaults
89: # $authformkrb = &Apache::loncommon::authform_kerberos(%param);
90: $authformint = &Apache::loncommon::authform_internal(%param);
91: $authformfsys = &Apache::loncommon::authform_filesystem(%param);
92: $authformloc = &Apache::loncommon::authform_local(%param);
93: }
94:
95:
96: # ======================================================= Existing Custom Roles
97:
98: sub my_custom_roles {
99: my %returnhash=();
100: my %rolehash=&Apache::lonnet::dump('roles');
101: foreach my $key (keys %rolehash) {
102: if ($key=~/^rolesdef\_(\w+)$/) {
103: $returnhash{$1}=$1;
104: }
105: }
106: return %returnhash;
107: }
108:
109: # ==================================================== Figure out author access
110:
111: sub authorpriv {
112: my ($auname,$audom)=@_;
113: unless ((&Apache::lonnet::allowed('cca',$audom.'/'.$auname))
114: || (&Apache::lonnet::allowed('caa',$audom.'/'.$auname))) { return ''; }
115: return 1;
116: }
117:
118: # ====================================================
119:
120: sub portfolio_quota {
121: my ($ccuname,$ccdomain) = @_;
122: my %lt = &Apache::lonlocal::texthash(
123: 'disk' => "Disk space allocated to user's portfolio files",
124: 'cuqu' => "Current quota",
125: 'cust' => "Custom quota",
126: 'defa' => "Default",
127: 'chqu' => "Change quota",
128: );
129: my ($currquota,$quotatype,$inststatus,$defquota) =
130: &Apache::loncommon::get_user_quota($ccuname,$ccdomain);
131: my ($usertypes,$order) = &Apache::lonnet::retrieve_inst_usertypes($ccdomain);
132: my ($longinsttype,$showquota,$custom_on,$custom_off,$defaultinfo);
133: if ($inststatus ne '') {
134: if ($usertypes->{$inststatus} ne '') {
135: $longinsttype = $usertypes->{$inststatus};
136: }
137: }
138: $custom_on = ' ';
139: $custom_off = ' checked="checked" ';
140: my $quota_javascript = <<"END_SCRIPT";
141: <script type="text/javascript">
142: function quota_changes(caller) {
143: if (caller == "custom") {
144: if (document.cu.customquota[0].checked) {
145: document.cu.portfolioquota.value = "";
146: }
147: }
148: if (caller == "quota") {
149: document.cu.customquota[1].checked = true;
150: }
151: }
152: </script>
153: END_SCRIPT
154: if ($quotatype eq 'custom') {
155: $custom_on = $custom_off;
156: $custom_off = ' ';
157: $showquota = $currquota;
158: if ($longinsttype eq '') {
159: $defaultinfo = &mt('For this user, the default quota would be [_1]
160: Mb.',$defquota);
161: } else {
162: $defaultinfo = &mt("For this user, the default quota would be [_1]
163: Mb, as determined by the user's institutional
164: affiliation ([_2]).",$defquota,$longinsttype);
165: }
166: } else {
167: if ($longinsttype eq '') {
168: $defaultinfo = &mt('For this user, the default quota is [_1]
169: Mb.',$defquota);
170: } else {
171: $defaultinfo = &mt("For this user, the default quota of [_1]
172: Mb, is determined by the user's institutional
173: affiliation ([_2]).",$defquota,$longinsttype);
174: }
175: }
176: my $output = $quota_javascript.
177: '<h3>'.$lt{'disk'}.'</h3>'.
178: $lt{'cuqu'}.': '.$currquota.' Mb. '.
179: $defaultinfo.'<br /><span class="LC_nobreak">'.$lt{'chqu'}.
180: ': <label>'.
181: '<input type="radio" name="customquota" value="0" '.
182: $custom_off.' onchange="javascript:quota_changes('."'custom'".')"
183: />'.$lt{'defa'}.' ('.$defquota.' Mb).</label> '.
184: ' <label><input type="radio" name="customquota" value="1" '.
185: $custom_on.' onchange="javascript:quota_changes('."'custom'".')" />'.
186: $lt{'cust'}.':</label> '.
187: '<input type="text" name="portfolioquota" size ="5" value="'.
188: $showquota.'" onfocus="javascript:quota_changes('."'quota'".')" '.
189: '/> Mb';
190: return $output;
191: }
192:
193: # =================================================================== Phase one
194:
195: sub print_username_entry_form {
196: my ($r) = @_;
197: my $defdom=$env{'request.role.domain'};
198: my $domform = &Apache::loncommon::select_dom_form($defdom,'ccdomain');
199: my $selscript=&Apache::loncommon::studentbrowser_javascript();
200: my $start_page =
201: &Apache::loncommon::start_page('Create Users, Change User Privileges',
202: $selscript);
203:
204: my $sellink=&Apache::loncommon::selectstudent_link
205: ('crtuser','ccuname','ccdomain');
206: my %existingroles=&my_custom_roles();
207: my $choice=&Apache::loncommon::select_form('make new role','rolename',
208: ('make new role' => 'Generate new role ...',%existingroles));
209: my %lt=&Apache::lonlocal::texthash(
210: 'siur' => "Set Individual User Roles",
211: 'usr' => "Username",
212: 'dom' => "Domain",
213: 'usrr' => "User Roles",
214: 'ecrp' => "Edit Custom Role Privileges",
215: 'nr' => "Name of Role",
216: 'cre' => "Custom Role Editor"
217: );
218: my $help = &Apache::loncommon::help_open_menu(undef,undef,282,'Instructor Interface');
219: my $helpsiur=&Apache::loncommon::help_open_topic('Course_Change_Privileges');
220: my $helpecpr=&Apache::loncommon::help_open_topic('Course_Editing_Custom_Roles');
221: $r->print(<<"ENDDOCUMENT");
222: $start_page
223: <form action="/adm/createuser" method="post" name="crtuser">
224: <input type="hidden" name="phase" value="get_user_info" />
225: <h2>$lt{siur}$helpsiur</h2>
226: <table>
227: <tr><td>$lt{usr}:</td><td><input type="text" size="15" name="ccuname" />
228: </td><td rowspan="2">$sellink</td></tr><tr><td>
229: $lt{'dom'}:</td><td>$domform</td></tr>
230: </table>
231: <input name="userrole" type="submit" value="$lt{usrr}" />
232: </form>
233: ENDDOCUMENT
234: if (&Apache::lonnet::allowed('mcr','/')) {
235: $r->print(<<ENDCUSTOM);
236: <form action="/adm/createuser" method="post" name="docustom">
237: <input type="hidden" name="phase" value="selected_custom_edit" />
238: <h2>$lt{'ecrp'}$helpecpr</h2>
239: $lt{'nr'}: $choice <input type="text" size="15" name="newrolename" /><br />
240: <input name="customeditor" type="submit" value="$lt{'cre'}" />
241: </form>
242: ENDCUSTOM
243: }
244: $r->print(&Apache::loncommon::end_page());
245: }
246:
247:
248: sub user_modification_js {
249: my ($pjump_def,$dc_setcourse_code,$nondc_setsection_code,$groupslist)=@_;
250:
251: return <<END;
252: <script type="text/javascript" language="Javascript">
253:
254: function pclose() {
255: parmwin=window.open("/adm/rat/empty.html","LONCAPAparms",
256: "height=350,width=350,scrollbars=no,menubar=no");
257: parmwin.close();
258: }
259:
260: $pjump_def
261: $dc_setcourse_code
262:
263: function dateset() {
264: eval("document.cu."+document.cu.pres_marker.value+
265: ".value=document.cu.pres_value.value");
266: pclose();
267: }
268:
269: $nondc_setsection_code
270:
271: </script>
272: END
273: }
274:
275: # =================================================================== Phase two
276: sub print_user_modification_page {
277: my $r=shift;
278: my $ccuname =&LONCAPA::clean_username($env{'form.ccuname'});
279: my $ccdomain=&LONCAPA::clean_domain($env{'form.ccdomain'});
280:
281: unless (($ccuname) && ($ccdomain)) {
282: &print_username_entry_form($r);
283: return;
284: }
285:
286: my $defdom=$env{'request.role.domain'};
287:
288: my ($krbdef,$krbdefdom) =
289: &Apache::loncommon::get_kerberos_defaults($defdom);
290:
291: my %param = ( formname => 'document.cu',
292: kerb_def_dom => $krbdefdom,
293: kerb_def_auth => $krbdef
294: );
295: $loginscript = &Apache::loncommon::authform_header(%param);
296: $authformkrb = &Apache::loncommon::authform_kerberos(%param);
297:
298: $ccuname =&LONCAPA::clean_username($ccuname);
299: $ccdomain=&LONCAPA::clean_domain($ccdomain);
300: my $pjump_def = &Apache::lonhtmlcommon::pjump_javascript_definition();
301: my $dc_setcourse_code = '';
302: my $nondc_setsection_code = '';
303:
304: my %loaditem;
305:
306: my $groupslist;
307: my %curr_groups = &Apache::longroup::coursegroups();
308: if (%curr_groups) {
309: $groupslist = join('","',sort(keys(%curr_groups)));
310: $groupslist = '"'.$groupslist.'"';
311: }
312:
313: if ($env{'request.role'} =~ m-^dc\./($match_domain)/$-) {
314: my $dcdom = $1;
315: $loaditem{'onload'} = "document.cu.coursedesc.value='';";
316: my @rolevals = ('st','ta','ep','in','cc');
317: my (@crsroles,@grproles);
318: for (my $i=0; $i<@rolevals; $i++) {
319: $crsroles[$i]=&Apache::lonnet::plaintext($rolevals[$i],'Course');
320: $grproles[$i]=&Apache::lonnet::plaintext($rolevals[$i],'Group');
321: }
322: my $rolevalslist = join('","',@rolevals);
323: my $crsrolenameslist = join('","',@crsroles);
324: my $grprolenameslist = join('","',@grproles);
325: my $pickcrsfirst = '<--'.&mt('Pick course first');
326: my $pickgrpfirst = '<--'.&mt('Pick group first');
327: $dc_setcourse_code = <<"ENDSCRIPT";
328: function setCourse() {
329: var course = document.cu.dccourse.value;
330: if (course != "") {
331: if (document.cu.dcdomain.value != document.cu.origdom.value) {
332: alert("You must select a course in the current domain");
333: return;
334: }
335: var userrole = document.cu.role.options[document.cu.role.selectedIndex].value
336: var section="";
337: var numsections = 0;
338: var newsecs = new Array();
339: for (var i=0; i<document.cu.currsec.length; i++) {
340: if (document.cu.currsec.options[i].selected == true ) {
341: if (document.cu.currsec.options[i].value != "" && document.cu.currsec.options[i].value != null) {
342: if (numsections == 0) {
343: section = document.cu.currsec.options[i].value
344: numsections = 1;
345: }
346: else {
347: section = section + "," + document.cu.currsec.options[i].value
348: numsections ++;
349: }
350: }
351: }
352: }
353: if (document.cu.newsec.value != "" && document.cu.newsec.value != null) {
354: if (numsections == 0) {
355: section = document.cu.newsec.value
356: }
357: else {
358: section = section + "," + document.cu.newsec.value
359: }
360: newsecs = document.cu.newsec.value.split(/,/g);
361: numsections = numsections + newsecs.length;
362: }
363: if ((userrole == 'st') && (numsections > 1)) {
364: alert("In each course, each user may only have one student role at a time. You had selected "+numsections+" sections.\\nPlease modify your selections so they include no more than one section.")
365: return;
366: }
367: for (var j=0; j<newsecs.length; j++) {
368: if ((newsecs[j] == 'all') || (newsecs[j] == 'none')) {
369: alert("'"+newsecs[j]+"' may not be used as the name for a section, as it is a reserved word.\\nPlease choose a different section name.");
370: return;
371: }
372: if (document.cu.groups.value != '') {
373: var groups = document.cu.groups.value.split(/,/g);
374: for (var k=0; k<groups.length; k++) {
375: if (newsecs[j] == groups[k]) {
376: alert("'"+newsecs[j]+"' may not be used as the name for a section, as it is the name of a course group.\\nSection names and group names must be distinct. Please choose a different section name.");
377: return;
378: }
379: }
380: }
381: }
382: if ((userrole == 'cc') && (numsections > 0)) {
383: alert("Section designations do not apply to Course Coordinator roles.\\nA course coordinator role will be added with access to all sections.");
384: section = "";
385: }
386: var coursename = "_$dcdom"+"_"+course+"_"+userrole
387: var numcourse = getIndex(document.cu.dccourse);
388: if (numcourse == "-1") {
389: alert("There was a problem with your course selection");
390: return
391: }
392: else {
393: document.cu.elements[numcourse].name = "act"+coursename;
394: var numnewsec = getIndex(document.cu.newsec);
395: if (numnewsec != "-1") {
396: document.cu.elements[numnewsec].name = "sec"+coursename;
397: document.cu.elements[numnewsec].value = section;
398: }
399: var numstart = getIndex(document.cu.start);
400: if (numstart != "-1") {
401: document.cu.elements[numstart].name = "start"+coursename;
402: }
403: var numend = getIndex(document.cu.end);
404: if (numend != "-1") {
405: document.cu.elements[numend].name = "end"+coursename
406: }
407: }
408: }
409: document.cu.submit();
410: }
411:
412: function getIndex(caller) {
413: for (var i=0;i<document.cu.elements.length;i++) {
414: if (document.cu.elements[i] == caller) {
415: return i;
416: }
417: }
418: return -1;
419: }
420: ENDSCRIPT
421: } else {
422: $nondc_setsection_code = <<"ENDSECCODE";
423: function setSections() {
424: var re1 = /^currsec_/;
425: var groups = new Array($groupslist);
426: for (var i=0;i<document.cu.elements.length;i++) {
427: var str = document.cu.elements[i].name;
428: var checkcurr = str.match(re1);
429: if (checkcurr != null) {
430: if (document.cu.elements[i-1].checked == true) {
431: var match = str.split('_');
432: var role = match[3];
433: if (role == 'cc') {
434: alert("Section designations do not apply to Course Coordinator roles.\\nA course coordinator role will be added with access to all sections.");
435: }
436: else {
437: var sections = '';
438: var numsec = 0;
439: var sections;
440: for (var j=0; j<document.cu.elements[i].length; j++) {
441: if (document.cu.elements[i].options[j].selected == true ) {
442: if (document.cu.elements[i].options[j].value != "") {
443: if (numsec == 0) {
444: if (document.cu.elements[i].options[j].value != "") {
445: sections = document.cu.elements[i].options[j].value;
446: numsec ++;
447: }
448: }
449: else {
450: sections = sections + "," + document.cu.elements[i].options[j].value
451: numsec ++;
452: }
453: }
454: }
455: }
456: if (numsec > 0) {
457: if (document.cu.elements[i+1].value != "" && document.cu.elements[i+1].value != null) {
458: sections = sections + "," + document.cu.elements[i+1].value;
459: }
460: }
461: else {
462: sections = document.cu.elements[i+1].value;
463: }
464: var newsecs = document.cu.elements[i+1].value;
465: var numsplit;
466: if (newsecs != null && newsecs != "") {
467: numsplit = newsecs.split(/,/g);
468: numsec = numsec + numsplit.length;
469: }
470:
471: if ((role == 'st') && (numsec > 1)) {
472: alert("In each course, each user may only have one student role at a time. You had selected "+numsec+" sections.\\nPlease modify your selections so they include no more than one section.")
473: return;
474: }
475: else if (numsplit != null) {
476: for (var j=0; j<numsplit.length; j++) {
477: if ((numsplit[j] == 'all') ||
478: (numsplit[j] == 'none')) {
479: alert("'"+numsplit[j]+"' may not be used as the name for a section, as it is a reserved word.\\nPlease choose a different section name.");
480: return;
481: }
482: for (var k=0; k<groups.length; k++) {
483: if (numsplit[j] == groups[k]) {
484: alert("'"+numsplit[j]+"' may not be used as a section name, as it is the name of a course group.\\nSection names and group names must be distinct. Please choose a different section name.");
485: return;
486: }
487: }
488: }
489: }
490: document.cu.elements[i+2].value = sections;
491: }
492: }
493: }
494: }
495: document.cu.submit();
496: }
497: ENDSECCODE
498: }
499: my $js = &user_modification_js($pjump_def,$dc_setcourse_code,
500: $nondc_setsection_code,$groupslist);
501: my $start_page =
502: &Apache::loncommon::start_page('Create Users, Change User Privileges',
503: $js,{'add_entries' => \%loaditem,});
504:
505: my $forminfo =<<"ENDFORMINFO";
506: <form action="/adm/createuser" method="post" name="cu">
507: <input type="hidden" name="phase" value="update_user_data" />
508: <input type="hidden" name="ccuname" value="$ccuname" />
509: <input type="hidden" name="ccdomain" value="$ccdomain" />
510: <input type="hidden" name="pres_value" value="" />
511: <input type="hidden" name="pres_type" value="" />
512: <input type="hidden" name="pres_marker" value="" />
513: ENDFORMINFO
514: my $uhome=&Apache::lonnet::homeserver($ccuname,$ccdomain);
515: my %inccourses;
516: foreach my $key (keys(%env)) {
517: if ($key=~/^user\.priv\.cm\.\/($match_domain)\/($match_username)/) {
518: $inccourses{$1.'_'.$2}=1;
519: }
520: }
521: if ($uhome eq 'no_host') {
522: my $home_server_list=
523: '<option value="default" selected>default</option>'."\n".
524: &Apache::loncommon::home_server_option_list($ccdomain);
525:
526: my %lt=&Apache::lonlocal::texthash(
527: 'cnu' => "Create New User",
528: 'nu' => "New User",
529: 'id' => "in domain",
530: 'pd' => "Personal Data",
531: 'fn' => "First Name",
532: 'mn' => "Middle Name",
533: 'ln' => "Last Name",
534: 'gen' => "Generation",
535: 'idsn' => "ID/Student Number",
536: 'hs' => "Home Server",
537: 'lg' => "Login Data"
538: );
539: my $portfolioform;
540: if (&Apache::lonnet::allowed('mpq',$env{'request.role.domain'})) {
541: # Current user has quota modification privileges
542: $portfolioform = &portfolio_quota($ccuname,$ccdomain);
543: }
544: my $genhelp=&Apache::loncommon::help_open_topic('Generation');
545: &initialize_authen_forms();
546: $r->print(<<ENDNEWUSER);
547: $start_page
548: <h1>$lt{'cnu'}</h1>
549: $forminfo
550: <h2>$lt{'nu'} "$ccuname" $lt{'id'} $ccdomain</h2>
551: <script type="text/javascript" language="Javascript">
552: $loginscript
553: </script>
554: <input type='hidden' name='makeuser' value='1' />
555: <h3>$lt{'pd'}</h3>
556: <p>
557: <table>
558: <tr><td>$lt{'fn'} </td>
559: <td><input type='text' name='cfirst' size='15' /></td></tr>
560: <tr><td>$lt{'mn'} </td>
561: <td><input type='text' name='cmiddle' size='15' /></td></tr>
562: <tr><td>$lt{'ln'} </td>
563: <td><input type='text' name='clast' size='15' /></td></tr>
564: <tr><td>$lt{'gen'}$genhelp</td>
565: <td><input type='text' name='cgen' size='5' /></td></tr>
566: </table>
567: $lt{'idsn'} <input type='text' name='cstid' size='15' /></p>
568: $lt{'hs'}: <select name="hserver" size="1"> $home_server_list </select>
569: <hr />
570: <h3>$lt{'lg'}</h3>
571: <p>$generalrule </p>
572: <p>$authformkrb </p>
573: <p>$authformint </p>
574: <p>$authformfsys</p>
575: <p>$authformloc </p>
576: <hr />
577: $portfolioform
578: ENDNEWUSER
579: } else { # user already exists
580: my %lt=&Apache::lonlocal::texthash(
581: 'cup' => "Change User Privileges",
582: 'usr' => "User",
583: 'id' => "in domain",
584: 'fn' => "first name",
585: 'mn' => "middle name",
586: 'ln' => "last name",
587: 'gen' => "generation"
588: );
589: $r->print(<<ENDCHANGEUSER);
590: $start_page
591: <h1>$lt{'cup'}</h1>
592: $forminfo
593: <h2>$lt{'usr'} "$ccuname" $lt{'id'} "$ccdomain"</h2>
594: ENDCHANGEUSER
595: # Get the users information
596: my %userenv = &Apache::lonnet::get('environment',
597: ['firstname','middlename','lastname','generation',
598: 'portfolioquota'],$ccdomain,$ccuname);
599: my %rolesdump=&Apache::lonnet::dump('roles',$ccdomain,$ccuname);
600: $r->print('
601: <hr />'.
602: &Apache::loncommon::start_data_table().
603: &Apache::loncommon::start_data_table_header_row().
604: '<th>'.$lt{'fn'}.'</th><th>'.$lt{'mn'}.'</th><th>'.$lt{'ln'}.'</th><th>'.$lt{'gen'}.'</th>'.
605: &Apache::loncommon::end_data_table_header_row().
606: &Apache::loncommon::start_data_table_row());
607: foreach my $item ('firstname','middlename','lastname','generation') {
608: if (&Apache::lonnet::allowed('mau',$ccdomain)) {
609: $r->print(<<"END");
610: <td><input type="text" name="c$item" value="$userenv{$item}" size="15" /></td>
611: END
612: } else {
613: $r->print('<td>'.$userenv{$item}.'</td>');
614: }
615: }
616: $r->print(&Apache::loncommon::end_data_table_row().
617: &Apache::loncommon::end_data_table());
618: # Build up table of user roles to allow revocation of a role.
619: my ($tmp) = keys(%rolesdump);
620: unless ($tmp =~ /^(con_lost|error)/i) {
621: my $now=time;
622: my %lt=&Apache::lonlocal::texthash(
623: 'rer' => "Revoke Existing Roles",
624: 'rev' => "Revoke",
625: 'del' => "Delete",
626: 'ren' => "Re-Enable",
627: 'rol' => "Role",
628: 'ext' => "Extent",
629: 'sta' => "Start",
630: 'end' => "End"
631: );
632: my (%roletext,%sortrole,%roleclass,%rolepriv);
633: foreach my $area (sort { my $a1=join('_',(split('_',$a))[1,0]);
634: my $b1=join('_',(split('_',$b))[1,0]);
635: return $a1 cmp $b1;
636: } keys(%rolesdump)) {
637: next if ($area =~ /^rolesdef/);
638: my $envkey=$area;
639: my $role = $rolesdump{$area};
640: my $thisrole=$area;
641: $area =~ s/\_\w\w$//;
642: my ($role_code,$role_end_time,$role_start_time) =
643: split(/_/,$role);
644: # Is this a custom role? Get role owner and title.
645: my ($croleudom,$croleuname,$croletitle)=
646: ($role_code=~m{^cr/($match_domain)/($match_username)/(\w+)$});
647: my $allowed=0;
648: my $delallowed=0;
649: my $sortkey=$role_code;
650: my $class='Unknown';
651: if ($area =~ m{^/($match_domain)/($match_courseid)} ) {
652: $class='Course';
653: my ($coursedom,$coursedir) = ($1,$2);
654: $sortkey.="\0$coursedom";
655: # $1.'_'.$2 is the course id (eg. 103_12345abcef103l3).
656: my %coursedata=
657: &Apache::lonnet::coursedescription($1.'_'.$2);
658: my $carea;
659: if (defined($coursedata{'description'})) {
660: $carea=$coursedata{'description'}.
661: '<br />'.&mt('Domain').': '.$coursedom.(' 'x8).
662: &Apache::loncommon::syllabuswrapper('Syllabus',$coursedir,$coursedom);
663: $sortkey.="\0".$coursedata{'description'};
664: $class=$coursedata{'type'};
665: } else {
666: $carea=&mt('Unavailable course').': '.$area;
667: $sortkey.="\0".&mt('Unavailable course').': '.$area;
668: }
669: $sortkey.="\0$coursedir";
670: $inccourses{$1.'_'.$2}=1;
671: if ((&Apache::lonnet::allowed('c'.$role_code,$1.'/'.$2)) ||
672: (&Apache::lonnet::allowed('c'.$role_code,$ccdomain))) {
673: $allowed=1;
674: }
675: if ((&Apache::lonnet::allowed('dro',$1)) ||
676: (&Apache::lonnet::allowed('dro',$ccdomain))) {
677: $delallowed=1;
678: }
679: # - custom role. Needs more info, too
680: if ($croletitle) {
681: if (&Apache::lonnet::allowed('ccr',$1.'/'.$2)) {
682: $allowed=1;
683: $thisrole.='.'.$role_code;
684: }
685: }
686: # Compute the background color based on $area
687: if ($area=~m{^/($match_domain)/($match_courseid)/(\w+)}) {
688: $carea.='<br />Section: '.$3;
689: $sortkey.="\0$3";
690: }
691: $area=$carea;
692: } else {
693: $sortkey.="\0".$area;
694: # Determine if current user is able to revoke privileges
695: if ($area=~m{^/($match_domain)/}) {
696: if ((&Apache::lonnet::allowed('c'.$role_code,$1)) ||
697: (&Apache::lonnet::allowed('c'.$role_code,$ccdomain))) {
698: $allowed=1;
699: }
700: if (((&Apache::lonnet::allowed('dro',$1)) ||
701: (&Apache::lonnet::allowed('dro',$ccdomain))) &&
702: ($role_code ne 'dc')) {
703: $delallowed=1;
704: }
705: } else {
706: if (&Apache::lonnet::allowed('c'.$role_code,'/')) {
707: $allowed=1;
708: }
709: }
710: if ($role_code eq 'ca' || $role_code eq 'au') {
711: $class='Construction Space';
712: } elsif ($role_code eq 'su') {
713: $class='System';
714: } else {
715: $class='Domain';
716: }
717: }
718: if (($role_code eq 'ca') || ($role_code eq 'aa')) {
719: $area=~m{/($match_domain)/($match_username)};
720: if (&authorpriv($2,$1)) {
721: $allowed=1;
722: } else {
723: $allowed=0;
724: }
725: }
726: my $row = '';
727: $row.= '<td>';
728: my $active=1;
729: $active=0 if (($role_end_time) && ($now>$role_end_time));
730: if (($active) && ($allowed)) {
731: $row.= '<input type="checkbox" name="rev:'.$thisrole.'" />';
732: } else {
733: if ($active) {
734: $row.=' ';
735: } else {
736: $row.=&mt('expired or revoked');
737: }
738: }
739: $row.='</td><td>';
740: if ($allowed && !$active) {
741: $row.= '<input type="checkbox" name="ren:'.$thisrole.'" />';
742: } else {
743: $row.=' ';
744: }
745: $row.='</td><td>';
746: if ($delallowed) {
747: $row.= '<input type="checkbox" name="del:'.$thisrole.'" />';
748: } else {
749: $row.=' ';
750: }
751: my $plaintext='';
752: if (!$croletitle) {
753: $plaintext=&Apache::lonnet::plaintext($role_code,$class)
754: } else {
755: $plaintext=
756: "Customrole '$croletitle' defined by $croleuname\@$croleudom";
757: }
758: $row.= '</td><td>'.$plaintext.
759: '</td><td>'.$area.
760: '</td><td>'.($role_start_time?localtime($role_start_time)
761: : ' ' ).
762: '</td><td>'.($role_end_time ?localtime($role_end_time)
763: : ' ' )
764: ."</td>";
765: $sortrole{$sortkey}=$envkey;
766: $roletext{$envkey}=$row;
767: $roleclass{$envkey}=$class;
768: $rolepriv{$envkey}=$allowed;
769: #$r->print($row);
770: } # end of foreach (table building loop)
771: my $rolesdisplay = 0;
772: my %output = ();
773: foreach my $type ('Construction Space','Course','Group','Domain','System','Unknown') {
774: $output{$type} = '';
775: foreach my $which (sort {uc($a) cmp uc($b)} (keys(%sortrole))) {
776: if ( ($roleclass{$sortrole{$which}} =~ /^\Q$type\E/ ) && ($rolepriv{$sortrole{$which}}) ) {
777: $output{$type}.=
778: &Apache::loncommon::start_data_table_row().
779: $roletext{$sortrole{$which}}.
780: &Apache::loncommon::end_data_table_row();
781: }
782: }
783: unless($output{$type} eq '') {
784: $output{$type} = '<tr class="LC_info_row">'.
785: "<td align='center' colspan='7'>".&mt($type)."</td></tr>".
786: $output{$type};
787: $rolesdisplay = 1;
788: }
789: }
790: if ($rolesdisplay == 1) {
791: $r->print('
792: <hr />
793: <h3>'.$lt{'rer'}.'</h3>'.
794: &Apache::loncommon::start_data_table("LC_createuser").
795: &Apache::loncommon::start_data_table_header_row().
796: '<th>'.$lt{'rev'}.'</th><th>'.$lt{'ren'}.'</th><th>'.$lt{'del'}.
797: '</th><th>'.$lt{'rol'}.'</th><th>'.$lt{'ext'}.
798: '</th><th>'.$lt{'sta'}.'</th><th>'.$lt{'end'}.'</th>'.
799: &Apache::loncommon::end_data_table_header_row());
800: foreach my $type ('Construction Space','Course','Group','Domain','System','Unknown') {
801: if ($output{$type}) {
802: $r->print($output{$type}."\n");
803: }
804: }
805: $r->print(&Apache::loncommon::end_data_table());
806: }
807: } # End of unless
808: my $currentauth=&Apache::lonnet::queryauthenticate($ccuname,$ccdomain);
809: if ($currentauth=~/^krb(4|5):/) {
810: $currentauth=~/^krb(4|5):(.*)/;
811: my $krbdefdom=$2;
812: my %param = ( formname => 'document.cu',
813: kerb_def_dom => $krbdefdom
814: );
815: $loginscript = &Apache::loncommon::authform_header(%param);
816: }
817: # Check for a bad authentication type
818: unless ($currentauth=~/^krb(4|5):/ or
819: $currentauth=~/^unix:/ or
820: $currentauth=~/^internal:/ or
821: $currentauth=~/^localauth:/
822: ) { # bad authentication scheme
823: if (&Apache::lonnet::allowed('mau',$ccdomain)) {
824: &initialize_authen_forms();
825: my %lt=&Apache::lonlocal::texthash(
826: 'err' => "ERROR",
827: 'uuas' => "This user has an unrecognized authentication scheme",
828: 'sldb' => "Please specify login data below",
829: 'ld' => "Login Data"
830: );
831: $r->print(<<ENDBADAUTH);
832: <hr />
833: <script type="text/javascript" language="Javascript">
834: $loginscript
835: </script>
836: <font color='#ff0000'>$lt{'err'}:</font>
837: $lt{'uuas'} ($currentauth). $lt{'sldb'}.
838: <h3>$lt{'ld'}</h3>
839: <p>$generalrule</p>
840: <p>$authformkrb</p>
841: <p>$authformint</p>
842: <p>$authformfsys</p>
843: <p>$authformloc</p>
844: ENDBADAUTH
845: } else {
846: # This user is not allowed to modify the user's
847: # authentication scheme, so just notify them of the problem
848: my %lt=&Apache::lonlocal::texthash(
849: 'err' => "ERROR",
850: 'uuas' => "This user has an unrecognized authentication scheme",
851: 'adcs' => "Please alert a domain coordinator of this situation"
852: );
853: $r->print(<<ENDBADAUTH);
854: <hr />
855: <font color="#ff0000"> $lt{'err'}: </font>
856: $lt{'uuas'} ($currentauth). $lt{'adcs'}.
857: <hr />
858: ENDBADAUTH
859: }
860: } else { # Authentication type is valid
861: my $authformcurrent='';
862: my $authform_other='';
863: &initialize_authen_forms();
864: if ($currentauth=~/^krb(4|5):/) {
865: $authformcurrent=$authformkrb;
866: $authform_other="<p>$authformint</p>\n".
867: "<p>$authformfsys</p><p>$authformloc</p>";
868: }
869: elsif ($currentauth=~/^internal:/) {
870: $authformcurrent=$authformint;
871: $authform_other="<p>$authformkrb</p>".
872: "<p>$authformfsys</p><p>$authformloc</p>";
873: }
874: elsif ($currentauth=~/^unix:/) {
875: $authformcurrent=$authformfsys;
876: $authform_other="<p>$authformkrb</p>".
877: "<p>$authformint</p><p>$authformloc;</p>";
878: }
879: elsif ($currentauth=~/^localauth:/) {
880: $authformcurrent=$authformloc;
881: $authform_other="<p>$authformkrb</p>".
882: "<p>$authformint</p><p>$authformfsys</p>";
883: }
884: $authformcurrent.=' <i>(will override current values)</i><br />';
885: if (&Apache::lonnet::allowed('mau',$ccdomain)) {
886: # Current user has login modification privileges
887: my %lt=&Apache::lonlocal::texthash(
888: 'ccld' => "Change Current Login Data",
889: 'enld' => "Enter New Login Data"
890: );
891: $r->print(<<ENDOTHERAUTHS);
892: <hr />
893: <script type="text/javascript" language="Javascript">
894: $loginscript
895: </script>
896: <h3>$lt{'ccld'}</h3>
897: <p>$generalrule</p>
898: <p>$authformnop</p>
899: <p>$authformcurrent</p>
900: <h3>$lt{'enld'}</h3>
901: $authform_other
902: ENDOTHERAUTHS
903: } else {
904: if (&Apache::lonnet::allowed('mau',$env{'request.role.domain'})) {
905: my %lt=&Apache::lonlocal::texthash(
906: 'ccld' => "Change Current Login Data",
907: 'yodo' => "You do not have privileges to modify the authentication configuration for this user.",
908: 'ifch' => "If a change is required, contact a domain coordinator for the domain",
909: );
910: $r->print(<<ENDNOPRIV);
911: <hr />
912: <h3>$lt{'ccld'}</h3>
913: $lt{'yodo'} $lt{'ifch'}: $ccdomain
914: ENDNOPRIV
915: }
916: }
917: if (&Apache::lonnet::allowed('mpq',$env{'request.role.domain'})) {
918: # Current user has quota modification privileges
919: $r->print(&portfolio_quota($ccuname,$ccdomain));
920: }
921: } ## End of "check for bad authentication type" logic
922: } ## End of new user/old user logic
923: $r->print('<hr /><h3>'.&mt('Add Roles').'</h3>');
924: #
925: # Co-Author
926: #
927: if (&authorpriv($env{'user.name'},$env{'request.role.domain'}) &&
928: ($env{'user.name'} ne $ccuname || $env{'user.domain'} ne $ccdomain)) {
929: # No sense in assigning co-author role to yourself
930: my $cuname=$env{'user.name'};
931: my $cudom=$env{'request.role.domain'};
932: my %lt=&Apache::lonlocal::texthash(
933: 'cs' => "Construction Space",
934: 'act' => "Activate",
935: 'rol' => "Role",
936: 'ext' => "Extent",
937: 'sta' => "Start",
938: 'end' => "End",
939: 'cau' => "Co-Author",
940: 'caa' => "Assistant Co-Author",
941: 'ssd' => "Set Start Date",
942: 'sed' => "Set End Date"
943: );
944: $r->print('<h4>'.$lt{'cs'}.'</h4>'."\n".
945: &Apache::loncommon::start_data_table()."\n".
946: &Apache::loncommon::start_data_table_header_row()."\n".
947: '<th>'.$lt{'act'}.'</th><th>'.$lt{'rol'}.'</th>'.
948: '<th>'.$lt{'ext'}.'</th><th>'.$lt{'sta'}.'</th>'.
949: '<th>'.$lt{'end'}.'</th>'."\n".
950: &Apache::loncommon::end_data_table_header_row()."\n".
951: &Apache::loncommon::start_data_table_row()."\n".
952: '<td>
953: <input type=checkbox name="act_'.$cudom.'_'.$cuname.'_ca" />
954: </td>
955: <td>'.$lt{'cau'}.'</td>
956: <td>'.$cudom.'_'.$cuname.'</td>
957: <td><input type="hidden" name="start_'.$cudom.'_'.$cuname.'_ca" value="" />
958: <a href=
959: "javascript:pjump('."'date_start','Start Date Co-Author',document.cu.start_$cudom\_$cuname\_ca.value,'start_$cudom\_$cuname\_ca','cu.pres','dateset'".')">'.$lt{'ssd'}.'</a></td>
960: <td><input type=hidden name="end_'.$cudom.'_'.$cuname.'_ca" value="" />
961: <a href=
962: "javascript:pjump('."'date_end','End Date Co-Author',document.cu.end_$cudom\_$cuname\_ca.value,'end_$cudom\_$cuname\_ca','cu.pres','dateset'".')">'.$lt{'sed'}.'</a></td>'."\n".
963: &Apache::loncommon::end_data_table_row()."\n".
964: &Apache::loncommon::start_data_table_row()."\n".
965: '<td><input type=checkbox name="act_'.$cudom.'_'.$cuname.'_aa" /></td>
966: <td>'.$lt{'caa'}.'</td>
967: <td>'.$cudom.'_'.$cuname.'</td>
968: <td><input type=hidden name="start_'.$cudom.'_'.$cuname.'_aa" value="" />
969: <a href=
970: "javascript:pjump('."'date_start','Start Date Assistant Co-Author',document.cu.start_$cudom\_$cuname\_aa.value,'start_$cudom\_$cuname\_aa','cu.pres','dateset'".')">'.$lt{'ssd'}.'</a></td>
971: <td><input type=hidden name="end_'.$cudom.'_'.$cuname.'_aa" value="" />
972: <a href=
973: "javascript:pjump('."'date_end','End Date Assistant Co-Author',document.cu.end_$cudom\_$cuname\_aa.value,'end_$cudom\_$cuname\_aa','cu.pres','dateset'".')">'.$lt{'sed'}.'</a></td>'."\n".
974: &Apache::loncommon::end_data_table_row()."\n".
975: &Apache::loncommon::end_data_table());
976: }
977: #
978: # Domain level
979: #
980: my $num_domain_level = 0;
981: my $domaintext =
982: '<h4>'.&mt('Domain Level').'</h4>'.
983: &Apache::loncommon::start_data_table().
984: &Apache::loncommon::start_data_table_header_row().
985: '<th>'.&mt('Activate').'</th><th>'.&mt('Role').'</th><th>'.
986: &mt('Extent').'</th>'.
987: '<th>'.&mt('Start').'</th><th>'.&mt('End').'</th>'.
988: &Apache::loncommon::end_data_table_header_row();
989: foreach my $thisdomain (sort(&Apache::lonnet::all_domains())) {
990: foreach my $role ('dc','li','dg','au','sc') {
991: if (&Apache::lonnet::allowed('c'.$role,$thisdomain)) {
992: my $plrole=&Apache::lonnet::plaintext($role);
993: my %lt=&Apache::lonlocal::texthash(
994: 'ssd' => "Set Start Date",
995: 'sed' => "Set End Date"
996: );
997: $num_domain_level ++;
998: $domaintext .=
999: &Apache::loncommon::start_data_table_row().
1000: '<td><input type=checkbox name="act_'.$thisdomain.'_'.$role.'" /></td>
1001: <td>'.$plrole.'</td>
1002: <td>'.$thisdomain.'</td>
1003: <td><input type=hidden name="start_'.$thisdomain.'_'.$role.'" value="" />
1004: <a href=
1005: "javascript:pjump('."'date_start','Start Date $plrole',document.cu.start_$thisdomain\_$role.value,'start_$thisdomain\_$role','cu.pres','dateset'".')">'.$lt{'ssd'}.'</a></td>
1006: <td><input type=hidden name="end_'.$thisdomain.'_'.$role.'" value="" />
1007: <a href=
1008: "javascript:pjump('."'date_end','End Date $plrole',document.cu.end_$thisdomain\_$role.value,'end_$thisdomain\_$role','cu.pres','dateset'".')">'.$lt{'sed'}.'</a></td>'.
1009: &Apache::loncommon::end_data_table_row();
1010: }
1011: }
1012: }
1013: $domaintext.= &Apache::loncommon::end_data_table();
1014: if ($num_domain_level > 0) {
1015: $r->print($domaintext);
1016: }
1017: #
1018: # Course and group levels
1019: #
1020:
1021: if ($env{'request.role'} =~ m{^dc\./($match_domain)/$}) {
1022: $r->print(&course_level_dc($1,'Course'));
1023: $r->print('<hr /><input type="button" value="'.&mt('Modify User').'" onClick="setCourse()" />'."\n");
1024: } else {
1025: $r->print(&course_level_table(%inccourses));
1026: $r->print('<hr /><input type="button" value="'.&mt('Modify User').'" onClick="setSections()" />'."\n");
1027: }
1028: $r->print("</form>".&Apache::loncommon::end_page());
1029: }
1030:
1031: # ================================================================= Phase Three
1032: sub update_user_data {
1033: my $r=shift;
1034: my $uhome=&Apache::lonnet::homeserver($env{'form.ccuname'},
1035: $env{'form.ccdomain'});
1036: # Error messages
1037: my $error = '<font color="#ff0000">'.&mt('Error').':</font>';
1038: my $end = &Apache::loncommon::end_page();
1039:
1040: my $title;
1041: if (exists($env{'form.makeuser'})) {
1042: $title='Set Privileges for New User';
1043: } else {
1044: $title='Modify User Privileges';
1045: }
1046: $r->print(&Apache::loncommon::start_page($title));
1047: my %disallowed;
1048: # Check Inputs
1049: if (! $env{'form.ccuname'} ) {
1050: $r->print($error.&mt('No login name specified').'.'.$end);
1051: return;
1052: }
1053: if ( $env{'form.ccuname'} ne
1054: &LONCAPA::clean_username($env{'form.ccuname'}) ) {
1055: $r->print($error.&mt('Invalid login name').'. '.
1056: &mt('Only letters, numbers, and underscores are valid').'.'.
1057: $end);
1058: return;
1059: }
1060: if (! $env{'form.ccdomain'} ) {
1061: $r->print($error.&mt('No domain specified').'.'.$end);
1062: return;
1063: }
1064: if ( $env{'form.ccdomain'} ne
1065: &LONCAPA::clean_domain($env{'form.ccdomain'}) ) {
1066: $r->print($error.&mt ('Invalid domain name').'. '.
1067: &mt('Only letters, numbers, periods, dashes, and underscores are valid').'.'.
1068: $end);
1069: return;
1070: }
1071: if (! exists($env{'form.makeuser'})) {
1072: # Modifying an existing user, so check the validity of the name
1073: if ($uhome eq 'no_host') {
1074: $r->print($error.&mt('Unable to determine home server for ').
1075: $env{'form.ccuname'}.&mt(' in domain ').
1076: $env{'form.ccdomain'}.'.');
1077: return;
1078: }
1079: }
1080: # Determine authentication method and password for the user being modified
1081: my $amode='';
1082: my $genpwd='';
1083: if ($env{'form.login'} eq 'krb') {
1084: $amode='krb';
1085: $amode.=$env{'form.krbver'};
1086: $genpwd=$env{'form.krbarg'};
1087: } elsif ($env{'form.login'} eq 'int') {
1088: $amode='internal';
1089: $genpwd=$env{'form.intarg'};
1090: } elsif ($env{'form.login'} eq 'fsys') {
1091: $amode='unix';
1092: $genpwd=$env{'form.fsysarg'};
1093: } elsif ($env{'form.login'} eq 'loc') {
1094: $amode='localauth';
1095: $genpwd=$env{'form.locarg'};
1096: $genpwd=" " if (!$genpwd);
1097: } elsif (($env{'form.login'} eq 'nochange') ||
1098: ($env{'form.login'} eq '' )) {
1099: # There is no need to tell the user we did not change what they
1100: # did not ask us to change.
1101: # If they are creating a new user but have not specified login
1102: # information this will be caught below.
1103: } else {
1104: $r->print($error.&mt('Invalid login mode or password').$end);
1105: return;
1106: }
1107: if ($env{'form.makeuser'}) {
1108: # Create a new user
1109: my %lt=&Apache::lonlocal::texthash(
1110: 'cru' => "Creating user",
1111: 'id' => "in domain"
1112: );
1113: $r->print(<<ENDNEWUSERHEAD);
1114: <h3>$lt{'cru'} "$env{'form.ccuname'}" $lt{'id'} "$env{'form.ccdomain'}"</h3>
1115: ENDNEWUSERHEAD
1116: # Check for the authentication mode and password
1117: if (! $amode || ! $genpwd) {
1118: $r->print($error.&mt('Invalid login mode or password').$end);
1119: return;
1120: }
1121: # Determine desired host
1122: my $desiredhost = $env{'form.hserver'};
1123: if (lc($desiredhost) eq 'default') {
1124: $desiredhost = undef;
1125: } else {
1126: my %home_servers =
1127: &Apache::lonnet::get_servers($env{'form.ccdomain'},'library');
1128: if (! exists($home_servers{$desiredhost})) {
1129: $r->print($error.&mt('Invalid home server specified'));
1130: return;
1131: }
1132: }
1133: # Call modifyuser
1134: my $result = &Apache::lonnet::modifyuser
1135: ($env{'form.ccdomain'},$env{'form.ccuname'},$env{'form.cstid'},
1136: $amode,$genpwd,$env{'form.cfirst'},
1137: $env{'form.cmiddle'},$env{'form.clast'},$env{'form.cgen'},
1138: undef,$desiredhost
1139: );
1140: $r->print(&mt('Generating user').': '.$result);
1141: my $home = &Apache::lonnet::homeserver($env{'form.ccuname'},
1142: $env{'form.ccdomain'});
1143: $r->print('<br />'.&mt('Home server').': '.$home.' '.
1144: &Apache::lonnet::hostname($home));
1145: } elsif (($env{'form.login'} ne 'nochange') &&
1146: ($env{'form.login'} ne '' )) {
1147: # Modify user privileges
1148: my %lt=&Apache::lonlocal::texthash(
1149: 'usr' => "User",
1150: 'id' => "in domain"
1151: );
1152: $r->print(<<ENDMODIFYUSERHEAD);
1153: <h2>$lt{'usr'} "$env{'form.ccuname'}" $lt{'id'} "$env{'form.ccdomain'}"</h2>
1154: ENDMODIFYUSERHEAD
1155: if (! $amode || ! $genpwd) {
1156: $r->print($error.'Invalid login mode or password'.$end);
1157: return;
1158: }
1159: # Only allow authentification modification if the person has authority
1160: if (&Apache::lonnet::allowed('mau',$env{'form.ccdomain'})) {
1161: $r->print('Modifying authentication: '.
1162: &Apache::lonnet::modifyuserauth(
1163: $env{'form.ccdomain'},$env{'form.ccuname'},
1164: $amode,$genpwd));
1165: $r->print('<br />'.&mt('Home server').': '.&Apache::lonnet::homeserver
1166: ($env{'form.ccuname'},$env{'form.ccdomain'}));
1167: } else {
1168: # Okay, this is a non-fatal error.
1169: $r->print($error.&mt('You do not have the authority to modify this users authentification information').'.');
1170: }
1171: }
1172: ##
1173: if (! $env{'form.makeuser'} ) {
1174: # Check for need to change
1175: my %userenv = &Apache::lonnet::get
1176: ('environment',['firstname','middlename','lastname','generation',
1177: 'portfolioquota','inststatus'],$env{'form.ccdomain'},
1178: $env{'form.ccuname'});
1179: my ($tmp) = keys(%userenv);
1180: if ($tmp =~ /^(con_lost|error)/i) {
1181: %userenv = ();
1182: }
1183: # Check to see if we need to change user information
1184: foreach my $item ('firstname','middlename','lastname','generation') {
1185: # Strip leading and trailing whitespace
1186: $env{'form.c'.$item} =~ s/(\s+$|^\s+)//g;
1187: }
1188: my ($quotachanged,$namechanged,$oldportfolioquota,$newportfolioquota,
1189: $inststatus,$isdefault,$defquotatext);
1190: my ($defquota,$settingstatus) =
1191: &Apache::loncommon::default_quota($env{'form.ccdomain'},$inststatus);
1192: my %changeHash;
1193: if ($userenv{'portfolioquota'} ne '') {
1194: $oldportfolioquota = $userenv{'portfolioquota'};
1195: if ($env{'form.customquota'} == 1) {
1196: if ($env{'form.portfolioquota'} eq '') {
1197: $newportfolioquota = 0;
1198: } else {
1199: $newportfolioquota = $env{'form.portfolioquota'};
1200: $newportfolioquota =~ s/[^\d\.]//g;
1201: }
1202: if ($newportfolioquota != $userenv{'portfolioquota'}) {
1203: $quotachanged = "a_admin($newportfolioquota,\%changeHash);
1204: }
1205: } else {
1206: $quotachanged = "a_admin('',\%changeHash);
1207: $newportfolioquota = $defquota;
1208: $isdefault = 1;
1209: }
1210: } else {
1211: $oldportfolioquota = $defquota;
1212: if ($env{'form.customquota'} == 1) {
1213: if ($env{'form.portfolioquota'} eq '') {
1214: $newportfolioquota = 0;
1215: } else {
1216: $newportfolioquota = $env{'form.portfolioquota'};
1217: $newportfolioquota =~ s/[^\d\.]//g;
1218: }
1219: $quotachanged = "a_admin($newportfolioquota,\%changeHash);
1220: } else {
1221: $newportfolioquota = $defquota;
1222: $isdefault = 1;
1223: }
1224: }
1225: if ($isdefault) {
1226: if ($settingstatus eq '') {
1227: $defquotatext = &mt('(default)');
1228: } else {
1229: my ($usertypes,$order) =
1230: &Apache::lonnet::retrieve_inst_usertypes($env{'form.ccdomain'});
1231: if ($usertypes->{$settingstatus} eq '') {
1232: $defquotatext = &mt('(default)');
1233: } else {
1234: $defquotatext = &mt('(default for [_1])',$usertypes->{$settingstatus});
1235: }
1236: }
1237: }
1238: if (&Apache::lonnet::allowed('mau',$env{'form.ccdomain'}) &&
1239: ($env{'form.cfirstname'} ne $userenv{'firstname'} ||
1240: $env{'form.cmiddlename'} ne $userenv{'middlename'} ||
1241: $env{'form.clastname'} ne $userenv{'lastname'} ||
1242: $env{'form.cgeneration'} ne $userenv{'generation'} )) {
1243: $namechanged = 1;
1244: }
1245: if ($namechanged) {
1246: # Make the change
1247: $changeHash{'firstname'} = $env{'form.cfirstname'};
1248: $changeHash{'middlename'} = $env{'form.cmiddlename'};
1249: $changeHash{'lastname'} = $env{'form.clastname'};
1250: $changeHash{'generation'} = $env{'form.cgeneration'};
1251: my $putresult = &Apache::lonnet::put
1252: ('environment',\%changeHash,
1253: $env{'form.ccdomain'},$env{'form.ccuname'});
1254: if ($putresult eq 'ok') {
1255: # Tell the user we changed the name
1256: my %lt=&Apache::lonlocal::texthash(
1257: 'uic' => "User Information Changed",
1258: 'frst' => "first",
1259: 'mddl' => "middle",
1260: 'lst' => "last",
1261: 'gen' => "generation",
1262: 'disk' => "disk space allocated to portfolio files",
1263: 'prvs' => "Previous",
1264: 'chto' => "Changed To"
1265: );
1266: $r->print(<<"END");
1267: <table border="2">
1268: <caption>$lt{'uic'}</caption>
1269: <tr><th> </th>
1270: <th>$lt{'frst'}</th>
1271: <th>$lt{'mddl'}</th>
1272: <th>$lt{'lst'}</th>
1273: <th>$lt{'gen'}</th>
1274: <th>$lt{'disk'}<th></tr>
1275: <tr><td>$lt{'prvs'}</td>
1276: <td>$userenv{'firstname'} </td>
1277: <td>$userenv{'middlename'} </td>
1278: <td>$userenv{'lastname'} </td>
1279: <td>$userenv{'generation'} </td>
1280: <td>$oldportfolioquota Mb</td>
1281: </tr>
1282: <tr><td>$lt{'chto'}</td>
1283: <td>$env{'form.cfirstname'} </td>
1284: <td>$env{'form.cmiddlename'} </td>
1285: <td>$env{'form.clastname'} </td>
1286: <td>$env{'form.cgeneration'} </td>
1287: <td>$newportfolioquota Mb $defquotatext </td></tr>
1288: </table>
1289: END
1290: if (($env{'form.ccdomain'} eq $env{'user.domain'}) &&
1291: ($env{'form.ccuname'} eq $env{'user.name'})) {
1292: my %newenvhash;
1293: foreach my $key (keys(%changeHash)) {
1294: $newenvhash{'environment.'.$key} = $changeHash{$key};
1295: }
1296: &Apache::lonnet::appenv(%newenvhash);
1297: }
1298: } else { # error occurred
1299: $r->print("<h2>".&mt('Unable to successfully change environment for')." ".
1300: $env{'form.ccuname'}." ".&mt('in domain')." ".
1301: $env{'form.ccdomain'}."</h2>");
1302: }
1303: } else { # End of if ($env ... ) logic
1304: my $putresult;
1305: if ($quotachanged) {
1306: $putresult = &Apache::lonnet::put
1307: ('environment',\%changeHash,
1308: $env{'form.ccdomain'},$env{'form.ccuname'});
1309: }
1310: # They did not want to change the users name but we can
1311: # still tell them what the name is
1312: my %lt=&Apache::lonlocal::texthash(
1313: 'usr' => "User",
1314: 'id' => "in domain",
1315: 'gen' => "Generation",
1316: 'disk' => "Disk space allocated to user's portfolio files",
1317: );
1318: $r->print(<<"END");
1319: <h2>$lt{'usr'} "$env{'form.ccuname'}" $lt{'id'} "$env{'form.ccdomain'}"</h2>
1320: <h4>$userenv{'firstname'} $userenv{'middlename'} $userenv{'lastname'} </h4>
1321: <h4>$lt{'gen'}: $userenv{'generation'}</h4>
1322: END
1323: if ($putresult eq 'ok') {
1324: if ($oldportfolioquota != $newportfolioquota) {
1325: $r->print('<h4>'.$lt{'disk'}.': '.$newportfolioquota.' Mb '.
1326: $defquotatext.'</h4>');
1327: &Apache::lonnet::appenv('environment.portfolioquota' => $changeHash{'portfolioquota'});
1328: }
1329: }
1330: }
1331: }
1332: ##
1333: my $now=time;
1334: $r->print('<h3>'.&mt('Modifying Roles').'</h3>');
1335: foreach my $key (keys (%env)) {
1336: next if (! $env{$key});
1337: # Revoke roles
1338: if ($key=~/^form\.rev/) {
1339: if ($key=~/^form\.rev\:([^\_]+)\_([^\_\.]+)$/) {
1340: # Revoke standard role
1341: $r->print(&mt('Revoking').' '.$2.' in '.$1.': <b>'.
1342: &Apache::lonnet::revokerole($env{'form.ccdomain'},
1343: $env{'form.ccuname'},$1,$2).'</b><br />');
1344: if ($2 eq 'st') {
1345: $1=~m{^/($match_domain)/($match_courseid)};
1346: my $cid=$1.'_'.$2;
1347: my $user = $env{'form.ccuname'}.':'.$env{'form.ccdomain'};
1348: my $result =
1349: &Apache::lonnet::cput('classlist',
1350: { $user => $now },
1351: $env{'course.'.$cid.'.domain'},
1352: $env{'course.'.$cid.'.num'});
1353: $r->print(&mt('Drop from classlist: [_1]',
1354: '<b>'.$result.'</b>').'<br />');
1355: }
1356: }
1357: if ($key=~m{^form\.rev\:([^_]+)_cr\.cr/($match_domain)/($match_username)/(\w+)$}) {
1358: # Revoke custom role
1359: $r->print(&mt('Revoking custom role:').
1360: ' '.$4.' by '.$3.':'.$2.' in '.$1.': <b>'.
1361: &Apache::lonnet::revokecustomrole($env{'form.ccdomain'},
1362: $env{'form.ccuname'},$1,$2,$3,$4).
1363: '</b><br />');
1364: }
1365: } elsif ($key=~/^form\.del/) {
1366: if ($key=~/^form\.del\:([^\_]+)\_([^\_\.]+)$/) {
1367: # Delete standard role
1368: $r->print(&mt('Deleting').' '.$2.' in '.$1.': '.
1369: &Apache::lonnet::assignrole($env{'form.ccdomain'},
1370: $env{'form.ccuname'},$1,$2,$now,0,1).'<br />');
1371: if ($2 eq 'st') {
1372: $1=~m{^/($match_domain)/($match_courseid)};
1373: my $cid=$1.'_'.$2;
1374: my $user = $env{'form.ccuname'}.':'.$env{'form.ccdomain'};
1375: my $result =
1376: &Apache::lonnet::cput('classlist',
1377: { $user => $now },
1378: $env{'course.'.$cid.'.domain'},
1379: $env{'course.'.$cid.'.num'});
1380: $r->print(&mt('Drop from classlist: [_1]',
1381: '<b>'.$result.'</b>').'<br />');
1382: }
1383: }
1384: if ($key=~m{^form\.del\:([^_]+)_cr\.cr/($match_domain)/($match_username)/(\w+)$}) {
1385: my ($url,$rdom,$rnam,$rolename) = ($1,$2,$3,$4);
1386: # Delete custom role
1387: $r->print(&mt('Deleting custom role [_1] by [_2]@[_3] in [_4]',
1388: $rolename,$rnam,$rdom,$url).': <b>'.
1389: &Apache::lonnet::assigncustomrole($env{'form.ccdomain'},
1390: $env{'form.ccuname'},$url,$rdom,$rnam,$rolename,$now,
1391: 0,1).'</b><br />');
1392: }
1393: } elsif ($key=~/^form\.ren/) {
1394: my $udom = $env{'form.ccdomain'};
1395: my $uname = $env{'form.ccuname'};
1396: # Re-enable standard role
1397: if ($key=~/^form\.ren\:([^\_]+)\_([^\_\.]+)$/) {
1398: my $url = $1;
1399: my $role = $2;
1400: my $logmsg;
1401: my $output;
1402: if ($role eq 'st') {
1403: if ($url =~ m-^/($match_domain)/($match_courseid)/?(\w*)$-) {
1404: my $result = &Apache::loncommon::commit_studentrole(\$logmsg,$udom,$uname,$url,$role,$now,0,$1,$2,$3);
1405: if (($result =~ /^error/) || ($result eq 'not_in_class') || ($result eq 'unknown_course')) {
1406: $output = "Error: $result\n";
1407: } else {
1408: $output = &mt('Assigning').' '.$role.' in '.$url.
1409: &mt('starting').' '.localtime($now).
1410: ': <br />'.$logmsg.'<br />'.
1411: &mt('Add to classlist').': <b>ok</b><br />';
1412: }
1413: }
1414: } else {
1415: my $result=&Apache::lonnet::assignrole($env{'form.ccdomain'},
1416: $env{'form.ccuname'},$url,$role,0,$now);
1417: $output = &mt('Re-enabling [_1] in [_2]: <b>[_3]</b>',
1418: $role,$url,$result).'<br />';
1419: }
1420: $r->print($output);
1421: }
1422: # Re-enable custom role
1423: if ($key=~m{^form\.ren\:([^_]+)_cr\.cr/($match_domain)/($match_username)/(\w+)$}) {
1424: my ($url,$rdom,$rnam,$rolename) = ($1,$2,$3,$4);
1425: my $result = &Apache::lonnet::assigncustomrole(
1426: $env{'form.ccdomain'}, $env{'form.ccuname'},
1427: $url,$rdom,$rnam,$rolename,0,$now);
1428: $r->print(&mt('Re-enabling custom role [_1] by [_2]@[_3] in [_4] : <b>[_5]</b>',
1429: $rolename,$rnam,$rdom,$url,$result).'<br />');
1430: }
1431: } elsif ($key=~/^form\.act/) {
1432: my $udom = $env{'form.ccdomain'};
1433: my $uname = $env{'form.ccuname'};
1434: if ($key=~/^form\.act\_($match_domain)\_($match_courseid)\_cr_cr_($match_domain)_($match_username)_([^\_]+)$/) {
1435: # Activate a custom role
1436: my ($one,$two,$three,$four,$five)=($1,$2,$3,$4,$5);
1437: my $url='/'.$one.'/'.$two;
1438: my $full=$one.'_'.$two.'_cr_cr_'.$three.'_'.$four.'_'.$five;
1439:
1440: my $start = ( $env{'form.start_'.$full} ?
1441: $env{'form.start_'.$full} :
1442: $now );
1443: my $end = ( $env{'form.end_'.$full} ?
1444: $env{'form.end_'.$full} :
1445: 0 );
1446:
1447: # split multiple sections
1448: my %sections = ();
1449: my $num_sections = &build_roles($env{'form.sec_'.$full},\%sections,$5);
1450: if ($num_sections == 0) {
1451: $r->print(&Apache::loncommon::commit_customrole($udom,$uname,$url,$three,$four,$five,$start,$end));
1452: } else {
1453: my %curr_groups =
1454: &Apache::longroup::coursegroups($one,$two);
1455: foreach my $sec (sort {$a cmp $b} keys %sections) {
1456: if (($sec eq 'none') || ($sec eq 'all') ||
1457: exists($curr_groups{$sec})) {
1458: $disallowed{$sec} = $url;
1459: next;
1460: }
1461: my $securl = $url.'/'.$sec;
1462: $r->print(&Apache::loncommon::commit_customrole($udom,$uname,$securl,$three,$four,$five,$start,$end));
1463: }
1464: }
1465: } elsif ($key=~/^form\.act\_($match_domain)\_($match_name)\_([^\_]+)$/) {
1466: # Activate roles for sections with 3 id numbers
1467: # set start, end times, and the url for the class
1468: my ($one,$two,$three)=($1,$2,$3);
1469: my $start = ( $env{'form.start_'.$one.'_'.$two.'_'.$three} ?
1470: $env{'form.start_'.$one.'_'.$two.'_'.$three} :
1471: $now );
1472: my $end = ( $env{'form.end_'.$one.'_'.$two.'_'.$three} ?
1473: $env{'form.end_'.$one.'_'.$two.'_'.$three} :
1474: 0 );
1475: my $url='/'.$one.'/'.$two;
1476: my $type = 'three';
1477: # split multiple sections
1478: my %sections = ();
1479: my $num_sections = &build_roles($env{'form.sec_'.$one.'_'.$two.'_'.$three},\%sections,$three);
1480: if ($num_sections == 0) {
1481: $r->print(&Apache::loncommon::commit_standardrole($udom,$uname,$url,$three,$start,$end,$one,$two,''));
1482: } else {
1483: my %curr_groups =
1484: &Apache::longroup::coursegroups($one,$two);
1485: my $emptysec = 0;
1486: foreach my $sec (sort {$a cmp $b} keys %sections) {
1487: $sec =~ s/\W//g;
1488: if ($sec ne '') {
1489: if (($sec eq 'none') || ($sec eq 'all') ||
1490: exists($curr_groups{$sec})) {
1491: $disallowed{$sec} = $url;
1492: next;
1493: }
1494: my $securl = $url.'/'.$sec;
1495: $r->print(&Apache::loncommon::commit_standardrole($udom,$uname,$securl,$three,$start,$end,$one,$two,$sec));
1496: } else {
1497: $emptysec = 1;
1498: }
1499: }
1500: if ($emptysec) {
1501: $r->print(&Apache::loncommon::commit_standardrole($udom,$uname,$url,$three,$start,$end,$one,$two,''));
1502: }
1503: }
1504: } elsif ($key=~/^form\.act\_([^\_]+)\_([^\_]+)$/) {
1505: # Activate roles for sections with two id numbers
1506: # set start, end times, and the url for the class
1507: my $start = ( $env{'form.start_'.$1.'_'.$2} ?
1508: $env{'form.start_'.$1.'_'.$2} :
1509: $now );
1510: my $end = ( $env{'form.end_'.$1.'_'.$2} ?
1511: $env{'form.end_'.$1.'_'.$2} :
1512: 0 );
1513: my $url='/'.$1.'/';
1514: # split multiple sections
1515: my %sections = ();
1516: my $num_sections = &build_roles($env{'form.sec_'.$1.'_'.$2},\%sections,$2);
1517: if ($num_sections == 0) {
1518: $r->print(&Apache::loncommon::commit_standardrole($udom,$uname,$url,$2,$start,$end,$1,undef,''));
1519: } else {
1520: my $emptysec = 0;
1521: foreach my $sec (sort {$a cmp $b} keys %sections) {
1522: if ($sec ne '') {
1523: my $securl = $url.'/'.$sec;
1524: $r->print(&Apache::loncommon::commit_standardrole($udom,$uname,$securl,$2,$start,$end,$1,undef,$sec));
1525: } else {
1526: $emptysec = 1;
1527: }
1528: }
1529: if ($emptysec) {
1530: $r->print(&Apache::loncommon::commit_standardrole($udom,$uname,$url,$2,$start,$end,$1,undef,''));
1531: }
1532: }
1533: } else {
1534: $r->print('<p>'.&mt('ERROR').': '.&mt('Unknown command').' <tt>'.$key.'</tt></p><br />');
1535: }
1536: foreach my $key (sort(keys(%disallowed))) {
1537: if (($key eq 'none') || ($key eq 'all')) {
1538: $r->print('<p>'.&mt('[_1] may not be used as the name for a section, as it is a reserved word.',$key));
1539: } else {
1540: $r->print('<p>'.&mt('[_1] may not be used as the name for a section, as it is the name of a course group.',$key));
1541: }
1542: $r->print(' '.&mt('Please <a href="javascript:history.go(-1)">go back</a> and choose a different section name.').'</p><br />');
1543: }
1544: }
1545: } # End of foreach (keys(%env))
1546: # Flush the course logs so reverse user roles immediately updated
1547: &Apache::lonnet::flushcourselogs();
1548: $r->print('<p><a href="/adm/createuser">Create/Modify Another User</a></p>');
1549: $r->print(&Apache::loncommon::end_page());
1550: }
1551:
1552: sub quota_admin {
1553: my ($setquota,$changeHash) = @_;
1554: my $quotachanged;
1555: if (&Apache::lonnet::allowed('mpq',$env{'form.ccdomain'})) {
1556: # Current user has quota modification privileges
1557: $quotachanged = 1;
1558: $changeHash->{'portfolioquota'} = $setquota;
1559: }
1560: return $quotachanged;
1561: }
1562:
1563: sub build_roles {
1564: my ($sectionstr,$sections,$role) = @_;
1565: my $num_sections = 0;
1566: if ($sectionstr=~ /,/) {
1567: my @secnums = split/,/,$sectionstr;
1568: if ($role eq 'st') {
1569: $secnums[0] =~ s/\W//g;
1570: $$sections{$secnums[0]} = 1;
1571: $num_sections = 1;
1572: } else {
1573: foreach my $sec (@secnums) {
1574: $sec =~ ~s/\W//g;
1575: if (!($sec eq "")) {
1576: if (exists($$sections{$sec})) {
1577: $$sections{$sec} ++;
1578: } else {
1579: $$sections{$sec} = 1;
1580: $num_sections ++;
1581: }
1582: }
1583: }
1584: }
1585: } else {
1586: $sectionstr=~s/\W//g;
1587: unless ($sectionstr eq '') {
1588: $$sections{$sectionstr} = 1;
1589: $num_sections ++;
1590: }
1591: }
1592:
1593: return $num_sections;
1594: }
1595:
1596: # ========================================================== Custom Role Editor
1597:
1598: sub custom_role_editor {
1599: my $r=shift;
1600: my $rolename=$env{'form.rolename'};
1601:
1602: if ($rolename eq 'make new role') {
1603: $rolename=$env{'form.newrolename'};
1604: }
1605:
1606: $rolename=~s/[^A-Za-z0-9]//gs;
1607:
1608: if (!$rolename) {
1609: &print_username_entry_form($r);
1610: return;
1611: }
1612: # ------------------------------------------------------- What can be assigned?
1613: my %full=();
1614: my %courselevel=();
1615: my %courselevelcurrent=();
1616: my $syspriv='';
1617: my $dompriv='';
1618: my $coursepriv='';
1619: my $body_top;
1620: my ($disp_dummy,$disp_roles) = &Apache::lonnet::get('roles',["st"]);
1621: my ($rdummy,$roledef)=
1622: &Apache::lonnet::get('roles',["rolesdef_$rolename"]);
1623: # ------------------------------------------------------- Does this role exist?
1624: $body_top .= '<h2>';
1625: if (($rdummy ne 'con_lost') && ($roledef ne '')) {
1626: $body_top .= &mt('Existing Role').' "';
1627: # ------------------------------------------------- Get current role privileges
1628: ($syspriv,$dompriv,$coursepriv)=split(/\_/,$roledef);
1629: } else {
1630: $body_top .= &mt('New Role').' "';
1631: $roledef='';
1632: }
1633: $body_top .= $rolename.'"</h2>';
1634: foreach my $item (split(/\:/,$Apache::lonnet::pr{'cr:c'})) {
1635: my ($priv,$restrict)=split(/\&/,$item);
1636: if (!$restrict) { $restrict='F'; }
1637: $courselevel{$priv}=$restrict;
1638: if ($coursepriv=~/\:$priv/) {
1639: $courselevelcurrent{$priv}=1;
1640: }
1641: $full{$priv}=1;
1642: }
1643: my %domainlevel=();
1644: my %domainlevelcurrent=();
1645: foreach my $item (split(/\:/,$Apache::lonnet::pr{'cr:d'})) {
1646: my ($priv,$restrict)=split(/\&/,$item);
1647: if (!$restrict) { $restrict='F'; }
1648: $domainlevel{$priv}=$restrict;
1649: if ($dompriv=~/\:$priv/) {
1650: $domainlevelcurrent{$priv}=1;
1651: }
1652: $full{$priv}=1;
1653: }
1654: my %systemlevel=();
1655: my %systemlevelcurrent=();
1656: foreach my $item (split(/\:/,$Apache::lonnet::pr{'cr:s'})) {
1657: my ($priv,$restrict)=split(/\&/,$item);
1658: if (!$restrict) { $restrict='F'; }
1659: $systemlevel{$priv}=$restrict;
1660: if ($syspriv=~/\:$priv/) {
1661: $systemlevelcurrent{$priv}=1;
1662: }
1663: $full{$priv}=1;
1664: }
1665: my $button_code = "\n";
1666: my $head_script = "\n";
1667: $head_script .= '<script type="text/javascript">'."\n";
1668: my @template_roles = ("cc","in","ta","ep","st");
1669: foreach my $role (@template_roles) {
1670: $head_script .= &make_script_template($role);
1671: $button_code .= &make_button_code($role);
1672: }
1673: $head_script .= '</script>'."\n";
1674: $r->print(&Apache::loncommon::start_page('Custom Role Editor',$head_script));
1675: $r->print($body_top);
1676: my %lt=&Apache::lonlocal::texthash(
1677: 'prv' => "Privilege",
1678: 'crl' => "Course Level",
1679: 'dml' => "Domain Level",
1680: 'ssl' => "System Level");
1681: $r->print('Select a Template<br />');
1682: $r->print('<form action="">');
1683: $r->print($button_code);
1684: $r->print('</form>');
1685: $r->print(<<ENDCCF);
1686: <form name=form1 method="post">
1687: <input type="hidden" name="phase" value="set_custom_roles" />
1688: <input type="hidden" name="rolename" value="$rolename" />
1689: ENDCCF
1690: $r->print(&Apache::loncommon::start_data_table().
1691: &Apache::loncommon::start_data_table_header_row().
1692: '<th>'.$lt{'prv'}.'</th><th>'.$lt{'crl'}.'</th><th>'.$lt{'dml'}.
1693: '</th><th>'.$lt{'ssl'}.'</th>'.
1694: &Apache::loncommon::end_data_table_header_row());
1695: foreach my $priv (sort keys %full) {
1696: my $privtext = &Apache::lonnet::plaintext($priv);
1697: $r->print(&Apache::loncommon::start_data_table_row().
1698: '<td>'.$privtext.'</td><td>'.
1699: ($courselevel{$priv}?'<input type="checkbox" name="'.$priv.'_c" '.
1700: ($courselevelcurrent{$priv}?'checked="1"':'').' />':' ').
1701: '</td><td>'.
1702: ($domainlevel{$priv}?'<input type="checkbox" name="'.$priv.'_d" '.
1703: ($domainlevelcurrent{$priv}?'checked="1"':'').' />':' ').
1704: '</td><td>'.
1705: ($systemlevel{$priv}?'<input type="checkbox" name="'.$priv.'_s" '.
1706: ($systemlevelcurrent{$priv}?'checked="1"':'').' />':' ').
1707: '</td>'.
1708: &Apache::loncommon::end_data_table_row());
1709: }
1710: $r->print(&Apache::loncommon::end_data_table().
1711: '<input type="reset" value="'.&mt("Reset").'" /><input type="submit" value="'.&mt('Define Role').'" /></form>'.
1712: &Apache::loncommon::end_page());
1713: }
1714: # --------------------------------------------------------
1715: sub make_script_template {
1716: my ($role) = @_;
1717: my %full_c=();
1718: my %full_d=();
1719: my %full_s=();
1720: my $return_script;
1721: foreach my $item (split(/\:/,$Apache::lonnet::pr{'cr:c'})) {
1722: my ($priv,$restrict)=split(/\&/,$item);
1723: $full_c{$priv}=1;
1724: }
1725: foreach my $item (split(/\:/,$Apache::lonnet::pr{'cr:d'})) {
1726: my ($priv,$restrict)=split(/\&/,$item);
1727: $full_d{$priv}=1;
1728: }
1729: foreach my $item (split(/\:/,$Apache::lonnet::pr{'cr:s'})) {
1730: my ($priv,$restrict)=split(/\&/,$item);
1731: $full_s{$priv}=1;
1732: }
1733: $return_script .= 'function set_'.$role.'() {'."\n";
1734: my @temp = split(/:/,$Apache::lonnet::pr{$role.':c'});
1735: my %role_c;
1736: foreach my $priv (@temp) {
1737: my ($priv_item, $dummy) = split(/\&/,$priv);
1738: $role_c{$priv_item} = 1;
1739: }
1740: foreach my $priv_item (keys(%full_c)) {
1741: my ($priv, $dummy) = split(/\&/,$priv_item);
1742: if (exists($role_c{$priv})) {
1743: $return_script .= "document.form1.$priv"."_c.checked = true;\n";
1744: } else {
1745: $return_script .= "document.form1.$priv"."_c.checked = false;\n";
1746: }
1747: }
1748: my %role_d;
1749: @temp = split(/:/,$Apache::lonnet::pr{$role.':d'});
1750: foreach my $priv(@temp) {
1751: my ($priv_item, $dummy) = split(/\&/,$priv);
1752: $role_d{$priv_item} = 1;
1753: }
1754: foreach my $priv_item (keys(%full_d)) {
1755: my ($priv, $dummy) = split(/\&/,$priv_item);
1756: if (exists($role_d{$priv})) {
1757: $return_script .= "document.form1.$priv"."_d.checked = true;\n";
1758: } else {
1759: $return_script .= "document.form1.$priv"."_d.checked = false;\n";
1760: }
1761: }
1762: my %role_s;
1763: @temp = split(/:/,$Apache::lonnet::pr{$role.':s'});
1764: foreach my $priv(@temp) {
1765: my ($priv_item, $dummy) = split(/\&/,$priv);
1766: $role_s{$priv_item} = 1;
1767: }
1768: foreach my $priv_item (keys(%full_s)) {
1769: my ($priv, $dummy) = split(/\&/,$priv_item);
1770: if (exists($role_s{$priv})) {
1771: $return_script .= "document.form1.$priv"."_s.checked = true;\n";
1772: } else {
1773: $return_script .= "document.form1.$priv"."_s.checked = false;\n";
1774: }
1775: }
1776: $return_script .= '}'."\n";
1777: return ($return_script);
1778: }
1779: # ----------------------------------------------------------
1780: sub make_button_code {
1781: my ($role) = @_;
1782: my $label = &Apache::lonnet::plaintext($role);
1783: my $button_code = '<input type="button" onClick="set_'.$role.'()" value="'.$label.'" />';
1784: return ($button_code);
1785: }
1786: # ---------------------------------------------------------- Call to definerole
1787: sub set_custom_role {
1788: my ($r) = @_;
1789:
1790: my $rolename=$env{'form.rolename'};
1791:
1792: $rolename=~s/[^A-Za-z0-9]//gs;
1793:
1794: if (!$rolename) {
1795: &print_username_entry_form($r);
1796: return;
1797: }
1798:
1799: $r->print(&Apache::loncommon::start_page('Save Custom Role').'<h2>');
1800: my ($rdummy,$roledef)=
1801: &Apache::lonnet::get('roles',["rolesdef_$rolename"]);
1802:
1803: # ------------------------------------------------------- Does this role exist?
1804: if (($rdummy ne 'con_lost') && ($roledef ne '')) {
1805: $r->print(&mt('Existing Role').' "');
1806: } else {
1807: $r->print(&mt('New Role').' "');
1808: $roledef='';
1809: }
1810: $r->print($rolename.'"</h2>');
1811: # ------------------------------------------------------- What can be assigned?
1812: my $sysrole='';
1813: my $domrole='';
1814: my $courole='';
1815:
1816: foreach my $item (split(/\:/,$Apache::lonnet::pr{'cr:c'})) {
1817: my ($priv,$restrict)=split(/\&/,$item);
1818: if (!$restrict) { $restrict=''; }
1819: if ($env{'form.'.$priv.'_c'}) {
1820: $courole.=':'.$item;
1821: }
1822: }
1823:
1824: foreach my $item (split(/\:/,$Apache::lonnet::pr{'cr:d'})) {
1825: my ($priv,$restrict)=split(/\&/,$item);
1826: if (!$restrict) { $restrict=''; }
1827: if ($env{'form.'.$priv.'_d'}) {
1828: $domrole.=':'.$item;
1829: }
1830: }
1831:
1832: foreach my $item (split(/\:/,$Apache::lonnet::pr{'cr:s'})) {
1833: my ($priv,$restrict)=split(/\&/,$item);
1834: if (!$restrict) { $restrict=''; }
1835: if ($env{'form.'.$priv.'_s'}) {
1836: $sysrole.=':'.$item;
1837: }
1838: }
1839: $r->print('<br />Defining Role: '.
1840: &Apache::lonnet::definerole($rolename,$sysrole,$domrole,$courole));
1841: if ($env{'request.course.id'}) {
1842: my $url='/'.$env{'request.course.id'};
1843: $url=~s/\_/\//g;
1844: $r->print('<br />'.&mt('Assigning Role to Self').': '.
1845: &Apache::lonnet::assigncustomrole($env{'user.domain'},
1846: $env{'user.name'},
1847: $url,
1848: $env{'user.domain'},
1849: $env{'user.name'},
1850: $rolename));
1851: }
1852: $r->print('<p><a href="/adm/createuser">Create another role, or Create/Modify a user.</a></p>');
1853: $r->print(&Apache::loncommon::end_page());
1854: }
1855:
1856: # ================================================================ Main Handler
1857: sub handler {
1858: my $r = shift;
1859:
1860: if ($r->header_only) {
1861: &Apache::loncommon::content_type($r,'text/html');
1862: $r->send_http_header;
1863: return OK;
1864: }
1865:
1866: if ((&Apache::lonnet::allowed('cta',$env{'request.course.id'})) ||
1867: (&Apache::lonnet::allowed('cin',$env{'request.course.id'})) ||
1868: (&Apache::lonnet::allowed('ccr',$env{'request.course.id'})) ||
1869: (&Apache::lonnet::allowed('cep',$env{'request.course.id'})) ||
1870: (&authorpriv($env{'user.name'},$env{'request.role.domain'})) ||
1871: (&Apache::lonnet::allowed('mau',$env{'request.role.domain'}))) {
1872: &Apache::loncommon::content_type($r,'text/html');
1873: $r->send_http_header;
1874: if (!$env{'form.phase'}) {
1875: &print_username_entry_form($r);
1876: }
1877: if ($env{'form.phase'} eq 'get_user_info') {
1878: &print_user_modification_page($r);
1879: } elsif ($env{'form.phase'} eq 'update_user_data') {
1880: &update_user_data($r);
1881: } elsif ($env{'form.phase'} eq 'selected_custom_edit') {
1882: &custom_role_editor($r);
1883: } elsif ($env{'form.phase'} eq 'set_custom_roles') {
1884: &set_custom_role($r);
1885: }
1886: } else {
1887: $env{'user.error.msg'}=
1888: "/adm/createuser:mau:0:0:Cannot modify user data";
1889: return HTTP_NOT_ACCEPTABLE;
1890: }
1891: return OK;
1892: }
1893:
1894: #-------------------------------------------------- functions for &phase_two
1895: sub course_level_table {
1896: my (%inccourses) = @_;
1897: my $table = '';
1898: # Custom Roles?
1899:
1900: my %customroles=&my_custom_roles();
1901: my %lt=&Apache::lonlocal::texthash(
1902: 'exs' => "Existing sections",
1903: 'new' => "Define new section",
1904: 'ssd' => "Set Start Date",
1905: 'sed' => "Set End Date",
1906: 'crl' => "Course Level",
1907: 'act' => "Activate",
1908: 'rol' => "Role",
1909: 'ext' => "Extent",
1910: 'grs' => "Section",
1911: 'sta' => "Start",
1912: 'end' => "End"
1913: );
1914:
1915: foreach my $protectedcourse (sort( keys(%inccourses))) {
1916: my $thiscourse=$protectedcourse;
1917: $thiscourse=~s:_:/:g;
1918: my %coursedata=&Apache::lonnet::coursedescription($thiscourse);
1919: my $area=$coursedata{'description'};
1920: my $type=$coursedata{'type'};
1921: if (!defined($area)) { $area=&mt('Unavailable course').': '.$protectedcourse; }
1922: my ($domain,$cnum)=split(/\//,$thiscourse);
1923: my %sections_count;
1924: if (defined($env{'request.course.id'})) {
1925: if ($env{'request.course.id'} eq $domain.'_'.$cnum) {
1926: %sections_count =
1927: &Apache::loncommon::get_sections($domain,$cnum);
1928: }
1929: }
1930: foreach my $role ('st','ta','ep','in','cc') {
1931: if (&Apache::lonnet::allowed('c'.$role,$thiscourse)) {
1932: my $plrole=&Apache::lonnet::plaintext($role);
1933: $table .= &Apache::loncommon::start_data_table_row().
1934: '<td><input type="checkbox" name="act_'.$protectedcourse.'_'.$role.'" /></td>
1935: <td>'.$plrole.'</td>
1936: <td>'.$area.'<br />Domain: '.$domain.'</td>'."\n";
1937: if ($role ne 'cc') {
1938: if (%sections_count) {
1939: my $currsec = &course_sections(\%sections_count,$protectedcourse.'_'.$role);
1940: $table .=
1941: '<td><table class="LC_createuser">'.
1942: '<tr class="LC_section_row">
1943: <td valign="top">'.$lt{'exs'}.'<br />'.
1944: $currsec.'</td>'.
1945: '<td> </td>'.
1946: '<td valign="top"> '.$lt{'new'}.'<br />'.
1947: '<input type="text" name="newsec_'.$protectedcourse.'_'.$role.'" value="" />'.
1948: '<input type="hidden" '.
1949: 'name="sec_'.$protectedcourse.'_'.$role.'" /></td>'.
1950: '</tr></table></td>';
1951: } else {
1952: $table .= '<td><input type="text" size="10" '.
1953: 'name="sec_'.$protectedcourse.'_'.$role.'" /></td>';
1954: }
1955: } else {
1956: $table .= '<td> </td>';
1957: }
1958: $table .= <<ENDTIMEENTRY;
1959: <td><input type=hidden name="start_$protectedcourse\_$role" value='' />
1960: <a href=
1961: "javascript:pjump('date_start','Start Date $plrole',document.cu.start_$protectedcourse\_$role.value,'start_$protectedcourse\_$role','cu.pres','dateset')">$lt{'ssd'}</a></td>
1962: <td><input type=hidden name="end_$protectedcourse\_$role" value='' />
1963: <a href=
1964: "javascript:pjump('date_end','End Date $plrole',document.cu.end_$protectedcourse\_$role.value,'end_$protectedcourse\_$role','cu.pres','dateset')">$lt{'sed'}</a></td>
1965: ENDTIMEENTRY
1966: $table.= &Apache::loncommon::end_data_table_row();
1967: }
1968: }
1969: foreach my $cust (sort keys %customroles) {
1970: if (&Apache::lonnet::allowed('ccr',$thiscourse)) {
1971: my $plrole=$cust;
1972: my $customrole=$protectedcourse.'_cr_cr_'.$env{'user.domain'}.
1973: '_'.$env{'user.name'}.'_'.$plrole;
1974: $table .= &Apache::loncommon::start_data_table_row().
1975: '<td><input type="checkbox" name="act_'.$customrole.'" /></td>
1976: <td>'.$plrole.'</td>
1977: <td>'.$area.'</td>'."\n";
1978: if (%sections_count) {
1979: my $currsec = &course_sections(\%sections_count,$customrole);
1980: $table.=
1981: '<td><table border="0" cellspacing="0" cellpadding="0">'.
1982: '<tr><td valign="top">'.$lt{'exs'}.'<br />'.
1983: $currsec.'</td>'.
1984: '<td> </td>'.
1985: '<td valign="top"> '.$lt{'new'}.'<br />'.
1986: '<input type="text" name="newsec_'.$customrole.'" value="" /></td>'.
1987: '<input type="hidden" '.
1988: 'name="sec_'.$customrole.'" /></td>'.
1989: '</tr></table></td>';
1990: } else {
1991: $table .= '<td><input type="text" size="10" '.
1992: 'name="sec_'.$customrole.'" /></td>';
1993: }
1994: $table .= <<ENDENTRY;
1995: <td><input type=hidden name="start_$customrole" value='' />
1996: <a href=
1997: "javascript:pjump('date_start','Start Date $plrole',document.cu.start_$customrole.value,'start_$customrole','cu.pres','dateset')">$lt{'ssd'}</a></td>
1998: <td><input type=hidden name="end_$customrole" value='' />
1999: <a href=
2000: "javascript:pjump('date_end','End Date $plrole',document.cu.end_$customrole.value,'end_$customrole','cu.pres','dateset')">$lt{'sed'}</a></td>
2001: ENDENTRY
2002: $table .= &Apache::loncommon::end_data_table_row();
2003: }
2004: }
2005: }
2006: return '' if ($table eq ''); # return nothing if there is nothing
2007: # in the table
2008: my $result = '
2009: <h4>'.$lt{'crl'}.'</h4>'.
2010: &Apache::loncommon::start_data_table().
2011: &Apache::loncommon::start_data_table_header_row().
2012: '<th>'.$lt{'act'}.'</th><th>'.$lt{'rol'}.'</th><th>'.$lt{'ext'}.'</th>
2013: <th>'.$lt{'grs'}.'</th><th>'.$lt{'sta'}.'</th><th>'.$lt{'end'}.'</th>'.
2014: &Apache::loncommon::end_data_table_header_row().
2015: $table.
2016: &Apache::loncommon::end_data_table();
2017: return $result;
2018: }
2019:
2020: sub course_sections {
2021: my ($sections_count,$role) = @_;
2022: my $output = '';
2023: my @sections = (sort {$a <=> $b} keys %{$sections_count});
2024: if (scalar(@sections) == 1) {
2025: $output = '<select name="currsec_'.$role.'" >'."\n".
2026: ' <option value="">Select</option>'."\n".
2027: ' <option value="">No section</option>'."\n".
2028: ' <option value="'.$sections[0].'" >'.$sections[0].'</option>'."\n";
2029: } else {
2030: $output = '<select name="currsec_'.$role.'" ';
2031: my $multiple = 4;
2032: if (scalar(@sections) < 4) { $multiple = scalar(@sections); }
2033: $output .= 'multiple="multiple" size="'.$multiple.'">'."\n";
2034: foreach my $sec (@sections) {
2035: $output .= '<option value="'.$sec.'">'.$sec."</option>\n";
2036: }
2037: }
2038: $output .= '</select>';
2039: return $output;
2040: }
2041:
2042: sub course_level_dc {
2043: my ($dcdom) = @_;
2044: my %customroles=&my_custom_roles();
2045: my $hiddenitems = '<input type="hidden" name="dcdomain" value="'.$dcdom.'" />'.
2046: '<input type="hidden" name="origdom" value="'.$dcdom.'" />'.
2047: '<input type="hidden" name="dccourse" value="" />';
2048: my $courseform='<b>'.&Apache::loncommon::selectcourse_link
2049: ('cu','dccourse','dcdomain','coursedesc',undef,undef,'Course').'</b>';
2050: my $cb_jscript = &Apache::loncommon::coursebrowser_javascript($dcdom,'currsec','cu');
2051: my %lt=&Apache::lonlocal::texthash(
2052: 'rol' => "Role",
2053: 'grs' => "Section",
2054: 'exs' => "Existing sections",
2055: 'new' => "Define new section",
2056: 'sta' => "Start",
2057: 'end' => "End",
2058: 'ssd' => "Set Start Date",
2059: 'sed' => "Set End Date"
2060: );
2061: my $header = '<h4>'.&mt('Course Level').'</h4>'.
2062: &Apache::loncommon::start_data_table().
2063: &Apache::loncommon::start_data_table_header_row().
2064: '<th>'.$courseform.'</th><th>'.$lt{'rol'}.'</th><th>'.$lt{'grs'}.'</th><th>'.$lt{'sta'}.'</th><th>'.$lt{'end'}.'</th>'.
2065: &Apache::loncommon::end_data_table_header_row();
2066: my $otheritems = &Apache::loncommon::start_data_table_row()."\n".
2067: '<td><input type="text" name="coursedesc" value="" onFocus="this.blur();opencrsbrowser('."'cu','dccourse','dcdomain','coursedesc',''".')" /></td>'."\n".
2068: '<td><select name="role">'."\n";
2069: foreach my $role ('st','ta','ep','in','cc') {
2070: my $plrole=&Apache::lonnet::plaintext($role);
2071: $otheritems .= ' <option value="'.$role.'">'.$plrole;
2072: }
2073: if ( keys %customroles > 0) {
2074: foreach my $cust (sort keys %customroles) {
2075: my $custrole='cr_cr_'.$env{'user.domain'}.
2076: '_'.$env{'user.name'}.'_'.$cust;
2077: $otheritems .= ' <option value="'.$custrole.'">'.$cust;
2078: }
2079: }
2080: $otheritems .= '</select></td><td>'.
2081: '<table border="0" cellspacing="0" cellpadding="0">'.
2082: '<tr><td valign="top"><b>'.$lt{'exs'}.'</b><br /><select name="currsec">'.
2083: ' <option value=""><--'.&mt('Pick course first').'</select></td>'.
2084: '<td> </td>'.
2085: '<td valign="top"> <b>'.$lt{'new'}.'</b><br />'.
2086: '<input type="text" name="newsec" value="" />'.
2087: '<input type="hidden" name="groups" value="" /></td>'.
2088: '</tr></table></td>';
2089: $otheritems .= <<ENDTIMEENTRY;
2090: <td><input type=hidden name="start" value='' />
2091: <a href=
2092: "javascript:pjump('date_start','Start Date',document.cu.start.value,'start','cu.pres','dateset')">$lt{'ssd'}</a></td>
2093: <td><input type=hidden name="end" value='' />
2094: <a href=
2095: "javascript:pjump('date_end','End Date',document.cu.end.value,'end','cu.pres','dateset')">$lt{'sed'}</a></td>
2096: ENDTIMEENTRY
2097: $otheritems .= &Apache::loncommon::end_data_table_row().
2098: &Apache::loncommon::end_data_table()."\n";
2099: return $cb_jscript.$header.$hiddenitems.$otheritems;
2100: }
2101:
2102: #---------------------------------------------- end functions for &phase_two
2103:
2104: #--------------------------------- functions for &phase_two and &phase_three
2105:
2106: #--------------------------end of functions for &phase_two and &phase_three
2107:
2108: 1;
2109: __END__
2110:
2111:
FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>