File:  [LON-CAPA] / loncom / interface / lonexttool.pm
Revision 1.25: download - view: text, annotated - select for diffs
Fri Jun 2 01:20:26 2023 UTC (19 months, 1 week ago) by raeburn
Branches: MAIN
CVS tags: version_2_12_X, HEAD
- Bugs 6754 and 6907
  - Return of grades to launcher CMS supported for resources or folders
    accessed via LTI-mediated deep link.
  - Support option: "Encrypt stored consumer secrets defined in domain"
  - Signing of LTI payloads for roster retrieval, passback of grades,
    and callback to logput launcher CMS session all now occur on
    primary library server for course's domain.

# The LearningOnline Network with CAPA
# Launch External Tool Provider (LTI)
#
# $Id: lonexttool.pm,v 1.25 2023/06/02 01:20:26 raeburn Exp $
#
# Copyright Michigan State University Board of Trustees
#
# This file is part of the LearningOnline Network with CAPA (LON-CAPA).
#
# LON-CAPA is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# LON-CAPA is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with LON-CAPA; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
#
# /home/httpd/html/adm/gpl.txt
#
# http://www.lon-capa.org/
#

=pod

=head1 NAME

Apache::lonexttool - Tool Provider launcher

=head1 SYNOPSIS


=head1 OVERVIEW

=cut

package Apache::lonexttool;

use strict;
use Apache::Constants qw(:common :http);
use Encode;
use Digest::SHA;
use HTML::Entities;
use Apache::lonlocal;
use Apache::lonnet;
use Apache::loncommon;
use Apache::londatecheck;
use Apache::lonipcheck;
use Apache::lonhomework;
use Apache::structuretags;
use LONCAPA::ltiutils;

sub handler {
    my $r=shift;
    &Apache::loncommon::content_type($r,'text/html');
    $r->send_http_header;

    return OK if $r->header_only;

    my $target=$env{'form.grade_target'};
# ------------------------------------------------------------ Print the screen
    if ($target eq 'tex') {
        $r->print(&Apache::lonprintout::print_latex_header($env{'form.latex_type'}));
    } else {
        $target = 'web';
    }

# Is this even in a course?
    unless ($env{'request.course.id'}) {
        if ($target ne 'tex') {
            &Apache::loncommon::simple_error_page($r,'','Not in a course',
                                                  {'only_body' => 1});
        } else {
            $r->print('\textbf{Not in a course}\end{document}');
        }
        return OK;
    }

    my ($marker,$exttool) = (split(m{/},$r->uri))[4,5];
    $marker=~s/\D//g;

    if (!$marker) {
        if ($target ne 'tex') {
            $r->print(&mt('Invalid Call'));
        } else {
            $r->print('\textbf{'&mt('Invalid Call').'}\end{document}');
        }
        return OK;
    }

    my $cdom = $env{'course.'.$env{'request.course.id'}.'.domain'};
    my $cnum = $env{'course.'.$env{'request.course.id'}.'.num'};
    my $chome = $env{'course.'.$env{'request.course.id'}.'.home'};
    my ($idx,$crstool,$is_tool,%toolhash,%toolsettings);

    if ($r->uri eq "/adm/$cdom/$cnum/$marker/$exttool") {
        %toolsettings=&Apache::lonnet::dump('exttool_'.$marker,$cdom,$cnum);
        if ($toolsettings{'id'}) {
            my %ltitools;
            if ($toolsettings{'id'} =~ /^c(\d+)$/) {
                $idx = $1;
                $crstool = 1;
                %ltitools = &Apache::lonnet::get_course_lti($cnum,$cdom,'consumer');
            } else {
                $idx = $toolsettings{'id'};
                %ltitools = &Apache::lonnet::get_domain_lti($cdom,'consumer');
            }
            if (ref($ltitools{$idx}) eq 'HASH') {
                %toolhash = %{$ltitools{$idx}};
                $toolhash{'display'} = {
                                           target => $toolsettings{'target'},
                                           width  => $toolsettings{'width'},
                                           height => $toolsettings{'height'},
                                       };
                foreach my $item (qw(crslabel crstitle crsappend gradable)) {
                    $toolhash{$item} = $toolsettings{$item};
                }
                $is_tool = 1;
            }
        }
    }
    unless ($is_tool) {
        if ($target ne 'tex') {
            $r->print('<div>'.&mt('Invalid Call').'</div>');
        } else {
            $r->print('\textbf{'.&mt(Invalid Call).'}\end{document}');
        }
        return OK;
    }

    my ($symb,$status,$open,$close,$msg,$donebuttonresult,$donemsg);
    if (($target eq 'tex') || ($toolhash{'gradable'})) {
        ($symb) = &Apache::lonnet::whichuser();
    }
    if ($target eq 'tex') {
        my $title = &Apache::lonnet::gettitle($symb);
        $r->print(&mt('External Tool: [_1]','\textit{'.$title.'}').'\\\\');
    }
    if ($toolhash{'gradable'}) {
        $Apache::lonhomework::browse = &Apache::lonnet::allowed('bre',$r->uri);
        if ($env{'form.markaccess'}) {
            my @interval=&Apache::lonnet::EXT('resource.0.interval',$symb);
            my ($timelimit) = split(/_/,$interval[0]);
            &Apache::lonnet::set_first_access($interval[1],$timelimit);
        } elsif ($symb && $env{'form.LC_interval_done'} eq 'true') {
            # Set the event timer to zero if the "done button" was clicked.  The button is
            # part of the doneButton form created in lonmenu.pm
            ($donebuttonresult,$donemsg) = &Apache::lonhomework::zero_timer($symb);
            undef($env{'form.LC_interval_done'});
            undef($env{'form.LC_interval_done_proctorpass'});
        }
        ($status,$msg) = &gradabletool_access_check($target);
        undef($Apache::lonhomework::browse);
        if ($status eq 'SHOW_ANSWER') {
            $r->print(&display_score($target));
            if ($target eq 'tex') {
                $r->print('\end{document}');
            }
            return OK;
        } elsif ($status ne 'CAN_ANSWER') {
            if ($target eq 'tex') {
                $r->print('\end{document}');
            } else {
                $r->print($msg);
            }
            return OK;
        }
    } else {
        my ($status,$open,$close,$msg)=&Apache::londatecheck::content_date_check();
        if ($status ne 'OPEN') {
            if ($target eq 'tex') {
                $r->print(&mt('Not open to be viewed').'\end{document}');
            } else {
                $r->print($msg);
            }
            return OK;
        } else {
            ($status,$msg)=&Apache::lonipcheck::ip_access_check();
            if ($status ne 'OPEN') {
                if ($target eq 'tex') {
                    $r->print(&mt('Not open to be viewed').'\end{document}');
                } else {
                    $r->print($msg);
                }
                return OK;
            }
        }
    }
    my $launchok = 1;
    if ($target eq 'tex') {
        $r->print('\end{document}');
    } else {
        my $now = time;
        if ($toolhash{'passback'}) {
            if (&LONCAPA::ltiutils::set_service_secret($cdom,$cnum,$marker,'grade',$now,
                                                       \%toolsettings,\%toolhash) eq 'ok') {
                $toolhash{'gradesecret'} = $toolsettings{'gradesecret'};
            } else {
                undef($launchok);
            }
        }
        if ($toolhash{'roster'}) {
            if (&LONCAPA::ltiutils::set_service_secret($cdom,$cnum,$marker,'roster',$now,
                                                       \%toolsettings,\%toolhash) eq 'ok') {
                $toolhash{'rostersecret'} = $toolsettings{'rostersecret'};
            }
        }
        my $submittext = &mt('Launch [_1]',$toolhash{'title'});
        if (($toolhash{'url'} ne '') && ($launchok)) {
            my %lti = &lti_params($r,$cnum,$cdom,$idx,$submittext,\%toolhash);
            my $url = $toolhash{'url'};
            if ($toolhash{'crsappend'} ne '') {
                $url .= $toolhash{'crsappend'};
            }
            my %info = (
                         method => $toolhash{'sigmethod'},
                       );
            $r->print(&launch_html($cdom,$cnum,$crstool,$url,$idx,
                                   $toolhash{'cipher'},$submittext,\%lti,\%info));
        } else {
            $r->print('<div class="LC_warning">'.&mt('External Tool Unavailable').'</div>');
        }
    }
    return OK;
}

sub lti_params {
    my ($r,$cnum,$cdom,$idx,$submittext,$toolsref) = @_;
    my ($version,$context_type,$msgtype,$toolname,$passback,$roster,$locale,
        $crslabel,$crstitle,$gradesecret,$rostersecret,%fields,%rolesmap,
        %display,%custom,@userlangs,$incdom);
    if (ref($toolsref) eq 'HASH') {
        $version = $toolsref->{'version'};
        $toolname = $toolsref->{'title'};
        $passback = $toolsref->{'passback'};
        $gradesecret = $toolsref->{'gradesecret'};
        $roster = $toolsref->{'roster'};
        $rostersecret = $toolsref->{'rostersecret'};
        $msgtype = $toolsref->{'messagetype'};
        $incdom = $toolsref->{'incdom'};
        if (ref($toolsref->{'fields'}) eq 'HASH') {
            %fields = %{$toolsref->{'fields'}};
        }
        if (ref($toolsref->{'roles'}) eq 'HASH') {
            %rolesmap = %{$toolsref->{'roles'}};
        }
        if (ref($toolsref->{'display'}) eq 'HASH') {
            %display = %{$toolsref->{'display'}};
        }
        if (ref($toolsref->{'custom'}) eq 'HASH') {
            %custom = %{$toolsref->{'custom'}};
        }
        $crslabel = $toolsref->{'crslabel'};
        $crstitle = $toolsref->{'crstitle'};
    }
    if ($version eq '') {
        $version = 'LTI-1p0';
    }
    if ($context_type eq '') {
        $context_type = 'CourseSection';
    }
    if ($msgtype eq '') {
        $msgtype = 'basic-lti-launch-request';
    }
    if ($crslabel eq '') {
        $crslabel = $env{'course.'.$env{'request.course.id'}.'.internal.coursecode'};
    }
    if ($crstitle eq '') {
        $crstitle = $env{'course.'.$env{'request.course.id'}.'.description'};
    }
    my $lonhost = $r->dir_config('lonHostID');
    my $loncaparev = $r->dir_config('lonVersion');
    my $uname = $env{'user.name'};
    my $udom = $env{'user.domain'};
    my @possroles = qw(Instructor ContentDeveloper TeachingAssistant Learner);
    my ($roleprefix) = ($env{'request.role'} =~ /^(\w+)\./);
    my $ltirole = $rolesmap{$roleprefix};
    unless (grep(/^\Q$ltirole\E$/,@possroles)) {
        $ltirole = 'Learner';
    }
    my @possdigest;
    my $digest_user = &Encode::decode('UTF-8',$uname.':'.$udom);
    $digest_user = &Digest::SHA::sha1_hex($digest_user);
    push(@possdigest,$digest_user);
    if ($env{'course.'.$env{'request.course.id'}.'.languages'} ne '') {
        @userlangs=(@userlangs,split(/\s*(\,|\;|\:)\s*/,
                    $env{'course.'.$env{'request.course.id'}.'.languages'}));
    } else {
        my %langhash = &Apache::loncommon::getlangs($uname,$udom);
        if ($langhash{'languages'} ne '') {
            @userlangs = split(/\s*(\,|\;|\:)\s*/,$langhash{'languages'});
        } else {
            my %domdefs = &Apache::lonnet::get_domain_defaults($udom);
            if ($domdefs{'lang_def'} ne '') {
                @userlangs = ($domdefs{'lang_def'});
            }
        }
    }
    if (scalar(@userlangs) == 1) {
        $locale = $userlangs[0];
    }
    my ($title,$digest_symb);
    my ($symb) = &Apache::lonnet::whichuser();
    if ($symb) {
        $digest_symb = &Encode::decode('UTF-8',$symb);
        $digest_symb = &Digest::SHA::sha1_hex($digest_symb);
        push(@possdigest,$digest_symb);
        my $navmap = Apache::lonnavmaps::navmap->new();
        if (ref($navmap)) {
            my $res = $navmap->getBySymb($symb);
            if (ref($res)) {
                $title = $res->compTitle();
            }
        }
    }
    my $domdesc = &Apache::lonnet::domain($cdom);
    my $primary_id = &Apache::lonnet::domain($cdom,'primary');
    my $int_dom = &Apache::lonnet::internet_dom($primary_id);
    my $portal_url = &Apache::lonnet::course_portal_url($cnum,$cdom,$r);

    my %ltiparams = (
        lti_version                            => $version,
        lti_message_type                       => $msgtype,
        resource_link_title                    => $title,
        resource_link_id                       => $digest_symb,
        tool_consumer_instance_guid            => $lonhost,
        tool_consumer_instance_description     => $domdesc,
        tool_consumer_info_product_family_code => 'loncapa',
        tool_consumer_instance_name            => $int_dom,
        tool_consumer_instance_url             => $portal_url,
        tool_consumer_info_version             => $loncaparev,
        user_id                                => $digest_user,
        roles                                  => $ltirole,
        context_id                             => $env{'request.course.id'},
        context_type                           => $context_type,
        context_label                          => $crslabel,
        context_title                          => $crstitle,
        launch_presentation_locale             => $locale,
    );
    my $crshome = $env{'course.'.$env{'request.course.id'}.'.home'};
    my $crshostname = &Apache::lonnet::hostname($crshome);
    if ($crshostname) {
        my $crsprotocol = $Apache::lonnet::protocol{$crshome};
        unless ($crsprotocol eq 'https') {
            $crsprotocol = 'http';
        }
        if (($passback) || ($roster)) {
            my (%currdigest,%digesthash);
            if (@possdigest) {
                %currdigest = &Apache::lonnet::get('exttools',\@possdigest,
                                                   $cdom,$cnum);
            }
            if ($passback) {
                $ltiparams{'lis_outcome_service_url'} = $crsprotocol.'://'.$crshostname.'/adm/service/passback';
                $ltiparams{'ext_ims_lis_basic_outcome_url'} = $ltiparams{'lis_outcome_service_url'};
                if ($gradesecret) {
                    my $uniqid = $digest_symb.':::'.$digest_user.':::'.$env{'request.course.id'};
                    $ltiparams{'lis_result_sourcedid'} = &LONCAPA::ltiutils::get_service_id($gradesecret,$uniqid);
                }
            }
            if ($roster) {
                if (&Apache::lonnet::allowed('opa',$env{'request.course.id'})) {
                    $ltiparams{'ext_ims_lis_memberships_url'} = $crsprotocol.'://'.$crshostname.'/adm/service/roster';
                    if ($rostersecret) {
                        my $uniqid = $digest_symb.':::'.$env{'request.course.id'};
                        $ltiparams{'ext_ims_lis_memberships_id'} = &LONCAPA::ltiutils::get_service_id($rostersecret,$uniqid);
                    }
                }
            }
            if (($digest_symb) && ($gradesecret || $rostersecret)) {
                unless ((exists($currdigest{$digest_symb})) && ($currdigest{$digest_symb} eq $symb)) {
                    $digesthash{$digest_symb} = $symb;
                }
            }
            if (($passback) && ($gradesecret)) {
                unless ((exists($currdigest{$digest_user})) && ($currdigest{$digest_user} eq $uname.':'.$udom)) {
                    $digesthash{$digest_user} = $uname.':'.$udom;
                }
            }
            if (keys(%digesthash)) {
                &Apache::lonnet::put('exttools',\%digesthash,$cdom,$cnum);
            }
        }
    }
    if ($display{'target'}) {
        $ltiparams{'launch_presentation_document_target'} = $display{'target'};
    }
    if ($display{'width'}) {
        $ltiparams{'launch_presentation_width'} = $display{'width'};
    }
    if ($display{'height'}) {
        $ltiparams{'launch_presentation_height'} = $display{'height'};
    }
    if ($fields{'firstname'}) {
        $ltiparams{'lis_person_name_given'} = $env{'environment.firstname'};
    }
    if ($fields{'lastname'}) {
        $ltiparams{'lis_person_name_family'} = $env{'environment.lastname'};
    }
    if ($fields{'fullname'}) {
        $ltiparams{'lis_person_name_full'} = &Apache::loncommon::plainname($uname,$udom);
    }
    if ($fields{'email'}) {
        my %emails = &Apache::loncommon::getemails($uname,$udom);
        my $contact_email;
        foreach my $type ('permanentemail','critnotification','notification') {
            if ($emails{$type} =~ /\@/) {
                $contact_email = $emails{$type};
                last;
            }
        }
        $ltiparams{'lis_person_contact_email_primary'} = $contact_email;
    }
    if ($fields{'user'}) {
        if ($incdom) {
            $ltiparams{'lis_person_sourcedid'} = $uname.':'.$udom;
        } else {
            $ltiparams{'lis_person_sourcedid'} = $uname;
        }
    }
    if (keys(%custom)) {
        foreach my $key (keys(%custom)) {
            my $value = $custom{$key};
            $value =~ s/^\s+|\s+\$//g;
            if ($value =~ /^\QLONCAPA::env{\E([^\}]+)\}$/) {
                if (exists($env{$1})) {
                    $value = $env{$1};
                }
            }
            $ltiparams{'custom_'.$key} = $value;
        }
    }
    foreach my $key (keys(%ltiparams)) {
        $ltiparams{$key} = &Encode::decode('UTF-8',$ltiparams{$key});
    }
    $ltiparams{'basiclti_submit'} = $submittext;
    return %ltiparams;
}

sub launch_html {
    my ($cdom,$cnum,$crstool,$url,$idx,$keynum,$submittext,$paramsref,$inforef) = @_;
    my ($status,$hashref) =
        &Apache::lonnet::sign_lti($cdom,$cnum,$crstool,'tools','launch',$url,$idx,$keynum,
                                  $paramsref,$inforef);
    unless ($status eq 'ok') {
        return '<div class="LC_warning">'.&mt('External Tool Unavailable').'</div>';
    }
    my $action = &HTML::Entities::encode($url,'<>&"');
    my $form = <<"END";
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<body>
<div id="LCltiLaunch">
<form name="LCltiLaunchForm" id="LCltiLaunchFormId" action="$action" method="post" encType="application/x-www-form-urlencoded">
END
    if (ref($hashref) eq 'HASH') {
        foreach my $item (keys(%{$hashref})) {
            my $type = 'hidden';
            if ($item eq 'basiclti_submit') {
                $type = 'submit';
            }
            $form .= '<input type="'.$type.'" name="'.$item.'" value="'.$hashref->{$item}.'" id="id_'.$item.'" />'."\n";
        }
    }
    $form .= "</form></div>\n";
    $form .= <<"ENDJS";
<script type="text/javascript">
    document.getElementById("LCltiLaunch").style.display = "none";
    nei = document.createElement('input');
    nei.setAttribute('type','hidden');
    nei.setAttribute('name','basiclti_submit');
    nei.setAttribute('value','$submittext');
    document.getElementById("LCltiLaunchFormId").appendChild(nei);
    document.LCltiLaunchForm.submit();
 </script>
ENDJS
    $form .= "</body></html>\n";
    return $form;
}

sub gradabletool_access_check {
    my ($target) = @_;
    my ($result,$resource_due);
    my $status;
    my ($symb,$courseid,$udom,$uname) = &Apache::lonnet::whichuser();
    my @targets;
    if ($target) {
        @targets = ($target);
    } elsif (defined($env{'form.submitted'}) && defined($env{'form.validate'})) {
        @targets = ('grade','web');
    } else {
        @targets = ('web');
    }
    foreach my $target (@targets) {
        &Apache::structuretags::initialize_storage($symb);
        &Apache::lonhomework::set_show_problem_status(&Apache::lonnet::EXT('resource.0.problemstatus'));
        my ($accessmsg,$slot_name,$slot,$ipused);
        ($status,$accessmsg,$slot_name,$slot,$ipused) =
            &Apache::lonhomework::check_slot_access('0','tool',$symb);
        if (( $status eq 'CLOSED' ) ||
            ( $status eq 'UNCHECKEDOUT') ||
            ( $status eq 'NOT_YET_VIEWED') ||
            ( $status eq 'BANNED') ||
            ( $status eq 'UNAVAILABLE') ||
            ( $status eq 'NOT_IN_A_SLOT') ||
            ( $status eq 'NOTRESERVABLE') ||
            ( $status eq 'RESERVABLE') ||
            ( $status eq 'RESERVABLE_LATER') ||
            ( $status eq 'INVALID_ACCESS') ||
            ( $status eq 'NEED_DIFFERENT_IP') ||
            ( $status eq 'WAITING_FOR_GRADE')) {
            $result = &Apache::structuretags::access_status_msg('tool',$status,$symb,
                                                                $target,$ipused,$accessmsg);
        } elsif ($status eq 'NEEDS_CHECKIN') {
            $result = &Apache::structuretags::checkin_prompt($target,$slot_name,$slot,'tool');
        } elsif ($target eq 'web') {
            if ($status eq 'CAN_ANSWER') {
                $resource_due = &Apache::lonhomework::due_date(0, $env{'request.symb'});
                if ($slot_name ne '') {
                    $resource_due = &Apache::structuretags::selfcheckin_resource($resource_due,
                                                                                 $slot_name,$slot,
                                                                                 $env{'request.symb'});
                }
            }
        }
        if (keys(%Apache::lonhomework::results)) {
            &Apache::structuretags::finalize_storage();
        }
    }
    return ($status,$result,$resource_due);
}

sub display_score {
    my ($target) = @_;
    my $weight = &Apache::lonnet::EXT('resource.0.weight');
    if ((!defined($weight)) || ($weight eq '')) { $weight=1; }
    my $awarded = $Apache::lonhomework::history{'resource.0.awarded'};
    if (!defined($awarded)) { $awarded=0; }
    my $display='';
    if ($target eq 'tex') {
        $display = '\\\\';
    }
    if (!defined($awarded)) {
        $display .= &mt('[_1] possible points.',$weight);
    } else {
        my $points = $awarded*$weight;
        my $result = sprintf('%.2f',$points);
        $display .= &mt('You have [_1] out of [quant,_2,possible point]',
                       $result,$weight);
    }
    my $comment = $Apache::lonhomework::history{'resource.0.comment'};
    if (!defined($comment) || $comment!~/\w/) {
        $comment='';
    } else {
        if ($target eq 'tex') {
            $comment = '\\\\'.$comment;
        } else {
            $comment='<br /><table><tr><td bgcolor="#FFFFDD">'.$comment.'</td></tr></table>';
        }
    }
    my $gradeinfo = $Apache::lonhomework::history{'resource.0.gradeinfo'};
    if (!defined($gradeinfo) || $gradeinfo!~/\w/) {
        $gradeinfo='';
    } else {
        if ($target eq 'tex') {
            $gradeinfo = '\\\\'.$gradeinfo;
        } else {
            $gradeinfo='<br /><table><tr><td bgcolor="#DDDDFF"><font size="+2">'.$gradeinfo.'</font></td></tr></table>';
        }
    }
    return $display.$comment.$gradeinfo;
}

1;

FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>