--- loncom/lond 2020/01/13 03:46:32 1.489.2.34
+++ loncom/lond 2016/07/25 19:49:45 1.523
@@ -2,7 +2,7 @@
# The LearningOnline Network
# lond "LON Daemon" Server (port "LOND" 5663)
#
-# $Id: lond,v 1.489.2.34 2020/01/13 03:46:32 raeburn Exp $
+# $Id: lond,v 1.523 2016/07/25 19:49:45 raeburn Exp $
#
# Copyright Michigan State University Board of Trustees
#
@@ -15,6 +15,7 @@
#
# LON-CAPA is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
+
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
@@ -40,7 +41,7 @@ use IO::File;
#use Apache::File;
use POSIX;
use Crypt::IDEA;
-use LWP::UserAgent();
+use HTTP::Request;
use Digest::MD5 qw(md5_hex);
use GDBM_File;
use Authen::Krb5;
@@ -57,13 +58,14 @@ use Mail::Send;
use Crypt::Eksblowfish::Bcrypt;
use Digest::SHA;
use Encode;
+use LONCAPA::LWPReq;
my $DEBUG = 0; # Non zero to enable debug log entries.
my $status='';
my $lastlog='';
-my $VERSION='$Revision: 1.489.2.34 $'; #' stupid emacs
+my $VERSION='$Revision: 1.523 $'; #' stupid emacs
my $remoteVERSION;
my $currenthostid="default";
my $currentdomainid;
@@ -666,10 +668,8 @@ sub PushFile {
$clientprotocol = 'http' if ($clientprotocol ne 'https');
my $url = '/adm/'.$filename;
$url =~ s{_}{/};
- my $ua=new LWP::UserAgent;
- $ua->timeout(60);
my $request=new HTTP::Request('GET',"$clientprotocol://$clienthost$url");
- my $response=$ua->request($request);
+ my $response = LONCAPA::LWPReq::makerequest($clientname,$request,'',\%perlvar,60,0);
if ($response->is_error()) {
&logthis(' Pushfile: unable to install '
.$tablefile." - error attempting to pull data. ");
@@ -1424,22 +1424,6 @@ sub du2_handler {
# selected directory the filename followed by the full output of
# the stat function is returned. The returned info for each
# file are separated by ':'. The stat fields are separated by &'s.
-#
-# If the requested path contains /../ or is:
-#
-# 1. for a directory, and the path does not begin with one of:
-# (a) /home/httpd/html/res/
-# (b) /home/httpd/html/userfiles/
-# (c) /home/httpd/lonUsers//<1>/<2>/<3>//userfiles
-# or is:
-#
-# 2. for a file, and the path (after prepending) does not begin with one of:
-# (a) /home/httpd/lonUsers//<1>/<2>/<3>//
-# (b) /home/httpd/html/res///
-# (c) /home/httpd/html/userfiles///
-#
-# the response will be "refused".
-#
# Parameters:
# $cmd - The command that dispatched us (ls).
# $ulsdir - The directory path to list... I'm not sure what this
@@ -1461,17 +1445,8 @@ sub ls_handler {
my $rights;
my $ulsout='';
my $ulsfn;
- if ($ulsdir =~m{/\.\./}) {
- &Failure($client,"refused\n",$userinput);
- return 1;
- }
if (-e $ulsdir) {
if(-d $ulsdir) {
- unless (($ulsdir =~ m{^/home/httpd/html/(res/$LONCAPA::match_domain|userfiles/)}) ||
- ($ulsdir =~ m{^/home/httpd/lonUsers/$LONCAPA::match_domain(?:/[\w\-.@]){3}/$LONCAPA::match_name/userfiles})) {
- &Failure($client,"refused\n",$userinput);
- return 1;
- }
if (opendir(LSDIR,$ulsdir)) {
while ($ulsfn=readdir(LSDIR)) {
undef($obs);
@@ -1495,11 +1470,6 @@ sub ls_handler {
closedir(LSDIR);
}
} else {
- unless (($ulsdir =~ m{^/home/httpd/lonUsers/$LONCAPA::match_domain(?:/[\w\-.@]){3}/$LONCAPA::match_name/}) ||
- ($ulsdir =~ m{^/home/httpd/html/(?:res|userfiles)/$LONCAPA::match_domain/$LONCAPA::match_name/})) {
- &Failure($client,"refused\n",$userinput);
- return 1;
- }
my @ulsstats=stat($ulsdir);
$ulsout.=$ulsfn.'&'.join('&',@ulsstats).':';
}
@@ -1524,22 +1494,6 @@ sub ls_handler {
# selected directory the filename followed by the full output of
# the stat function is returned. The returned info for each
# file are separated by ':'. The stat fields are separated by &'s.
-#
-# If the requested path contains /../ or is:
-#
-# 1. for a directory, and the path does not begin with one of:
-# (a) /home/httpd/html/res/
-# (b) /home/httpd/html/userfiles/
-# (c) /home/httpd/lonUsers//<1>/<2>/<3>//userfiles
-# or is:
-#
-# 2. for a file, and the path (after prepending) does not begin with one of:
-# (a) /home/httpd/lonUsers//<1>/<2>/<3>//
-# (b) /home/httpd/html/res///
-# (c) /home/httpd/html/userfiles///
-#
-# the response will be "refused".
-#
# Parameters:
# $cmd - The command that dispatched us (ls).
# $ulsdir - The directory path to list... I'm not sure what this
@@ -1560,17 +1514,8 @@ sub ls2_handler {
my $rights;
my $ulsout='';
my $ulsfn;
- if ($ulsdir =~m{/\.\./}) {
- &Failure($client,"refused\n",$userinput);
- return 1;
- }
if (-e $ulsdir) {
if(-d $ulsdir) {
- unless (($ulsdir =~ m{^/home/httpd/html/(res/$LONCAPA::match_domain|userfiles/)}) ||
- ($ulsdir =~ m{^/home/httpd/lonUsers/$LONCAPA::match_domain(?:/[\w\-.@]){3}/$LONCAPA::match_name/userfiles})) {
- &Failure($client,"refused\n","$userinput");
- return 1;
- }
if (opendir(LSDIR,$ulsdir)) {
while ($ulsfn=readdir(LSDIR)) {
undef($obs);
@@ -1595,11 +1540,6 @@ sub ls2_handler {
closedir(LSDIR);
}
} else {
- unless (($ulsdir =~ m{^/home/httpd/lonUsers/$LONCAPA::match_domain(?:/[\w\-.@]){3}/$LONCAPA::match_name/}) ||
- ($ulsdir =~ m{^/home/httpd/html/(?:res|userfiles)/$LONCAPA::match_domain/$LONCAPA::match_name/})) {
- &Failure($client,"refused\n",$userinput);
- return 1;
- }
my @ulsstats=stat($ulsdir);
$ulsout.=$ulsfn.'&'.join('&',@ulsstats).':';
}
@@ -1616,25 +1556,6 @@ sub ls2_handler {
# selected directory the filename followed by the full output of
# the stat function is returned. The returned info for each
# file are separated by ':'. The stat fields are separated by &'s.
-#
-# If the requested path (after prepending) contains /../ or is:
-#
-# 1. for a directory, and the path does not begin with one of:
-# (a) /home/httpd/html/res/
-# (b) /home/httpd/html/userfiles/
-# (c) /home/httpd/lonUsers//<1>/<2>/<3>//userfiles
-# (d) /home/httpd/html/priv/ and client is the homeserver
-#
-# or is:
-#
-# 2. for a file, and the path (after prepending) does not begin with one of:
-# (a) /home/httpd/lonUsers//<1>/<2>/<3>//
-# (b) /home/httpd/html/res///
-# (c) /home/httpd/html/userfiles///
-# (d) /home/httpd/html/priv/// and client is the homeserver
-#
-# the response will be "refused".
-#
# Parameters:
# $cmd - The command that dispatched us (ls).
# $tail - The tail of the request that invoked us.
@@ -1674,12 +1595,22 @@ sub ls3_handler {
}
my $dir_root = $perlvar{'lonDocRoot'};
- if (($getpropath) || ($getuserdir)) {
+ if ($getpropath) {
if (($uname =~ /^$LONCAPA::match_name$/) && ($udom =~ /^$LONCAPA::match_domain$/)) {
$dir_root = &propath($udom,$uname);
$dir_root =~ s/\/$//;
} else {
- &Failure($client,"refused\n",$userinput);
+ &Failure($client,"refused\n","$cmd:$tail");
+ return 1;
+ }
+ } elsif ($getuserdir) {
+ if (($uname =~ /^$LONCAPA::match_name$/) && ($udom =~ /^$LONCAPA::match_domain$/)) {
+ my $subdir=$uname.'__';
+ $subdir =~ s/(.)(.)(.).*/$1\/$2\/$3/;
+ $dir_root = $Apache::lonnet::perlvar{'lonUsersDir'}
+ ."/$udom/$subdir/$uname";
+ } else {
+ &Failure($client,"refused\n","$cmd:$tail");
return 1;
}
} elsif ($alternate_root ne '') {
@@ -1692,28 +1623,12 @@ sub ls3_handler {
$ulsdir = $dir_root.'/'.$ulsdir;
}
}
- if ($ulsdir =~m{/\.\./}) {
- &Failure($client,"refused\n",$userinput);
- return 1;
- }
- my $islocal;
- my @machine_ids = &Apache::lonnet::current_machine_ids();
- if (grep(/^\Q$clientname\E$/,@machine_ids)) {
- $islocal = 1;
- }
my $obs;
my $rights;
my $ulsout='';
my $ulsfn;
if (-e $ulsdir) {
if(-d $ulsdir) {
- unless (($getpropath) || ($getuserdir) ||
- ($ulsdir =~ m{^/home/httpd/html/(res/$LONCAPA::match_domain|userfiles/)}) ||
- ($ulsdir =~ m{^/home/httpd/lonUsers/$LONCAPA::match_domain(?:/[\w\-.@]){3}/$LONCAPA::match_name/userfiles}) ||
- (($ulsdir =~ m{^/home/httpd/html/priv/$LONCAPA::match_domain}) && ($islocal))) {
- &Failure($client,"refused\n",$userinput);
- return 1;
- }
if (opendir(LSDIR,$ulsdir)) {
while ($ulsfn=readdir(LSDIR)) {
undef($obs);
@@ -1738,13 +1653,6 @@ sub ls3_handler {
closedir(LSDIR);
}
} else {
- unless (($getpropath) || ($getuserdir) ||
- ($ulsdir =~ m{^/home/httpd/lonUsers/$LONCAPA::match_domain(?:/[\w\-.@]){3}/$LONCAPA::match_name/}) ||
- ($ulsdir =~ m{^/home/httpd/html/(?:res|userfiles)/$LONCAPA::match_domain/$LONCAPA::match_name/}) ||
- (($ulsdir =~ m{^/home/httpd/html/priv/$LONCAPA::match_domain/$LONCAPA::match_name/}) && ($islocal))) {
- &Failure($client,"refused\n",$userinput);
- return 1;
- }
my @ulsstats=stat($ulsdir);
$ulsout.=$ulsfn.'&'.join('&',@ulsstats).':';
}
@@ -1795,7 +1703,7 @@ sub read_lonnet_global {
}
if ($what eq 'perlvar') {
if (!exists($packagevars{$what}{'lonBalancer'})) {
- if ($dist =~ /^(centos|rhes|fedora|scientific|oracle)/) {
+ if ($dist =~ /^(centos|rhes|fedora|scientific)/) {
my $othervarref=LONCAPA::Configuration::read_conf('httpd.conf');
if (ref($othervarref) eq 'HASH') {
$items->{'lonBalancer'} = $othervarref->{'lonBalancer'};
@@ -1888,6 +1796,16 @@ sub server_distarch_handler {
}
®ister_handler("serverdistarch", \&server_distarch_handler, 0, 1, 0);
+sub server_certs_handler {
+ my ($cmd,$tail,$client) = @_;
+ my $userinput = "$cmd:$tail";
+ my $result;
+ my $result = &LONCAPA::Lond::server_certs(\%perlvar);
+ &Reply($client,\$result,$userinput);
+ return;
+}
+®ister_handler("servercerts", \&server_certs_handler, 0, 1, 0);
+
# Process a reinit request. Reinit requests that either
# lonc or lond be reinitialized so that an updated
# host.tab or domain.tab can be processed.
@@ -2020,18 +1938,14 @@ sub authenticate_handler {
my ($remote,$hosted);
my $remotesession = &get_usersession_config($udom,'remotesession');
if (ref($remotesession) eq 'HASH') {
- $remote = $remotesession->{'remote'};
+ $remote = $remotesession->{'remote'}
}
my $hostedsession = &get_usersession_config($clienthomedom,'hostedsession');
if (ref($hostedsession) eq 'HASH') {
$hosted = $hostedsession->{'hosted'};
}
- my $loncaparev = $clientversion;
- if ($loncaparev eq '') {
- $loncaparev = $Apache::lonnet::loncaparevs{$clientname};
- }
$canhost = &Apache::lonnet::can_host_session($udom,$clientname,
- $loncaparev,
+ $clientversion,
$remote,$hosted);
}
}
@@ -2107,84 +2021,12 @@ sub change_password_handler {
}
if($validated) {
my $realpasswd = &get_auth_type($udom, $uname); # Defined since authd.
+
my ($howpwd,$contentpwd)=split(/:/,$realpasswd);
- my $notunique;
if ($howpwd eq 'internal') {
&Debug("internal auth");
my $ncpass = &hash_passwd($udom,$npass);
- my (undef,$method,@rest) = split(/!/,$contentpwd);
- if ($method eq 'bcrypt') {
- my %passwdconf = &Apache::lonnet::get_passwdconf($udom);
- if (($passwdconf{'numsaved'}) && ($passwdconf{'numsaved'} =~ /^\d+$/)) {
- my @oldpasswds;
- my $userpath = &propath($udom,$uname);
- my $fullpath = $userpath.'/oldpasswds';
- if (-d $userpath) {
- my @oldfiles;
- if (-e $fullpath) {
- if (opendir(my $dir,$fullpath)) {
- (@oldfiles) = grep(/^\d+$/,readdir($dir));
- closedir($dir);
- }
- if (@oldfiles) {
- @oldfiles = sort { $b <=> $a } (@oldfiles);
- my $numremoved = 0;
- for (my $i=0; $i<@oldfiles; $i++) {
- if ($i>=$passwdconf{'numsaved'}) {
- if (-f "$fullpath/$oldfiles[$i]") {
- if (unlink("$fullpath/$oldfiles[$i]")) {
- $numremoved ++;
- }
- }
- } elsif (open(my $fh,'<',"$fullpath/$oldfiles[$i]")) {
- while (my $line = <$fh>) {
- push(@oldpasswds,$line);
- }
- close($fh);
- }
- }
- if ($numremoved) {
- &logthis("unlinked $numremoved old password files for $uname:$udom");
- }
- }
- }
- push(@oldpasswds,$contentpwd);
- foreach my $item (@oldpasswds) {
- my (undef,$method,@rest) = split(/!/,$item);
- if ($method eq 'bcrypt') {
- my $result = &hash_passwd($udom,$npass,@rest);
- if ($result eq $item) {
- $notunique = 1;
- last;
- }
- }
- }
- unless ($notunique) {
- unless (-e $fullpath) {
- if (&mkpath("$fullpath/")) {
- chmod(0700,$fullpath);
- }
- }
- if (-d $fullpath) {
- my $now = time;
- if (open(my $fh,'>',"$fullpath/$now")) {
- print $fh $contentpwd;
- close($fh);
- chmod(0400,"$fullpath/$now");
- }
- }
- }
- }
- }
- }
- if ($notunique) {
- my $msg="Result of password change for $uname:$udom - password matches one used before";
- if ($lonhost) {
- $msg .= " - request originated from: $lonhost";
- }
- &logthis($msg);
- &Reply($client, "prioruse\n", $userinput);
- } elsif (&rewrite_password_file($udom, $uname, "internal:$ncpass")) {
+ if(&rewrite_password_file($udom, $uname, "internal:$ncpass")) {
my $msg="Result of password change for $uname: pwchange_success";
if ($lonhost) {
$msg .= " - request originated from: $lonhost";
@@ -2201,7 +2043,7 @@ sub change_password_handler {
my $result = &change_unix_password($uname, $npass);
if ($result eq 'ok') {
&update_passwd_history($uname,$udom,$howpwd,$context);
- }
+ }
&logthis("Result of password change for $uname: ".
$result);
&Reply($client, \$result, $userinput);
@@ -2212,6 +2054,7 @@ sub change_password_handler {
#
&Failure( $client, "auth_mode_error\n", $userinput);
}
+
} else {
if ($failure eq '') {
$failure = 'non_authorized';
@@ -2232,8 +2075,12 @@ sub hash_passwd {
my $plainsalt = substr($rest[1],0,22);
$salt = Crypt::Eksblowfish::Bcrypt::de_base64($plainsalt);
} else {
- my %domdefaults = &Apache::lonnet::get_domain_defaults($domain);
- my $defaultcost = $domdefaults{'intauth_cost'};
+ my $defaultcost;
+ my %domconfig =
+ &Apache::lonnet::get_dom('configuration',['password'],$domain);
+ if (ref($domconfig{'password'}) eq 'HASH') {
+ $defaultcost = $domconfig{'password'}{'cost'};
+ }
if (($defaultcost eq '') || ($defaultcost =~ /D/)) {
$cost = 10;
} else {
@@ -2368,7 +2215,7 @@ sub change_authentication_handler {
my $result = &change_unix_password($uname, $npass);
&logthis("Result of password change for $uname: ".$result);
if ($result eq "ok") {
- &update_passwd_history($uname,$udom,$umode,'changeuserauth');
+ &update_passwd_history($uname,$udom,$umode,'changeuserauth');
&Reply($client, \$result);
} else {
&Failure($client, \$result);
@@ -2493,18 +2340,13 @@ sub update_resource_handler {
# FIXME: this should use the LWP mechanism, not internal alarms.
alarm(1200);
{
- my $ua=new LWP::UserAgent;
my $request=new HTTP::Request('GET',"$remoteurl");
- $response=$ua->request($request,$transname);
+ $response=&LONCAPA::LWPReq::makerequest($clientname,$request,$transname,\%perlvar,1200,0,1);
}
alarm(0);
if ($response->is_error()) {
- my $reply=&Apache::lonnet::reply("unsub:$fname","$clientname");
- &devalidate_meta_cache($fname);
- if (-e $transname) {
- unlink($transname);
- }
- unlink($fname);
+# FIXME: we should probably clean up here instead of just whine
+ unlink($transname);
my $message=$response->status_line;
&logthis("LWP GET: $message for $fname ($remoteurl)");
} else {
@@ -2512,9 +2354,8 @@ sub update_resource_handler {
# FIXME: isn't there an internal LWP mechanism for this?
alarm(120);
{
- my $ua=new LWP::UserAgent;
my $mrequest=new HTTP::Request('GET',$remoteurl.'.meta');
- my $mresponse=$ua->request($mrequest,$fname.'.meta');
+ my $mresponse = &LONCAPA::LWPReq::makerequest($clientname,$mrequest,$fname.'.meta',\%perlvar,120,0,1);
if ($mresponse->is_error()) {
unlink($fname.'.meta');
}
@@ -2589,11 +2430,15 @@ sub fetch_user_file_handler {
my $remoteurl=$clientprotocol.'://'.$clienthost.'/userfiles/'.$fname;
my $response;
Debug("Remote URL : $remoteurl Transfername $transname Destname: $destname");
- alarm(120);
+ alarm(1200);
{
- my $ua=new LWP::UserAgent;
my $request=new HTTP::Request('GET',"$remoteurl");
- $response=$ua->request($request,$transname);
+ my $verifycert = 1;
+ my @machine_ids = &Apache::lonnet::current_machine_ids();
+ if (grep(/^\Q$clientname\E$/,@machine_ids)) {
+ $verifycert = 0;
+ }
+ $response = &LONCAPA::LWPReq::makerequest($clientname,$request,$transname,\%perlvar,1200,$verifycert);
}
alarm(0);
if ($response->is_error()) {
@@ -2662,13 +2507,13 @@ sub remove_user_file_handler {
if (-e $file) {
#
# If the file is a regular file unlink is fine...
- # However it's possible the client wants a dir
- # removed, in which case rmdir is more appropriate
- # Note: rmdir will only remove an empty directory.
+ # However it's possible the client wants a dir
+ # removed, in which case rmdir is more appropriate.
+ # Note: rmdir will only remove an empty directory.
#
if (-f $file){
unlink($file);
- # for html files remove the associated .bak file
+ # for html files remove the associated .bak file
# which may have been created by the editor.
if ($ufile =~ m{^((docs|supplemental)/(?:\d+|default)/\d+(?:|/.+)/)[^/]+\.x?html?$}i) {
my $path = $1;
@@ -3042,8 +2887,8 @@ sub newput_user_profile_entry {
&logthis("error: ".($!+0)." untie (GDBM) failed ".
"while attempting newput - early out as key exists");
}
- &Failure($client, "key_exists: ".$key."\n",$userinput);
- return 1;
+ &Failure($client, "key_exists: ".$key."\n",$userinput);
+ return 1;
}
}
@@ -3293,8 +3138,7 @@ sub get_profile_entry {
#
# Parameters:
# $cmd - Command keyword of request (eget).
-# $tail - Tail of the command. See GetProfileEntry
-# for more information about this.
+# $tail - Tail of the command. See GetProfileEntry
# for more information about this.
# $client - File open on the client.
# Returns:
# 1 - Continue processing
@@ -3446,6 +3290,17 @@ sub get_profile_keys {
sub dump_profile_database {
my ($cmd, $tail, $client) = @_;
+ my $res = LONCAPA::Lond::dump_profile_database($tail);
+
+ if ($res =~ /^error:/) {
+ Failure($client, \$res, "$cmd:$tail");
+ } else {
+ Reply($client, \$res, "$cmd:$tail");
+ }
+
+ return 1;
+
+ #TODO remove
my $userinput = "$cmd:$tail";
my ($udom,$uname,$namespace) = split(/:/,$tail);
@@ -3525,11 +3380,11 @@ sub dump_with_regexp {
my ($cmd, $tail, $client) = @_;
my $res = LONCAPA::Lond::dump_with_regexp($tail, $clientversion);
-
+
if ($res =~ /^error:/) {
- &Failure($client, \$res, "$cmd:$tail");
+ Failure($client, \$res, "$cmd:$tail");
} else {
- &Reply($client, \$res, "$cmd:$tail");
+ Reply($client, \$res, "$cmd:$tail");
}
return 1;
@@ -3567,7 +3422,6 @@ sub store_handler {
my ($cmd, $tail, $client) = @_;
my $userinput = "$cmd:$tail";
-
chomp($tail);
my ($udom,$uname,$namespace,$rid,$what,$laststore) =split(/:/,$tail);
if ($namespace ne 'roles') {
@@ -3597,7 +3451,6 @@ sub store_handler {
$numtrans =~ s/D//g;
}
}
-
$hashref->{"version:$rid"}++;
my $version=$hashref->{"version:$rid"};
my $allkeys='';
@@ -3614,7 +3467,7 @@ sub store_handler {
if ($numtrans) {
$msg = 'delay:'.$numtrans;
}
- &Reply($client, "$msg\n", $userinput);
+ &Reply($client, "$msg\n", $userinput);
} else {
&Failure($client, "error: ".($!+0)." untie(GDBM) Failed ".
"while attempting store\n", $userinput);
@@ -3876,37 +3729,6 @@ sub send_query_handler {
my ($query,$arg1,$arg2,$arg3)=split(/\:/,$tail);
$query=~s/\n*$//g;
- if (($query eq 'usersearch') || ($query eq 'instdirsearch')) {
- my $usersearchconf = &get_usersearch_config($currentdomainid,'directorysrch');
- my $earlyout;
- if (ref($usersearchconf) eq 'HASH') {
- if ($currentdomainid eq $clienthomedom) {
- if ($query eq 'usersearch') {
- if ($usersearchconf->{'lcavailable'} eq '0') {
- $earlyout = 1;
- }
- } else {
- if ($usersearchconf->{'available'} eq '0') {
- $earlyout = 1;
- }
- }
- } else {
- if ($query eq 'usersearch') {
- if ($usersearchconf->{'lclocalonly'}) {
- $earlyout = 1;
- }
- } else {
- if ($usersearchconf->{'localonly'}) {
- $earlyout = 1;
- }
- }
- }
- }
- if ($earlyout) {
- &Reply($client, "query_not_authorized\n");
- return 1;
- }
- }
&Reply($client, "". &sql_reply("$clientname\&$query".
"\&$arg1"."\&$arg2"."\&$arg3")."\n",
$userinput);
@@ -4162,7 +3984,7 @@ sub put_course_id_hash_handler {
#
# domcloner - flag to indicate if user can create CCs in course's domain.
# If so, ability to clone course is automatic.
-# hasuniquecode - filter by courses for which a six character unique code has
+# hasuniquecode - filter by courses for which a six character unique code has
# been set.
#
# $client - The socket open on the client.
@@ -4172,6 +3994,17 @@ sub put_course_id_hash_handler {
# a reply is written to $client.
sub dump_course_id_handler {
my ($cmd, $tail, $client) = @_;
+
+ my $res = LONCAPA::Lond::dump_course_id_handler($tail);
+ if ($res =~ /^error:/) {
+ Failure($client, \$res, "$cmd:$tail");
+ } else {
+ Reply($client, \$res, "$cmd:$tail");
+ }
+
+ return 1;
+
+ #TODO remove
my $userinput = "$cmd:$tail";
my ($udom,$since,$description,$instcodefilter,$ownerfilter,$coursefilter,
@@ -4619,6 +4452,122 @@ sub put_domain_handler {
}
®ister_handler("putdom", \&put_domain_handler, 0, 1, 0);
+# Updates one or more entries in clickers.db file at the domain level
+#
+# Parameters:
+# $cmd - The command that got us here.
+# $tail - Tail of the command (remaining parameters).
+# In this case a colon separated list containing:
+# (a) the domain for which we are updating the entries,
+# (b) the action required -- add or del -- and
+# (c) a &-separated list of entries to add or delete.
+# $client - File descriptor connected to client.
+# Returns
+# 1 - Continue processing.
+# 0 - Requested to exit, caller should shut down.
+# Side effects:
+# reply is written to $client.
+#
+
+
+sub update_clickers {
+ my ($cmd, $tail, $client) = @_;
+
+ my $userinput = "$cmd:$tail";
+ my ($udom,$action,$what) =split(/:/,$tail,3);
+ chomp($what);
+
+ my $hashref = &tie_domain_hash($udom, "clickers", &GDBM_WRCREAT(),
+ "U","$action:$what");
+
+ if (!$hashref) {
+ &Failure( $client, "error: ".($!+0)." tie(GDBM) Failed ".
+ "while attempting updateclickers\n", $userinput);
+ return 1;
+ }
+
+ my @pairs=split(/\&/,$what);
+ foreach my $pair (@pairs) {
+ my ($key,$value)=split(/=/,$pair);
+ if ($action eq 'add') {
+ if (exists($hashref->{$key})) {
+ my @newvals = split(/,/,&unescape($value));
+ my @currvals = split(/,/,&unescape($hashref->{$key}));
+ my @merged = sort(keys(%{{map { $_ => 1 } (@newvals,@currvals)}}));
+ $hashref->{$key}=&escape(join(',',@merged));
+ } else {
+ $hashref->{$key}=$value;
+ }
+ } elsif ($action eq 'del') {
+ if (exists($hashref->{$key})) {
+ my %current;
+ map { $current{$_} = 1; } split(/,/,&unescape($hashref->{$key}));
+ map { delete($current{$_}); } split(/,/,&unescape($value));
+ if (keys(%current)) {
+ $hashref->{$key}=&escape(join(',',sort(keys(%current))));
+ } else {
+ delete($hashref->{$key});
+ }
+ }
+ }
+ }
+ if (&untie_user_hash($hashref)) {
+ &Reply( $client, "ok\n", $userinput);
+ } else {
+ &Failure($client, "error: ".($!+0)." untie(GDBM) failed ".
+ "while attempting put\n",
+ $userinput);
+ }
+ return 1;
+}
+®ister_handler("updateclickers", \&update_clickers, 0, 1, 0);
+
+
+# Deletes one or more entries in a namespace db file at the domain level
+#
+# Parameters:
+# $cmd - The command that got us here.
+# $tail - Tail of the command (remaining parameters).
+# In this case a colon separated list containing:
+# (a) the domain for which we are deleting the entries,
+# (b) &-separated list of keys to delete.
+# $client - File descriptor connected to client.
+# Returns
+# 1 - Continue processing.
+# 0 - Requested to exit, caller should shut down.
+# Side effects:
+# reply is written to $client.
+#
+
+sub del_domain_handler {
+ my ($cmd,$tail,$client) = @_;
+
+ my $userinput = "$cmd:$tail";
+
+ my ($udom,$namespace,$what)=split(/:/,$tail,3);
+ chomp($what);
+ my $hashref = &tie_domain_hash($udom,$namespace,&GDBM_WRCREAT(),
+ "D", $what);
+ if ($hashref) {
+ my @keys=split(/\&/,$what);
+ foreach my $key (@keys) {
+ delete($hashref->{$key});
+ }
+ if (&untie_user_hash($hashref)) {
+ &Reply($client, "ok\n", $userinput);
+ } else {
+ &Failure($client, "error: ".($!+0)." untie(GDBM) Failed ".
+ "while attempting deldom\n", $userinput);
+ }
+ } else {
+ &Failure( $client, "error: ".($!+0)." tie(GDBM) Failed ".
+ "while attempting deldom\n", $userinput);
+ }
+ return 1;
+}
+®ister_handler("deldom", \&del_domain_handler, 0, 1, 0);
+
+
# Unencrypted get from the namespace database file at the domain level.
# This function retrieves a keyed item from a specific named database in the
# domain directory.
@@ -4642,7 +4591,7 @@ sub get_domain_handler {
my ($cmd, $tail, $client) = @_;
- my $userinput = "$cmd:$tail";
+ my $userinput = "$client:$tail";
my ($udom,$namespace,$what)=split(/:/,$tail,3);
chomp($what);
@@ -4778,7 +4727,7 @@ sub get_id_handler {
# Returns:
# 1 - Continue processing
# 0 - Exit server.
-#
+#
#
sub del_id_handler {
@@ -5185,58 +5134,6 @@ sub tmp_del_handler {
®ister_handler("tmpdel", \&tmp_del_handler, 0, 1, 0);
#
-# Process the delbalcookie command. This command deletes a balancer
-# cookie in the lonBalancedir directory created by switchserver
-#
-# Parameters:
-# $cmd - Command that got us here.
-# $cookie - Cookie to be deleted.
-# $client - socket open on the client process.
-#
-# Returns:
-# 1 - Indicating processing should continue.
-# Side Effects:
-# A cookie file is deleted from the lonBalancedir directory
-# A reply is sent to the client.
-sub del_balcookie_handler {
- my ($cmd, $cookie, $client) = @_;
-
- my $userinput= "$cmd:$cookie";
-
- chomp($cookie);
- my $deleted = '';
- if ($cookie =~ /^$LONCAPA::match_domain\_$LONCAPA::match_username\_[a-f0-9]{32}$/) {
- my $execdir=$perlvar{'lonBalanceDir'};
- if (-e "$execdir/$cookie.id") {
- if (open(my $fh,'<',"$execdir/$cookie.id")) {
- my $dodelete;
- while (my $line = <$fh>) {
- chomp($line);
- if ($line eq $clientname) {
- $dodelete = 1;
- last;
- }
- }
- close($fh);
- if ($dodelete) {
- if (unlink("$execdir/$cookie.id")) {
- $deleted = 1;
- }
- }
- }
- }
- }
- if ($deleted) {
- &Reply($client, "ok\n", $userinput);
- } else {
- &Failure( $client, "error: ".($!+0)."Unlinking cookie file Failed ".
- "while attempting delbalcookie\n", $userinput);
- }
- return 1;
-}
-®ister_handler("delbalcookie", \&del_balcookie_handler, 0, 1, 0);
-
-#
# Processes the setannounce command. This command
# creates a file named announce.txt in the top directory of
# the documentn root and sets its contents. The announce.txt file is
@@ -5515,10 +5412,9 @@ sub validate_course_section_handler {
# Formal Parameters:
# $cmd - The command request that got us dispatched.
# $tail - The tail of the command. In this case this is a colon separated
-# set of values that will be split into:
+# set of words that will be split into:
# $inst_class - Institutional code for the specific class section
-# $ownerlist - An escaped comma-separated list of username:domain
-# of the course owner, and co-owner(s).
+# $courseowner - The escaped username:domain of the course owner
# $cdom - The domain of the course from the institution's
# point of view.
# $client - The socket open on the client.
@@ -5543,56 +5439,6 @@ sub validate_class_access_handler {
®ister_handler("autovalidateclass_sec", \&validate_class_access_handler, 0, 1, 0);
#
-# Validate course owner or co-owners(s) access to enrollment data for all sections
-# and crosslistings for a particular course.
-#
-#
-# Formal Parameters:
-# $cmd - The command request that got us dispatched.
-# $tail - The tail of the command. In this case this is a colon separated
-# set of values that will be split into:
-# $ownerlist - An escaped comma-separated list of username:domain
-# of the course owner, and co-owner(s).
-# $cdom - The domain of the course from the institution's
-# point of view.
-# $classes - Frozen hash of institutional course sections and
-# crosslistings.
-# $client - The socket open on the client.
-# Returns:
-# 1 - continue processing.
-#
-
-sub validate_classes_handler {
- my ($cmd, $tail, $client) = @_;
- my $userinput = "$cmd:$tail";
- my ($ownerlist,$cdom,$classes) = split(/:/, $tail);
- my $classesref = &Apache::lonnet::thaw_unescape($classes);
- my $owners = &unescape($ownerlist);
- my $result;
- eval {
- local($SIG{__DIE__})='DEFAULT';
- my %validations;
- my $response = &localenroll::check_instclasses($owners,$cdom,$classesref,
- \%validations);
- if ($response eq 'ok') {
- foreach my $key (keys(%validations)) {
- $result .= &escape($key).'='.&Apache::lonnet::freeze_escape($validations{$key}).'&';
- }
- $result =~ s/\&$//;
- } else {
- $result = 'error';
- }
- };
- if (!$@) {
- &Reply($client, \$result, $userinput);
- } else {
- &Failure($client,"unknown_cmd\n",$userinput);
- }
- return 1;
-}
-®ister_handler("autovalidateinstclasses", \&validate_classes_handler, 0, 1, 0);
-
-#
# Create a password for a new LON-CAPA user added by auto-enrollment.
# Only used for case where authentication method for new user is localauth
#
@@ -5672,14 +5518,13 @@ sub auto_export_grades_handler {
®ister_handler("autoexportgrades", \&auto_export_grades_handler,
0, 1, 0);
-
# Retrieve and remove temporary files created by/during autoenrollment.
#
# Formal Parameters:
# $cmd - The command that got us dispatched.
# $tail - The tail of the command. In our case this is a colon
# separated list that will be split into:
-# $filename - The name of the file to retrieve.
+# $filename - The name of the file to remove.
# The filename is given as a path relative to
# the LonCAPA temp file directory.
# $client - Socket open on the client.
@@ -5693,10 +5538,9 @@ sub retrieve_auto_file_handler {
my ($filename) = split(/:/, $tail);
my $source = $perlvar{'lonDaemons'}.'/tmp/'.$filename;
+
if ($filename =~m{/\.\./}) {
&Failure($client, "refused\n", $userinput);
- } elsif ($filename !~ /^$LONCAPA::match_domain\_$LONCAPA::match_courseid\_.+_classlist\.xml$/) {
- &Failure($client, "refused\n", $userinput);
} elsif ( (-e $source) && ($filename ne '') ) {
my $reply = '';
if (open(my $fh,$source)) {
@@ -5729,7 +5573,7 @@ sub crsreq_checks_handler {
my $userinput = "$cmd:$tail";
my $dom = $tail;
my $result;
- my @reqtypes = ('official','unofficial','community','textbook');
+ my @reqtypes = ('official','unofficial','community','textbook','placement');
eval {
local($SIG{__DIE__})='DEFAULT';
my %validations;
@@ -6570,8 +6414,8 @@ my $wwwid=getpwnam('www');
if ($wwwid!=$<) {
my $emailto="$perlvar{'lonAdmEMail'},$perlvar{'lonSysEMail'}";
my $subj="LON: $currenthostid User ID mismatch";
- system("echo 'User ID mismatch. lond must be run as user www.' |".
- " mail -s '$subj' $emailto > /dev/null");
+ system("echo 'User ID mismatch. lond must be run as user www.' |\
+ mailto $emailto -s '$subj' > /dev/null");
exit 1;
}
@@ -6774,6 +6618,9 @@ sub Debug {
# reply - Text to send to client.
# request - Original request from client.
#
+#NOTE $reply must be terminated by exactly *one* \n. If $reply is a reference
+#this is done automatically ($$reply must not contain any \n in this case).
+#If $reply is a string the caller has to ensure this.
sub Reply {
my ($fd, $reply, $request) = @_;
if (ref($reply)) {
@@ -7021,13 +6868,13 @@ sub make_new_child {
&Authen::Krb5::init_context();
my $no_ets;
- if ($dist =~ /^(?:centos|rhes|scientific|oracle)(\d+)$/) {
+ if ($dist =~ /^(?:centos|rhes|scientific)(\d+)$/) {
if ($1 >= 7) {
$no_ets = 1;
}
} elsif ($dist =~ /^suse(\d+\.\d+)$/) {
if (($1 eq '9.3') || ($1 >= 12.2)) {
- $no_ets = 1;
+ $no_ets = 1;
}
} elsif ($dist =~ /^sles(\d+)$/) {
if ($1 > 11) {
@@ -7039,8 +6886,8 @@ sub make_new_child {
}
}
unless ($no_ets) {
- &Authen::Krb5::init_ets();
- }
+ &Authen::Krb5::init_ets();
+ }
&status('Accepted connection');
# =============================================================================
@@ -7084,12 +6931,12 @@ sub make_new_child {
# If the remote is attempting a local init... give that a try:
#
(my $i, my $inittype, $clientversion) = split(/:/, $remotereq);
- # For LON-CAPA 2.9, the client session will have sent its LON-CAPA
- # version when initiating the connection. For LON-CAPA 2.8 and older,
- # the version is retrieved from the global %loncaparevs in lonnet.pm.
- # $clientversion contains path to keyfile if $inittype eq 'local'
- # it's overridden below in this case
- $clientversion ||= $Apache::lonnet::loncaparevs{$clientname};
+ # For LON-CAPA 2.9, the client session will have sent its LON-CAPA
+ # version when initiating the connection. For LON-CAPA 2.8 and older,
+ # the version is retrieved from the global %loncaparevs in lonnet.pm.
+ # $clientversion contains path to keyfile if $inittype eq 'local'
+ # it's overridden below in this case
+ $clientversion ||= $Apache::lonnet::loncaparevs{$clientname};
# If the connection type is ssl, but I didn't get my
# certificate files yet, then I'll drop back to
@@ -7154,6 +7001,7 @@ sub make_new_child {
."Attempted insecure connection disallowed ");
close $client;
$clientok = 0;
+
}
}
} else {
@@ -7162,6 +7010,7 @@ sub make_new_child {
."$clientip failed to initialize: >$remotereq< ");
&status('No init '.$clientip);
}
+
} else {
&logthis(
"WARNING: Unknown client $clientip");
@@ -7319,25 +7168,15 @@ sub password_filename {
# domain - domain of the user.
# name - User's name.
# contents - New contents of the file.
-# saveold - (optional). If true save old file in a passwd.bak file.
# Returns:
# 0 - Failed.
# 1 - Success.
#
sub rewrite_password_file {
- my ($domain, $user, $contents, $saveold) = @_;
+ my ($domain, $user, $contents) = @_;
my $file = &password_filename($domain, $user);
if (defined $file) {
- if ($saveold) {
- my $bakfile = $file.'.bak';
- if (CopyFile($file,$bakfile)) {
- chmod(0400,$bakfile);
- &logthis("Old password saved in passwd.bak for internally authenticated user: $user:$domain");
- } else {
- &logthis("Failed to save old password in passwd.bak for internally authenticated user: $user:$domain");
- }
- }
my $pf = IO::File->new(">$file");
if($pf) {
print $pf "$contents\n";
@@ -7428,27 +7267,20 @@ sub validate_user {
$contentpwd = $domdefaults{'auth_arg_def'};
}
}
- }
+ }
if ($howpwd ne 'nouser') {
if($howpwd eq "internal") { # Encrypted is in local password file.
if (length($contentpwd) == 13) {
$validated = (crypt($password,$contentpwd) eq $contentpwd);
if ($validated) {
- my %domdefaults = &Apache::lonnet::get_domain_defaults($domain);
- if ($domdefaults{'intauth_switch'}) {
- my $ncpass = &hash_passwd($domain,$password);
- my $saveold;
- if ($domdefaults{'intauth_switch'} == 2) {
- $saveold = 1;
- }
- if (&rewrite_password_file($domain,$user,"$howpwd:$ncpass",$saveold)) {
- &update_passwd_history($user,$domain,$howpwd,'conversion');
- &logthis("Validated password hashed with bcrypt for $user:$domain");
- }
+ my $ncpass = &hash_passwd($domain,$password);
+ if (&rewrite_password_file($domain,$user,"$howpwd:$ncpass")) {
+ &update_passwd_history($user,$domain,$howpwd,'conversion');
+ &logthis("Validated password hashed with bcrypt for $user:$domain");
}
}
} else {
- $validated = &check_internal_passwd($password,$contentpwd,$domain,$user);
+ $validated = &check_internal_passwd($password,$contentpwd,$domain);
}
}
elsif ($howpwd eq "unix") { # User is a normal unix user.
@@ -7518,35 +7350,24 @@ sub validate_user {
}
sub check_internal_passwd {
- my ($plainpass,$stored,$domain,$user) = @_;
+ my ($plainpass,$stored,$domain) = @_;
my (undef,$method,@rest) = split(/!/,$stored);
- if ($method eq 'bcrypt') {
+ if ($method eq "bcrypt") {
my $result = &hash_passwd($domain,$plainpass,@rest);
if ($result ne $stored) {
return 0;
}
- my %domdefaults = &Apache::lonnet::get_domain_defaults($domain);
- if ($domdefaults{'intauth_check'}) {
- # Upgrade to a larger number of rounds if necessary
- my $defaultcost = $domdefaults{'intauth_cost'};
- if (($defaultcost eq '') || ($defaultcost =~ /D/)) {
- $defaultcost = 10;
- }
- if (int($rest[0])new(">$passfilename");
if($pf) {
- print $pf "internal:$ncpass\n";
- &update_passwd_history($uname,$udom,$umode,$action);
+ print $pf "internal:$ncpass\n";
+ &update_passwd_history($uname,$udom,$umode,$action);
} else {
$result = "pass_file_failed_error";
}
@@ -7905,7 +7726,6 @@ sub make_passwd_file {
my $pf = IO::File->new(">$passfilename");
if($pf) {
print $pf "localauth:$npass\n";
- &update_passwd_history($uname,$udom,$umode,$action);
} else {
$result = "pass_file_failed_error";
}
@@ -7976,18 +7796,8 @@ sub get_usersession_config {
return;
}
-sub get_usersearch_config {
- my ($dom,$name) = @_;
- my ($usersearchconf,$cached)=&Apache::lonnet::is_cached_new($name,$dom);
- if (defined($cached)) {
- return $usersearchconf;
- } else {
- my %domconfig = &Apache::lonnet::get_dom('configuration',['directorysrch'],$dom);
- &Apache::lonnet::do_cache_new($name,$dom,$domconfig{'directorysrch'},3600);
- return $domconfig{'directorysrch'};
- }
- return;
-}
+
+
sub distro_and_arch {
return $dist.':'.$arch;
@@ -8172,7 +7982,7 @@ Allow for a password to be set.
Make a user.
-=item passwd
+=item changeuserauth
Allow for authentication mechanism and password to be changed.
@@ -8261,6 +8071,10 @@ for each student, defined perhaps by the
Returns usernames corresponding to IDs. (These "IDs" are unique identifiers
for each student, defined perhaps by the institutional Registrar.)
+=item iddel
+
+Deletes one or more ids in a domain's id database.
+
=item tmpput
Accept and store information in temporary space.
@@ -8317,6 +8131,8 @@ Authen::Krb5
=head1 COREQUISITES
+none
+
=head1 OSNAMES
linux
@@ -8404,9 +8220,9 @@ or the CA's certificate in the call to l
is the textual reason this failed. Usual reasons:
=over 2
-
+
=item Apache config file for loncapa incorrect:
-
+
one of the variables
lonCertificateDirectory, lonnetCertificateAuthority, or lonnetCertificate
undefined or incorrect
@@ -8525,7 +8341,7 @@ Could not rewrite the
internal password file for a user
=item Result of password change for :
-
+
A unix password change for was attempted
and the pipe returned
@@ -8554,7 +8370,7 @@ lond has been asked to exit by its clien
client systemand is the full exit command sent to the server.
=item Red CRITICAL: ABNORMAL EXIT. child for server died through a crass with this error->[].
-
+
A lond child terminated. NOte that this termination can also occur when the
child receives the QUIT or DIE signals. is the process id of the child,
the host lond is working for, and the reason the child died
@@ -8638,7 +8454,7 @@ file when sent it's USR1 signal. That p
assumed to be hung in some un-fixable way.
=item Finished checking children
-
+
Master processs's USR1 processing is cojmplete.
=item (Red) CRITICAL: ------- Starting ------
@@ -8652,7 +8468,7 @@ Started a new child process for
connected to the child. This was as a result of a TCP/IP connection from a client.
=item Unable to determine who caller was, getpeername returned nothing
-
+
In child process initialization. either getpeername returned undef or
a zero sized object was returned. Processing continues, but in my opinion,
this should be cause for the child to exit.
@@ -8663,7 +8479,7 @@ In child process initialization. The pe
The client address is stored as "Unavailable" and processing continues.
=item (Yellow) INFO: Connection connection type =
-
+
In child initialization. A good connectionw as received from .
=over 2
@@ -8713,7 +8529,7 @@ The client ( is the peer's name
negotiated an SSL connection with this child process.
=item (Green) Successful insecure authentication with
-
+
The client has successfully negotiated an insecure connection withthe child process.