Annotation of loncom/lonnet/perl/lonnet.pm, revision 1.70
1.1 albertel 1: # The LearningOnline Network
2: # TCP networking package
1.12 www 3: #
4: # Functions for use by content handlers:
5: #
6: # plaintext(short) : plain text explanation of short term
1.25 www 7: # fileembstyle(ext) : embed style in page for file extension
8: # filedescription(ext) : descriptor text for file extension
1.29 www 9: # allowed(short,url) : returns codes for allowed actions
10: # F: full access
11: # U,I,K: authentication modes (cxx only)
12: # '': forbidden
13: # 1: user needs to choose course
14: # 2: browse allowed
1.21 www 15: # definerole(rolename,sys,dom,cou) : define a custom role rolename
16: # set priviledges in format of lonTabs/roles.tab for
17: # system, domain and course level,
18: # assignrole(udom,uname,url,role,end,start) : give a role to a user for the
19: # level given by url. Optional start and end dates
20: # (leave empty string or zero for "no date")
21: # assigncustomrole (udom,uname,url,rdom,rnam,rolename,end,start) : give a
22: # custom role to a user for the level given by url.
23: # Specify name and domain of role author, and role name
24: # revokerole (udom,uname,url,role) : Revoke a role for url
25: # revokecustomrole (udom,uname,url,rdom,rnam,rolename) : Revoke a custom role
1.24 www 26: # appenv(hash) : adds hash to session environment
1.56 www 27: # delenv(varname) : deletes all environment entries starting with varname
1.12 www 28: # store(hash) : stores hash permanently for this url
1.47 www 29: # cstore(hash) : critical store
1.12 www 30: # restore : returns hash for this url
31: # eget(namesp,array) : returns hash with keys from array filled in from namesp
32: # get(namesp,array) : returns hash with keys from array filled in from namesp
1.38 www 33: # del(namesp,array) : deletes keys out of array from namesp
1.12 www 34: # put(namesp,hash) : stores hash in namesp
1.47 www 35: # cput(namesp,hash) : critical put
1.15 www 36: # dump(namesp) : dumps the complete namespace into a hash
1.23 www 37: # ssi(url,hash) : does a complete request cycle on url to localhost, posts
38: # hash
1.34 www 39: # coursedescription(id) : returns and caches course description for id
1.17 www 40: # repcopy(filename) : replicate file
41: # dirlist(url) : gets a directory listing
1.40 www 42: # directcondval(index) : reading condition value of single condition from
43: # state string
1.28 www 44: # condval(index) : value of condition index based on state
1.58 www 45: # EXT(name) : value of a variable
1.31 www 46: # symblist(map,hash) : Updates symbolic storage links
1.44 www 47: # symbread([filename]) : returns the data handle (filename optional)
1.31 www 48: # rndseed() : returns a random seed
1.36 albertel 49: # getfile(filename) : returns the contents of filename, or a -1 if it can't
50: # be found, replicates and subscribes to the file
51: # filelocation(dir,file) : returns a farily clean absolute reference to file
52: # from the directory dir
1.46 www 53: # hreflocation(dir,file) : same as filelocation, but for hrefs
1.47 www 54: # log(domain,user,home,msg) : write to permanent log for user
1.70 ! www 55: # usection(domain,user,courseid) : output of section name/number or '' for
! 56: # "not in course" and '-1' for "no section"
! 57: # userenvironment(domain,user,what) : puts out any environment parameter
! 58: # for a user
! 59: # idput(domain,hash) : writes IDs for users from hash (name=>id,name=>id)
! 60: # idget(domain,array): returns hash with usernames (id=>name,id=>name) for
! 61: # an array of IDs
! 62: # idrget(domain,array): returns hash with IDs for usernames (name=>id,...) for
! 63: # an array of names
1.12 www 64: #
1.1 albertel 65: # 6/1/99,6/2,6/10,6/11,6/12,6/14,6/26,6/28,6/29,6/30,
1.5 www 66: # 7/1,7/2,7/9,7/10,7/12,7/14,7/15,7/19,
1.8 www 67: # 11/8,11/16,11/18,11/22,11/23,12/22,
1.12 www 68: # 01/06,01/13,02/24,02/28,02/29,
69: # 03/01,03/02,03/06,03/07,03/13,
1.15 www 70: # 04/05,05/29,05/31,06/01,
71: # 06/05,06/26 Gerd Kortemeyer
72: # 06/26 Ben Tyszka
1.22 www 73: # 06/30,07/15,07/17,07/18,07/20,07/21,07/22,07/25 Gerd Kortemeyer
1.23 www 74: # 08/14 Ben Tyszka
1.36 albertel 75: # 08/22,08/28,08/31,09/01,09/02,09/04,09/05,09/25,09/28,09/30 Gerd Kortemeyer
1.35 www 76: # 10/04 Gerd Kortemeyer
1.36 albertel 77: # 10/04 Guy Albertelli
1.54 www 78: # 10/06,10/09,10/10,10/11,10/14,10/20,10/23,10/25,10/26,10/27,10/28,10/29,
1.69 www 79: # 10/30,10/31,11/2,11/14,11/15,11/16,11/20,11/21,11/22,11/25 Gerd Kortemeyer
1.1 albertel 80:
81: package Apache::lonnet;
82:
83: use strict;
84: use Apache::File;
1.8 www 85: use LWP::UserAgent();
1.15 www 86: use HTTP::Headers;
1.11 www 87: use vars
1.25 www 88: qw(%perlvar %hostname %homecache %spareid %hostdom %libserv %pr %prp %fe %fd $readit);
1.1 albertel 89: use IO::Socket;
1.31 www 90: use GDBM_File;
1.8 www 91: use Apache::Constants qw(:common :http);
1.1 albertel 92:
93: # --------------------------------------------------------------------- Logging
94:
95: sub logthis {
96: my $message=shift;
97: my $execdir=$perlvar{'lonDaemons'};
98: my $now=time;
99: my $local=localtime($now);
100: my $fh=Apache::File->new(">>$execdir/logs/lonnet.log");
101: print $fh "$local ($$): $message\n";
102: return 1;
103: }
104:
105: sub logperm {
106: my $message=shift;
107: my $execdir=$perlvar{'lonDaemons'};
108: my $now=time;
109: my $local=localtime($now);
110: my $fh=Apache::File->new(">>$execdir/logs/lonnet.perm.log");
111: print $fh "$now:$message:$local\n";
112: return 1;
113: }
114:
115: # -------------------------------------------------- Non-critical communication
116: sub subreply {
117: my ($cmd,$server)=@_;
118: my $peerfile="$perlvar{'lonSockDir'}/$server";
119: my $client=IO::Socket::UNIX->new(Peer =>"$peerfile",
120: Type => SOCK_STREAM,
121: Timeout => 10)
122: or return "con_lost";
123: print $client "$cmd\n";
124: my $answer=<$client>;
1.9 www 125: if (!$answer) { $answer="con_lost"; }
1.1 albertel 126: chomp($answer);
127: return $answer;
128: }
129:
130: sub reply {
131: my ($cmd,$server)=@_;
132: my $answer=subreply($cmd,$server);
133: if ($answer eq 'con_lost') { $answer=subreply($cmd,$server); }
1.65 www 134: if (($answer=~/^refused/) || ($answer=~/^rejected/)) {
1.12 www 135: &logthis("<font color=blue>WARNING:".
136: " $cmd to $server returned $answer</font>");
137: }
1.1 albertel 138: return $answer;
139: }
140:
141: # ----------------------------------------------------------- Send USR1 to lonc
142:
143: sub reconlonc {
144: my $peerfile=shift;
145: &logthis("Trying to reconnect for $peerfile");
146: my $loncfile="$perlvar{'lonDaemons'}/logs/lonc.pid";
147: if (my $fh=Apache::File->new("$loncfile")) {
148: my $loncpid=<$fh>;
149: chomp($loncpid);
150: if (kill 0 => $loncpid) {
151: &logthis("lonc at pid $loncpid responding, sending USR1");
152: kill USR1 => $loncpid;
153: sleep 1;
154: if (-e "$peerfile") { return; }
155: &logthis("$peerfile still not there, give it another try");
156: sleep 5;
157: if (-e "$peerfile") { return; }
1.12 www 158: &logthis(
159: "<font color=blue>WARNING: $peerfile still not there, giving up</font>");
1.1 albertel 160: } else {
1.12 www 161: &logthis(
162: "<font color=blue>WARNING:".
163: " lonc at pid $loncpid not responding, giving up</font>");
1.1 albertel 164: }
165: } else {
1.12 www 166: &logthis('<font color=blue>WARNING: lonc not running, giving up</font>');
1.1 albertel 167: }
168: }
169:
170: # ------------------------------------------------------ Critical communication
1.12 www 171:
1.1 albertel 172: sub critical {
173: my ($cmd,$server)=@_;
174: my $answer=reply($cmd,$server);
175: if ($answer eq 'con_lost') {
176: my $pingreply=reply('ping',$server);
177: &reconlonc("$perlvar{'lonSockDir'}/$server");
178: my $pongreply=reply('pong',$server);
179: &logthis("Ping/Pong for $server: $pingreply/$pongreply");
180: $answer=reply($cmd,$server);
181: if ($answer eq 'con_lost') {
182: my $now=time;
183: my $middlename=$cmd;
1.5 www 184: $middlename=substr($middlename,0,16);
1.1 albertel 185: $middlename=~s/\W//g;
186: my $dfilename=
187: "$perlvar{'lonSockDir'}/delayed/$now.$middlename.$server";
188: {
189: my $dfh;
190: if ($dfh=Apache::File->new(">$dfilename")) {
1.7 www 191: print $dfh "$cmd\n";
1.1 albertel 192: }
193: }
194: sleep 2;
195: my $wcmd='';
196: {
197: my $dfh;
198: if ($dfh=Apache::File->new("$dfilename")) {
199: $wcmd=<$dfh>;
200: }
201: }
202: chomp($wcmd);
1.7 www 203: if ($wcmd eq $cmd) {
1.12 www 204: &logthis("<font color=blue>WARNING: ".
205: "Connection buffer $dfilename: $cmd</font>");
1.1 albertel 206: &logperm("D:$server:$cmd");
207: return 'con_delayed';
208: } else {
1.12 www 209: &logthis("<font color=red>CRITICAL:"
210: ." Critical connection failed: $server $cmd</font>");
1.1 albertel 211: &logperm("F:$server:$cmd");
212: return 'con_failed';
213: }
214: }
215: }
216: return $answer;
217: }
218:
1.5 www 219: # ---------------------------------------------------------- Append Environment
220:
221: sub appenv {
1.6 www 222: my %newenv=@_;
1.35 www 223: map {
224: if (($newenv{$_}=~/^user\.role/) || ($newenv{$_}=~/^user\.priv/)) {
225: &logthis("<font color=blue>WARNING: ".
226: "Attempt to modify environment ".$_." to ".$newenv{$_});
227: delete($newenv{$_});
228: } else {
229: $ENV{$_}=$newenv{$_};
230: }
231: } keys %newenv;
1.6 www 232: my @oldenv;
233: {
234: my $fh;
235: unless ($fh=Apache::File->new("$ENV{'user.environment'}")) {
1.5 www 236: return 'error';
1.6 www 237: }
238: @oldenv=<$fh>;
239: }
240: for (my $i=0; $i<=$#oldenv; $i++) {
241: chomp($oldenv[$i]);
1.9 www 242: if ($oldenv[$i] ne '') {
243: my ($name,$value)=split(/=/,$oldenv[$i]);
1.24 www 244: unless (defined($newenv{$name})) {
245: $newenv{$name}=$value;
246: }
1.9 www 247: }
1.6 www 248: }
249: {
250: my $fh;
251: unless ($fh=Apache::File->new(">$ENV{'user.environment'}")) {
252: return 'error';
253: }
254: my $newname;
255: foreach $newname (keys %newenv) {
256: print $fh "$newname=$newenv{$newname}\n";
257: }
1.56 www 258: }
259: return 'ok';
260: }
261: # ----------------------------------------------------- Delete from Environment
262:
263: sub delenv {
264: my $delthis=shift;
265: my %newenv=();
266: if (($delthis=~/user\.role/) || ($delthis=~/user\.priv/)) {
267: &logthis("<font color=blue>WARNING: ".
268: "Attempt to delete from environment ".$delthis);
269: return 'error';
270: }
271: my @oldenv;
272: {
273: my $fh;
274: unless ($fh=Apache::File->new("$ENV{'user.environment'}")) {
275: return 'error';
276: }
277: @oldenv=<$fh>;
278: }
279: {
280: my $fh;
281: unless ($fh=Apache::File->new(">$ENV{'user.environment'}")) {
282: return 'error';
283: }
284: map {
285: unless ($_=~/^$delthis/) { print $fh $_; }
286: } @oldenv;
1.5 www 287: }
288: return 'ok';
289: }
1.1 albertel 290:
291: # ------------------------------ Find server with least workload from spare.tab
1.11 www 292:
1.1 albertel 293: sub spareserver {
294: my $tryserver;
295: my $spareserver='';
296: my $lowestserver=100;
297: foreach $tryserver (keys %spareid) {
298: my $answer=reply('load',$tryserver);
299: if (($answer =~ /\d/) && ($answer<$lowestserver)) {
300: $spareserver="http://$hostname{$tryserver}";
301: $lowestserver=$answer;
302: }
303: }
304: return $spareserver;
305: }
306:
307: # --------- Try to authenticate user from domain's lib servers (first this one)
1.11 www 308:
1.1 albertel 309: sub authenticate {
310: my ($uname,$upass,$udom)=@_;
1.12 www 311: $upass=escape($upass);
1.1 albertel 312: if (($perlvar{'lonRole'} eq 'library') &&
313: ($udom eq $perlvar{'lonDefDomain'})) {
1.3 www 314: my $answer=reply("encrypt:auth:$udom:$uname:$upass",$perlvar{'lonHostID'});
1.2 www 315: if ($answer =~ /authorized/) {
1.9 www 316: if ($answer eq 'authorized') {
317: &logthis("User $uname at $udom authorized by local server");
318: return $perlvar{'lonHostID'};
319: }
320: if ($answer eq 'non_authorized') {
321: &logthis("User $uname at $udom rejected by local server");
322: return 'no_host';
323: }
1.2 www 324: }
1.1 albertel 325: }
326:
327: my $tryserver;
328: foreach $tryserver (keys %libserv) {
329: if ($hostdom{$tryserver} eq $udom) {
1.10 www 330: my $answer=reply("encrypt:auth:$udom:$uname:$upass",$tryserver);
1.1 albertel 331: if ($answer =~ /authorized/) {
1.9 www 332: if ($answer eq 'authorized') {
333: &logthis("User $uname at $udom authorized by $tryserver");
334: return $tryserver;
335: }
336: if ($answer eq 'non_authorized') {
337: &logthis("User $uname at $udom rejected by $tryserver");
338: return 'no_host';
339: }
1.1 albertel 340: }
341: }
1.9 www 342: }
343: &logthis("User $uname at $udom could not be authenticated");
1.1 albertel 344: return 'no_host';
345: }
346:
347: # ---------------------- Find the homebase for a user from domain's lib servers
1.11 www 348:
1.1 albertel 349: sub homeserver {
350: my ($uname,$udom)=@_;
351:
352: my $index="$uname:$udom";
353: if ($homecache{$index}) { return "$homecache{$index}"; }
354:
355: my $tryserver;
356: foreach $tryserver (keys %libserv) {
357: if ($hostdom{$tryserver} eq $udom) {
358: my $answer=reply("home:$udom:$uname",$tryserver);
359: if ($answer eq 'found') {
360: $homecache{$index}=$tryserver;
361: return $tryserver;
362: }
363: }
364: }
365: return 'no_host';
1.70 ! www 366: }
! 367:
! 368: # ------------------------------------- Find the usernames behind a list of IDs
! 369:
! 370: sub idget {
! 371: my ($udom,@ids)=@_;
! 372: my %returnhash=();
! 373:
! 374: my $tryserver;
! 375: foreach $tryserver (keys %libserv) {
! 376: if ($hostdom{$tryserver} eq $udom) {
! 377: my $idlist=join('&',@ids);
! 378: $idlist=~tr/A-Z/a-z/;
! 379: my $reply=&reply("idget:$udom:".$idlist,$tryserver);
! 380: my @answer=();
! 381: if ($reply ne 'con_lost') {
! 382: @answer=split(/\&/,$reply);
! 383: } ;
! 384: my $i;
! 385: for ($i=0;$i<=$#ids;$i++) {
! 386: if ($answer[$i]) {
! 387: $returnhash{$ids[$i]}=$answer[$i];
! 388: }
! 389: }
! 390: }
! 391: }
! 392: return %returnhash;
! 393: }
! 394:
! 395: # ------------------------------------- Find the IDs behind a list of usernames
! 396:
! 397: sub idrget {
! 398: my ($udom,@unames)=@_;
! 399: my %returnhash=();
! 400: map {
! 401: $returnhash{$_}=(&userenvironment($udom,$_,'id'))[1];
! 402: } @unames;
! 403: return %returnhash;
! 404: }
! 405:
! 406: # ------------------------------- Store away a list of names and associated IDs
! 407:
! 408: sub idput {
! 409: my ($udom,%ids)=@_;
! 410: my %servers=();
! 411: map {
! 412: my $uhom=&homeserver($_,$udom);
! 413: if ($uhom ne 'no_host') {
! 414: my $id=&escape($ids{$_});
! 415: $id=~tr/A-Z/a-z/;
! 416: my $unam=&escape($_);
! 417: if ($servers{$uhom}) {
! 418: $servers{$uhom}.='&'.$id.'='.$unam;
! 419: } else {
! 420: $servers{$uhom}=$id.'='.$unam;
! 421: }
! 422: &critical('put:'.$udom.':'.$unam.':environment:id='.$id,$uhom);
! 423: }
! 424: } keys %ids;
! 425: map {
! 426: &critical('idput:'.$udom.':'.$servers{$_},$_);
! 427: } keys %servers;
! 428: }
! 429:
! 430: # ------------------------------------- Find the section of student in a course
! 431:
! 432: sub usection {
! 433: my ($udom,$unam,$courseid)=@_;
! 434: $courseid=~s/\_/\//g;
! 435: $courseid=~s/^(\w)/\/$1/;
! 436: map {
! 437: my ($key,$value)=split(/\=/,$_);
! 438: $key=&unescape($key);
! 439: if ($key=~/^$courseid(?:\/)*(\w+)*\_st$/) {
! 440: my $section=$1;
! 441: if ($key eq $courseid.'_st') { $section=''; }
! 442: my ($dummy,$end,$start)=split(/\_/,&unescape($value));
! 443: my $now=time;
! 444: my $notactive=0;
! 445: if ($start) {
! 446: if ($now<$start) { $notactive=1; }
! 447: }
! 448: if ($end) {
! 449: if ($now>$end) { $notactive=1; }
! 450: }
! 451: unless ($notactive) { return $section; }
! 452: }
! 453: } split(/\&/,&reply('dump:'.$udom.':'.$unam.':roles',
! 454: &homeserver($unam,$udom)));
! 455: return '-1';
! 456: }
! 457:
! 458: # ------------------------------------- Read an entry from a user's environment
! 459:
! 460: sub userenvironment {
! 461: my ($udom,$unam,@what)=@_;
! 462: my %returnhash=();
! 463: my @answer=split(/\&/,
! 464: &reply('get:'.$udom.':'.$unam.':environment:'.join('&',@what),
! 465: &homeserver($unam,$udom)));
! 466: my $i;
! 467: for ($i=0;$i<=$#what;$i++) {
! 468: $returnhash{$what[$i]}=&unescape($answer[$i]);
! 469: }
! 470: return %returnhash;
1.1 albertel 471: }
472:
473: # ----------------------------- Subscribe to a resource, return URL if possible
1.11 www 474:
1.1 albertel 475: sub subscribe {
476: my $fname=shift;
477: my $author=$fname;
478: $author=~s/\/home\/httpd\/html\/res\/([^\/]*)\/([^\/]*).*/$1\/$2/;
479: my ($udom,$uname)=split(/\//,$author);
480: my $home=homeserver($uname,$udom);
481: if (($home eq 'no_host') || ($home eq $perlvar{'lonHostID'})) {
482: return 'not_found';
483: }
484: my $answer=reply("sub:$fname",$home);
1.64 www 485: if (($answer eq 'con_lost') || ($answer eq 'rejected')) {
486: $answer.=' by '.$home;
487: }
1.1 albertel 488: return $answer;
489: }
490:
1.8 www 491: # -------------------------------------------------------------- Replicate file
492:
493: sub repcopy {
494: my $filename=shift;
1.23 www 495: $filename=~s/\/+/\//g;
1.8 www 496: my $transname="$filename.in.transfer";
1.17 www 497: if ((-e $filename) || (-e $transname)) { return OK; }
1.8 www 498: my $remoteurl=subscribe($filename);
1.64 www 499: if ($remoteurl =~ /^con_lost by/) {
500: &logthis("Subscribe returned $remoteurl: $filename");
1.8 www 501: return HTTP_SERVICE_UNAVAILABLE;
502: } elsif ($remoteurl eq 'not_found') {
503: &logthis("Subscribe returned not_found: $filename");
504: return HTTP_NOT_FOUND;
1.64 www 505: } elsif ($remoteurl =~ /^rejected by/) {
506: &logthis("Subscribe returned $remoteurl: $filename");
1.8 www 507: return FORBIDDEN;
1.20 www 508: } elsif ($remoteurl eq 'directory') {
509: return OK;
1.8 www 510: } else {
511: my @parts=split(/\//,$filename);
512: my $path="/$parts[1]/$parts[2]/$parts[3]/$parts[4]";
513: if ($path ne "$perlvar{'lonDocRoot'}/res") {
514: &logthis("Malconfiguration for replication: $filename");
515: return HTTP_BAD_REQUEST;
516: }
517: my $count;
518: for ($count=5;$count<$#parts;$count++) {
519: $path.="/$parts[$count]";
520: if ((-e $path)!=1) {
521: mkdir($path,0777);
522: }
523: }
524: my $ua=new LWP::UserAgent;
525: my $request=new HTTP::Request('GET',"$remoteurl");
526: my $response=$ua->request($request,$transname);
527: if ($response->is_error()) {
528: unlink($transname);
529: my $message=$response->status_line;
1.12 www 530: &logthis("<font color=blue>WARNING:"
531: ." LWP get: $message: $filename</font>");
1.8 www 532: return HTTP_SERVICE_UNAVAILABLE;
533: } else {
1.16 www 534: if ($remoteurl!~/\.meta$/) {
535: my $mrequest=new HTTP::Request('GET',$remoteurl.'.meta');
536: my $mresponse=$ua->request($mrequest,$filename.'.meta');
537: if ($mresponse->is_error()) {
538: unlink($filename.'.meta');
539: &logthis(
540: "<font color=yellow>INFO: No metadata: $filename</font>");
541: }
542: }
1.8 www 543: rename($transname,$filename);
544: return OK;
545: }
546: }
547: }
548:
1.15 www 549: # --------------------------------------------------------- Server Side Include
550:
551: sub ssi {
552:
1.23 www 553: my ($fn,%form)=@_;
1.15 www 554:
555: my $ua=new LWP::UserAgent;
1.23 www 556:
557: my $request;
558:
559: if (%form) {
560: $request=new HTTP::Request('POST',"http://".$ENV{'HTTP_HOST'}.$fn);
561: $request->content(join '&', map { "$_=$form{$_}" } keys %form);
562: } else {
563: $request=new HTTP::Request('GET',"http://".$ENV{'HTTP_HOST'}.$fn);
564: }
565:
1.15 www 566: $request->header(Cookie => $ENV{'HTTP_COOKIE'});
567: my $response=$ua->request($request);
568:
569: return $response->content;
570: }
571:
1.14 www 572: # ------------------------------------------------------------------------- Log
573:
574: sub log {
575: my ($dom,$nam,$hom,$what)=@_;
1.47 www 576: return critical("log:$dom:$nam:$what",$hom);
1.14 www 577: }
578:
1.9 www 579: # ----------------------------------------------------------------------- Store
580:
581: sub store {
1.31 www 582: my %storehash=@_;
583: my $symb;
1.44 www 584: unless ($symb=escape(&symbread())) { return ''; }
1.31 www 585: my $namespace;
1.33 www 586: unless ($namespace=$ENV{'request.course.id'}) { return ''; }
1.12 www 587: my $namevalue='';
588: map {
589: $namevalue.=escape($_).'='.escape($storehash{$_}).'&';
590: } keys %storehash;
591: $namevalue=~s/\&$//;
1.31 www 592: return reply(
593: "store:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$symb:$namevalue",
1.12 www 594: "$ENV{'user.home'}");
1.9 www 595: }
596:
1.47 www 597: # -------------------------------------------------------------- Critical Store
598:
599: sub cstore {
600: my %storehash=@_;
601: my $symb;
602: unless ($symb=escape(&symbread())) { return ''; }
603: my $namespace;
604: unless ($namespace=$ENV{'request.course.id'}) { return ''; }
605: my $namevalue='';
606: map {
607: $namevalue.=escape($_).'='.escape($storehash{$_}).'&';
608: } keys %storehash;
609: $namevalue=~s/\&$//;
610: return critical(
611: "store:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$symb:$namevalue",
612: "$ENV{'user.home'}");
613: }
614:
1.9 www 615: # --------------------------------------------------------------------- Restore
616:
617: sub restore {
1.31 www 618: my $symb;
1.44 www 619: unless ($symb=escape(&symbread())) { return ''; }
1.31 www 620: my $namespace;
1.33 www 621: unless ($namespace=$ENV{'request.course.id'}) { return ''; }
1.31 www 622: my $answer=reply(
623: "restore:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$symb",
624: "$ENV{'user.home'}");
1.12 www 625: my %returnhash=();
626: map {
627: my ($name,$value)=split(/\=/,$_);
628: $returnhash{&unescape($name)}=&unescape($value);
629: } split(/\&/,$answer);
1.31 www 630: map {
631: $returnhash{$_}=$returnhash{$returnhash{'version'}.':'.$_};
632: } split(/\:/,$returnhash{$returnhash{'version'}.':keys'});
1.13 www 633: return %returnhash;
1.34 www 634: }
635:
636: # ---------------------------------------------------------- Course Description
637:
638: sub coursedescription {
639: my $courseid=shift;
640: $courseid=~s/^\///;
1.49 www 641: $courseid=~s/\_/\//g;
1.34 www 642: my ($cdomain,$cnum)=split(/\//,$courseid);
643: my $chome=homeserver($cnum,$cdomain);
644: if ($chome ne 'no_host') {
645: my $rep=reply("dump:$cdomain:$cnum:environment",$chome);
646: if ($rep ne 'con_lost') {
1.54 www 647: my $normalid=$courseid;
648: $normalid=~s/\//\_/g;
1.53 www 649: my %envhash=();
1.34 www 650: my %returnhash=('home' => $chome,
651: 'domain' => $cdomain,
652: 'num' => $cnum);
653: map {
654: my ($name,$value)=split(/\=/,$_);
655: $name=&unescape($name);
656: $value=&unescape($value);
657: $returnhash{$name}=$value;
1.53 www 658: $envhash{'course.'.$normalid.'.'.$name}=$value;
1.34 www 659: } split(/\&/,$rep);
660: $returnhash{'url'}='/res/'.declutter($returnhash{'url'});
661: $returnhash{'fn'}=$perlvar{'lonDaemons'}.'/tmp/'.
1.38 www 662: $ENV{'user.name'}.'_'.$cdomain.'_'.$cnum;
1.54 www 663: $envhash{'course.'.$normalid.'.last_cache'}=time;
1.60 www 664: $envhash{'course.'.$normalid.'.home'}=$chome;
665: $envhash{'course.'.$normalid.'.domain'}=$cdomain;
666: $envhash{'course.'.$normalid.'.num'}=$cnum;
1.53 www 667: &appenv(%envhash);
1.34 www 668: return %returnhash;
669: }
670: }
671: return ();
1.9 www 672: }
1.1 albertel 673:
1.11 www 674: # -------------------------------------------------------- Get user priviledges
675:
676: sub rolesinit {
677: my ($domain,$username,$authhost)=@_;
678: my $rolesdump=reply("dump:$domain:$username:roles",$authhost);
1.12 www 679: if (($rolesdump eq 'con_lost') || ($rolesdump eq '')) { return ''; }
1.11 www 680: my %allroles=();
681: my %thesepriv=();
682: my $now=time;
1.21 www 683: my $userroles="user.login.time=$now\n";
1.11 www 684: my $thesestr;
685:
686: if ($rolesdump ne '') {
687: map {
1.21 www 688: if ($_!~/^rolesdef\&/) {
1.11 www 689: my ($area,$role)=split(/=/,$_);
1.21 www 690: $area=~s/\_\w\w$//;
1.11 www 691: my ($trole,$tend,$tstart)=split(/_/,$role);
1.21 www 692: $userroles.='user.role.'.$trole.'.'.$area.'='.
693: $tstart.'.'.$tend."\n";
1.11 www 694: if ($tend!=0) {
695: if ($tend<$now) {
696: $trole='';
697: }
698: }
699: if ($tstart!=0) {
700: if ($tstart>$now) {
701: $trole='';
702: }
703: }
704: if (($area ne '') && ($trole ne '')) {
1.50 www 705: my $spec=$trole.'.'.$area;
1.12 www 706: my ($tdummy,$tdomain,$trest)=split(/\//,$area);
707: if ($trole =~ /^cr\//) {
708: my ($rdummy,$rdomain,$rauthor,$rrole)=split(/\//,$trole);
709: my $homsvr=homeserver($rauthor,$rdomain);
710: if ($hostname{$homsvr} ne '') {
711: my $roledef=
1.21 www 712: reply("get:$rdomain:$rauthor:roles:rolesdef_$rrole",
1.12 www 713: $homsvr);
714: if (($roledef ne 'con_lost') && ($roledef ne '')) {
715: my ($syspriv,$dompriv,$coursepriv)=
1.21 www 716: split(/\_/,unescape($roledef));
1.50 www 717: $allroles{'cm./'}.=':'.$syspriv;
718: $allroles{$spec.'./'}.=':'.$syspriv;
1.12 www 719: if ($tdomain ne '') {
1.50 www 720: $allroles{'cm./'.$tdomain.'/'}.=':'.$dompriv;
721: $allroles{$spec.'./'.$tdomain.'/'}.=':'.$dompriv;
1.12 www 722: if ($trest ne '') {
1.50 www 723: $allroles{'cm.'.$area}.=':'.$coursepriv;
724: $allroles{$spec.'.'.$area}.=':'.$coursepriv;
1.12 www 725: }
726: }
727: }
1.11 www 728: }
1.12 www 729: } else {
1.50 www 730: $allroles{'cm./'}.=':'.$pr{$trole.':s'};
731: $allroles{$spec.'./'}.=':'.$pr{$trole.':s'};
1.12 www 732: if ($tdomain ne '') {
1.50 www 733: $allroles{'cm./'.$tdomain.'/'}.=':'.$pr{$trole.':d'};
734: $allroles{$spec.'./'.$tdomain.'/'}.=':'.$pr{$trole.':d'};
1.12 www 735: if ($trest ne '') {
1.50 www 736: $allroles{'cm.'.$area}.=':'.$pr{$trole.':c'};
737: $allroles{$spec.'.'.$area}.=':'.$pr{$trole.':c'};
1.12 www 738: }
739: }
1.11 www 740: }
1.12 www 741: }
742: }
1.11 www 743: } split(/&/,$rolesdump);
744: map {
745: %thesepriv=();
746: map {
747: if ($_ ne '') {
748: my ($priviledge,$restrictions)=split(/&/,$_);
749: if ($restrictions eq '') {
750: $thesepriv{$priviledge}='F';
751: } else {
752: if ($thesepriv{$priviledge} ne 'F') {
753: $thesepriv{$priviledge}.=$restrictions;
754: }
755: }
756: }
757: } split(/:/,$allroles{$_});
758: $thesestr='';
759: map { $thesestr.=':'.$_.'&'.$thesepriv{$_}; } keys %thesepriv;
760: $userroles.='user.priv.'.$_.'='.$thesestr."\n";
761: } keys %allroles;
762: }
763: return $userroles;
764: }
765:
1.12 www 766: # --------------------------------------------------------------- get interface
767:
768: sub get {
769: my ($namespace,@storearr)=@_;
770: my $items='';
771: map {
772: $items.=escape($_).'&';
773: } @storearr;
774: $items=~s/\&$//;
775: my $rep=reply("get:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
776: $ENV{'user.home'});
1.15 www 777: my @pairs=split(/\&/,$rep);
778: my %returnhash=();
1.42 www 779: my $i=0;
1.15 www 780: map {
1.42 www 781: $returnhash{$_}=unescape($pairs[$i]);
782: $i++;
783: } @storearr;
1.15 www 784: return %returnhash;
1.27 www 785: }
786:
787: # --------------------------------------------------------------- del interface
788:
789: sub del {
790: my ($namespace,@storearr)=@_;
791: my $items='';
792: map {
793: $items.=escape($_).'&';
794: } @storearr;
795: $items=~s/\&$//;
796: return reply("del:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
797: $ENV{'user.home'});
1.15 www 798: }
799:
800: # -------------------------------------------------------------- dump interface
801:
802: sub dump {
803: my $namespace=shift;
804: my $rep=reply("dump:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace",
805: $ENV{'user.home'});
1.12 www 806: my @pairs=split(/\&/,$rep);
807: my %returnhash=();
808: map {
809: my ($key,$value)=split(/=/,$_);
1.29 www 810: $returnhash{unescape($key)}=unescape($value);
1.12 www 811: } @pairs;
812: return %returnhash;
813: }
814:
815: # --------------------------------------------------------------- put interface
816:
817: sub put {
818: my ($namespace,%storehash)=@_;
819: my $items='';
820: map {
821: $items.=escape($_).'='.escape($storehash{$_}).'&';
822: } keys %storehash;
823: $items=~s/\&$//;
824: return reply("put:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
1.47 www 825: $ENV{'user.home'});
826: }
827:
828: # ------------------------------------------------------ critical put interface
829:
830: sub cput {
831: my ($namespace,%storehash)=@_;
832: my $items='';
833: map {
834: $items.=escape($_).'='.escape($storehash{$_}).'&';
835: } keys %storehash;
836: $items=~s/\&$//;
837: return critical
838: ("put:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
1.12 www 839: $ENV{'user.home'});
840: }
841:
842: # -------------------------------------------------------------- eget interface
843:
844: sub eget {
845: my ($namespace,@storearr)=@_;
846: my $items='';
847: map {
848: $items.=escape($_).'&';
849: } @storearr;
850: $items=~s/\&$//;
851: my $rep=reply("eget:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
852: $ENV{'user.home'});
853: my @pairs=split(/\&/,$rep);
854: my %returnhash=();
1.42 www 855: my $i=0;
1.12 www 856: map {
1.42 www 857: $returnhash{$_}=unescape($pairs[$i]);
858: $i++;
859: } @storearr;
1.12 www 860: return %returnhash;
861: }
862:
863: # ------------------------------------------------- Check for a user priviledge
864:
865: sub allowed {
866: my ($priv,$uri)=@_;
1.52 www 867: $uri=&declutter($uri);
1.29 www 868:
1.54 www 869: # Free bre access to adm and meta resources
1.29 www 870:
1.54 www 871: if ((($uri=~/^adm\//) || ($uri=~/\.meta$/)) && ($priv eq 'bre')) {
1.14 www 872: return 'F';
873: }
1.29 www 874:
1.52 www 875: my $thisallowed='';
876: my $statecond=0;
877: my $courseprivid='';
878:
879: # Course
880:
881: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'}=~/$priv\&([^\:]*)/) {
882: $thisallowed.=$1;
883: }
1.29 www 884:
1.52 www 885: # Domain
886:
887: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'.(split(/\//,$uri))[0].'/'}
888: =~/$priv\&([^\:]*)/) {
1.12 www 889: $thisallowed.=$1;
890: }
1.52 www 891:
892: # Course: uri itself is a course
1.66 www 893: my $courseuri=$uri;
894: $courseuri=~s/\_(\d)/\/$1/;
895: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'.$courseuri}
1.52 www 896: =~/$priv\&([^\:]*)/) {
1.12 www 897: $thisallowed.=$1;
898: }
1.29 www 899:
1.52 www 900: # Full access at system, domain or course-wide level? Exit.
1.29 www 901:
902: if ($thisallowed=~/F/) {
903: return 'F';
904: }
905:
1.52 www 906: # If this is generating or modifying users, exit with special codes
1.29 www 907:
1.52 www 908: if (':csu:cdc:ccc:cin:cta:cep:ccr:cst:cad:cli:cau:cdg:'=~/\:$priv\:/) {
909: return $thisallowed;
910: }
911: #
912: # Gathered so far: system, domain and course wide priviledges
913: #
914: # Course: See if uri or referer is an individual resource that is part of
915: # the course
916:
917: if ($ENV{'request.course.id'}) {
918: $courseprivid=$ENV{'request.course.id'};
919: if ($ENV{'request.course.sec'}) {
920: $courseprivid.='/'.$ENV{'request.course.sec'};
921: }
922: $courseprivid=~s/\_/\//;
923: my $checkreferer=1;
924: my @uriparts=split(/\//,$uri);
925: my $filename=$uriparts[$#uriparts];
926: my $pathname=$uri;
927: $pathname=~s/\/$filename$//;
928: if ($ENV{'acc.res.'.$ENV{'request.course.id'}.'.'.$pathname}=~
1.54 www 929: /\&$filename\:([\d\|]+)\&/) {
1.52 www 930: $statecond=$1;
931: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'.$courseprivid}
932: =~/$priv\&([^\:]*)/) {
933: $thisallowed.=$1;
934: $checkreferer=0;
935: }
1.29 www 936: }
1.55 www 937:
1.52 www 938: if (($ENV{'HTTP_REFERER'}) && ($checkreferer)) {
1.55 www 939: my $refuri=$ENV{'HTTP_REFERER'};
940: $refuri=~s/^http\:\/\/$ENV{'request.host'}//i;
941: $refuri=&declutter($refuri);
1.53 www 942: my @uriparts=split(/\//,$refuri);
1.52 www 943: my $filename=$uriparts[$#uriparts];
1.53 www 944: my $pathname=$refuri;
1.52 www 945: $pathname=~s/\/$filename$//;
1.55 www 946: my @filenameparts=split(/\./,$uri);
1.53 www 947: if (&fileembstyle($filenameparts[$#filenameparts]) ne 'ssi') {
948: if ($ENV{'acc.res.'.$ENV{'request.course.id'}.'.'.$pathname}=~
1.54 www 949: /\&$filename\:([\d\|]+)\&/) {
1.53 www 950: my $refstatecond=$1;
1.52 www 951: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'.$courseprivid}
952: =~/$priv\&([^\:]*)/) {
953: $thisallowed.=$1;
1.53 www 954: $uri=$refuri;
955: $statecond=$refstatecond;
1.52 www 956: }
1.53 www 957: }
1.52 www 958: }
1.29 www 959: }
1.52 www 960: }
1.29 www 961:
1.52 www 962: #
963: # Gathered now: all priviledges that could apply, and condition number
964: #
965: #
966: # Full or no access?
967: #
1.29 www 968:
1.52 www 969: if ($thisallowed=~/F/) {
970: return 'F';
971: }
1.29 www 972:
1.52 www 973: unless ($thisallowed) {
974: return '';
975: }
1.29 www 976:
1.52 www 977: # Restrictions exist, deal with them
978: #
979: # C:according to course preferences
980: # R:according to resource settings
981: # L:unless locked
982: # X:according to user session state
983: #
984:
985: # Possibly locked functionality, check all courses
1.54 www 986: # Locks might take effect only after 10 minutes cache expiration for other
987: # courses, and 2 minutes for current course
1.52 www 988:
989: my $envkey;
990: if ($thisallowed=~/L/) {
991: foreach $envkey (keys %ENV) {
1.54 www 992: if ($envkey=~/^user\.role\.(st|ta)\.([^\.]*)/) {
993: my $courseid=$2;
994: my $roleid=$1.'.'.$2;
995: my $expiretime=600;
996: if ($ENV{'request.role'} eq $roleid) {
997: $expiretime=120;
998: }
999: my ($cdom,$cnum,$csec)=split(/\//,$courseid);
1000: my $prefix='course.'.$cdom.'_'.$cnum.'.';
1001: if ((time-$ENV{$prefix.'last_cache'})>$expiretime) {
1002: &coursedescription($courseid);
1003: }
1004: if (($ENV{$prefix.'res.'.$uri.'.lock.sections'}=~/\,$csec\,/)
1005: || ($ENV{$prefix.'res.'.$uri.'.lock.sections'} eq 'all')) {
1006: if ($ENV{$prefix.'res.'.$uri.'.lock.expire'}>time) {
1.57 www 1007: &log($ENV{'user.domain'},$ENV{'user.name'},
1008: $ENV{'user.host'},
1009: 'Locked by res: '.$priv.' for '.$uri.' due to '.
1.52 www 1010: $cdom.'/'.$cnum.'/'.$csec.' expire '.
1.54 www 1011: $ENV{$prefix.'priv.'.$priv.'.lock.expire'});
1.52 www 1012: return '';
1013: }
1014: }
1.54 www 1015: if (($ENV{$prefix.'priv.'.$priv.'.lock.sections'}=~/\,$csec\,/)
1016: || ($ENV{$prefix.'priv.'.$priv.'.lock.sections'} eq 'all')) {
1017: if ($ENV{'priv.'.$priv.'.lock.expire'}>time) {
1.57 www 1018: &log($ENV{'user.domain'},$ENV{'user.name'},
1019: $ENV{'user.host'},
1020: 'Locked by priv: '.$priv.' for '.$uri.' due to '.
1.52 www 1021: $cdom.'/'.$cnum.'/'.$csec.' expire '.
1.54 www 1022: $ENV{$prefix.'priv.'.$priv.'.lock.expire'});
1.52 www 1023: return '';
1024: }
1025: }
1026: }
1.29 www 1027: }
1.52 www 1028: }
1029:
1030: #
1031: # Rest of the restrictions depend on selected course
1032: #
1033:
1034: unless ($ENV{'request.course.id'}) {
1035: return '1';
1036: }
1.29 www 1037:
1.52 www 1038: #
1039: # Now user is definitely in a course
1040: #
1.53 www 1041:
1042:
1043: # Course preferences
1044:
1045: if ($thisallowed=~/C/) {
1.54 www 1046: my $rolecode=(split(/\./,$ENV{'request.role'}))[0];
1047: if ($ENV{'course.'.$ENV{'request.course.id'}.'.'.$priv.'.roles.denied'}
1048: =~/\,$rolecode\,/) {
1.57 www 1049: &log($ENV{'user.domain'},$ENV{'user.name'},$ENV{'user.host'},
1050: 'Denied by role: '.$priv.' for '.$uri.' as '.$rolecode.' in '.
1.54 www 1051: $ENV{'request.course.id'});
1052: return '';
1053: }
1.53 www 1054: }
1055:
1056: # Resource preferences
1057:
1058: if ($thisallowed=~/R/) {
1.54 www 1059: my $rolecode=(split(/\./,$ENV{'request.role'}))[0];
1060: my $filename=$perlvar{'lonDocRoot'}.'/res/'.$uri.'.meta';
1061: if (-e $filename) {
1062: my @content;
1063: {
1064: my $fh=Apache::File->new($filename);
1065: @content=<$fh>;
1066: }
1067: if (join('',@content)=~
1068: /\<roledeny[^\>]*\>[^\<]*$rolecode[^\<]*\<\/roledeny\>/) {
1.57 www 1069: &log($ENV{'user.domain'},$ENV{'user.name'},$ENV{'user.host'},
1070: 'Denied by role: '.$priv.' for '.$uri.' as '.$rolecode);
1.54 www 1071: return '';
1072:
1073: }
1074: }
1.53 www 1075: }
1.30 www 1076:
1.52 www 1077: # Restricted by state?
1.30 www 1078:
1.52 www 1079: if ($thisallowed=~/X/) {
1080: if (&condval($statecond)) {
1081: return '2';
1082: } else {
1083: return '';
1084: }
1085: }
1.30 www 1086:
1.52 www 1087: return 'F';
1.12 www 1088: }
1089:
1090: # ----------------------------------------------------------------- Define Role
1091:
1092: sub definerole {
1093: if (allowed('mcr','/')) {
1094: my ($rolename,$sysrole,$domrole,$courole)=@_;
1.21 www 1095: map {
1096: my ($crole,$cqual)=split(/\&/,$_);
1097: if ($pr{'cr:s'}!~/$crole/) { return "refused:s:$crole"; }
1098: if ($pr{'cr:s'}=~/$crole\&/) {
1099: if ($pr{'cr:s'}!~/$crole\&\w*$cqual/) {
1100: return "refused:s:$crole&$cqual";
1101: }
1102: }
1103: } split('/',$sysrole);
1104: map {
1105: my ($crole,$cqual)=split(/\&/,$_);
1106: if ($pr{'cr:d'}!~/$crole/) { return "refused:d:$crole"; }
1107: if ($pr{'cr:d'}=~/$crole\&/) {
1108: if ($pr{'cr:d'}!~/$crole\&\w*$cqual/) {
1109: return "refused:d:$crole&$cqual";
1110: }
1111: }
1112: } split('/',$domrole);
1113: map {
1114: my ($crole,$cqual)=split(/\&/,$_);
1115: if ($pr{'cr:c'}!~/$crole/) { return "refused:c:$crole"; }
1116: if ($pr{'cr:c'}=~/$crole\&/) {
1117: if ($pr{'cr:c'}!~/$crole\&\w*$cqual/) {
1118: return "refused:c:$crole&$cqual";
1119: }
1120: }
1121: } split('/',$courole);
1.12 www 1122: my $command="encrypt:rolesput:$ENV{'user.domain'}:$ENV{'user.name'}:".
1123: "$ENV{'user.domain'}:$ENV{'user.name'}:".
1.21 www 1124: "rolesdef_$rolename=".
1125: escape($sysrole.'_'.$domrole.'_'.$courole);
1.12 www 1126: return reply($command,$ENV{'user.home'});
1127: } else {
1128: return 'refused';
1129: }
1130: }
1131:
1132: # ------------------------------------------------------------------ Plain Text
1133:
1134: sub plaintext {
1.22 www 1135: my $short=shift;
1136: return $prp{$short};
1.12 www 1137: }
1138:
1.25 www 1139: # ------------------------------------------------------------------ Plain Text
1140:
1141: sub fileembstyle {
1142: my $ending=shift;
1143: return $fe{$ending};
1144: }
1145:
1146: # ------------------------------------------------------------ Description Text
1147:
1148: sub filedecription {
1149: my $ending=shift;
1150: return $fd{$ending};
1151: }
1152:
1.12 www 1153: # ----------------------------------------------------------------- Assign Role
1154:
1155: sub assignrole {
1.21 www 1156: my ($udom,$uname,$url,$role,$end,$start)=@_;
1157: my $mrole;
1.31 www 1158: $url=declutter($url);
1.21 www 1159: if ($role =~ /^cr\//) {
1160: unless ($url=~/\.course$/) { return 'invalid'; }
1161: unless (allowed('ccr',$url)) { return 'refused'; }
1162: $mrole='cr';
1163: } else {
1164: unless (($url=~/\.course$/) || ($url=~/\/$/)) { return 'invalid'; }
1165: unless (allowed('c'+$role)) { return 'refused'; }
1166: $mrole=$role;
1167: }
1168: my $command="encrypt:rolesput:$ENV{'user.domain'}:$ENV{'user.name'}:".
1169: "$udom:$uname:$url".'_'."$mrole=$role";
1170: if ($end) { $command.='_$end'; }
1171: if ($start) {
1172: if ($end) {
1173: $command.='_$start';
1174: } else {
1175: $command.='_0_$start';
1176: }
1177: }
1178: return &reply($command,&homeserver($uname,$udom));
1179: }
1180:
1181: # ---------------------------------------------------------- Assign Custom Role
1182:
1183: sub assigncustomrole {
1184: my ($udom,$uname,$url,$rdom,$rnam,$rolename,$end,$start)=@_;
1185: return &assignrole($udom,$uname,$url,'cr/'.$rdom.'/'.$rnam.'/'.$rolename,
1186: $end,$start);
1187: }
1188:
1189: # ----------------------------------------------------------------- Revoke Role
1190:
1191: sub revokerole {
1192: my ($udom,$uname,$url,$role)=@_;
1193: my $now=time;
1194: return &assignrole($udom,$uname,$url,$role,$now);
1195: }
1196:
1197: # ---------------------------------------------------------- Revoke Custom Role
1198:
1199: sub revokecustomrole {
1200: my ($udom,$uname,$url,$rdom,$rnam,$rolename)=@_;
1201: my $now=time;
1202: return &assigncustomrole($udom,$uname,$url,$rdom,$rnam,$rolename,$now);
1.17 www 1203: }
1204:
1205: # ------------------------------------------------------------ Directory lister
1206:
1207: sub dirlist {
1208: my $uri=shift;
1.18 www 1209: $uri=~s/^\///;
1210: $uri=~s/\/$//;
1.19 www 1211: my ($res,$udom,$uname,@rest)=split(/\//,$uri);
1212: if ($udom) {
1213: if ($uname) {
1214: my $listing=reply('ls:'.$perlvar{'lonDocRoot'}.'/'.$uri,
1215: homeserver($uname,$udom));
1216: return split(/:/,$listing);
1217: } else {
1218: my $tryserver;
1219: my %allusers=();
1220: foreach $tryserver (keys %libserv) {
1221: if ($hostdom{$tryserver} eq $udom) {
1222: my $listing=reply('ls:'.$perlvar{'lonDocRoot'}.'/res/'.$udom,
1223: $tryserver);
1224: if (($listing ne 'no_such_dir') && ($listing ne 'empty')
1225: && ($listing ne 'con_lost')) {
1226: map {
1227: my ($entry,@stat)=split(/&/,$_);
1228: $allusers{$entry}=1;
1229: } split(/:/,$listing);
1230: }
1231: }
1232: }
1233: my $alluserstr='';
1234: map {
1235: $alluserstr.=$_.'&user:';
1236: } sort keys %allusers;
1237: $alluserstr=~s/:$//;
1238: return split(/:/,$alluserstr);
1239: }
1240: } else {
1241: my $tryserver;
1242: my %alldom=();
1243: foreach $tryserver (keys %libserv) {
1244: $alldom{$hostdom{$tryserver}}=1;
1245: }
1246: my $alldomstr='';
1247: map {
1248: $alldomstr.=$perlvar{'lonDocRoot'}.'/res/'.$_.'&domain:';
1249: } sort keys %alldom;
1250: $alldomstr=~s/:$//;
1251: return split(/:/,$alldomstr);
1252: }
1.26 www 1253: }
1254:
1255: # -------------------------------------------------------- Value of a Condition
1256:
1.40 www 1257: sub directcondval {
1258: my $number=shift;
1259: if ($ENV{'user.state.'.$ENV{'request.course.id'}}) {
1260: return substr($ENV{'user.state.'.$ENV{'request.course.id'}},$number,1);
1261: } else {
1262: return 2;
1263: }
1264: }
1265:
1.26 www 1266: sub condval {
1267: my $condidx=shift;
1268: my $result=0;
1.54 www 1269: my $allpathcond='';
1270: map {
1271: if (defined($ENV{'acc.cond.'.$ENV{'request.course.id'}.'.'.$_})) {
1272: $allpathcond.=
1273: '('.$ENV{'acc.cond.'.$ENV{'request.course.id'}.'.'.$_}.')|';
1274: }
1275: } split(/\|/,$condidx);
1276: $allpathcond=~s/\|$//;
1.33 www 1277: if ($ENV{'request.course.id'}) {
1.54 www 1278: if ($allpathcond) {
1.26 www 1279: my $operand='|';
1280: my @stack;
1281: map {
1282: if ($_ eq '(') {
1283: push @stack,($operand,$result)
1284: } elsif ($_ eq ')') {
1285: my $before=pop @stack;
1286: if (pop @stack eq '&') {
1287: $result=$result>$before?$before:$result;
1288: } else {
1289: $result=$result>$before?$result:$before;
1290: }
1291: } elsif (($_ eq '&') || ($_ eq '|')) {
1292: $operand=$_;
1293: } else {
1.40 www 1294: my $new=directcondval($_);
1.26 www 1295: if ($operand eq '&') {
1296: $result=$result>$new?$new:$result;
1297: } else {
1298: $result=$result>$new?$result:$new;
1299: }
1300: }
1.54 www 1301: } ($allpathcond=~/(\d+|\(|\)|\&|\|)/g);
1.26 www 1302: }
1303: }
1304: return $result;
1.28 www 1305: }
1306:
1307: # --------------------------------------------------------- Value of a Variable
1308:
1.58 www 1309: sub EXT {
1.48 www 1310: my $varname=shift;
1.68 www 1311: unless ($varname) { return ''; }
1.48 www 1312: my ($realm,$space,$qualifier,@therest)=split(/\./,$varname);
1313: my $rest;
1314: if ($therest[0]) {
1315: $rest=join('.',@therest);
1316: } else {
1317: $rest='';
1318: }
1.57 www 1319: my $qualifierrest=$qualifier;
1320: if ($rest) { $qualifierrest.='.'.$rest; }
1321: my $spacequalifierrest=$space;
1322: if ($qualifierrest) { $spacequalifierrest.='.'.$qualifierrest; }
1.28 www 1323: if ($realm eq 'user') {
1.48 www 1324: # --------------------------------------------------------------- user.resource
1325: if ($space eq 'resource') {
1.57 www 1326: my %restored=&restore;
1327: return $restored{$qualifierrest};
1.48 www 1328: # ----------------------------------------------------------------- user.access
1329: } elsif ($space eq 'access') {
1330: return &allowed($qualifier,$rest);
1331: # ------------------------------------------ user.preferences, user.environment
1332: } elsif (($space eq 'preferences') || ($space eq 'environment')) {
1.57 www 1333: return $ENV{join('.',('environment',$qualifierrest))};
1.48 www 1334: # ----------------------------------------------------------------- user.course
1335: } elsif ($space eq 'course') {
1336: return $ENV{join('.',('request.course',$qualifier))};
1337: # ------------------------------------------------------------------- user.role
1338: } elsif ($space eq 'role') {
1339: my ($role,$where)=split(/\./,$ENV{'request.role'});
1340: if ($qualifier eq 'value') {
1341: return $role;
1342: } elsif ($qualifier eq 'extent') {
1343: return $where;
1344: }
1345: # ----------------------------------------------------------------- user.domain
1346: } elsif ($space eq 'domain') {
1347: return $ENV{'user.domain'};
1348: # ------------------------------------------------------------------- user.name
1349: } elsif ($space eq 'name') {
1350: return $ENV{'user.name'};
1351: # ---------------------------------------------------- Any other user namespace
1.29 www 1352: } else {
1.48 www 1353: my $item=($rest)?$qualifier.'.'.$rest:$qualifier;
1354: my %reply=&get($space,$item);
1355: return $reply{$item};
1356: }
1357: } elsif ($realm eq 'request') {
1358: # ------------------------------------------------------------- request.browser
1359: if ($space eq 'browser') {
1360: return $ENV{'browser.'.$qualifier};
1.57 www 1361: # ------------------------------------------------------------ request.filename
1362: } else {
1363: return $ENV{'request.'.$spacequalifierrest};
1.29 www 1364: }
1.28 www 1365: } elsif ($realm eq 'course') {
1.48 www 1366: # ---------------------------------------------------------- course.description
1.57 www 1367: my $section='';
1368: if ($ENV{'request.course.sec'}) {
1369: $section='_'.$ENV{'request.course.sec'};
1.48 www 1370: }
1.57 www 1371: return $ENV{'course.'.$ENV{'request.course.id'}.$section.'.'.
1372: $spacequalifierrest};
1373: } elsif ($realm eq 'resource') {
1.60 www 1374: if ($ENV{'request.course.id'}) {
1375: # ----------------------------------------------------- Cascading lookup scheme
1.69 www 1376: my $symbp=&symbread();
1377: my $mapp=(split(/\_\_\_/,$symbp))[0];
1378:
1379: my $symbparm=$symbp.'.'.$spacequalifierrest;
1380: my $mapparm=$mapp.'___(all).'.$spacequalifierrest;
1381:
1.60 www 1382: my $seclevel=
1.69 www 1383: $ENV{'request.course.id'}.'.['.
1384: $ENV{'request.course.sec'}.'].'.$spacequalifierrest;
1385: my $seclevelr=
1386: $ENV{'request.course.id'}.'.['.
1387: $ENV{'request.course.sec'}.'].'.$symbparm;
1388: my $seclevelm=
1389: $ENV{'request.course.id'}.'.['.
1390: $ENV{'request.course.sec'}.'].'.$mapparm;
1391:
1.60 www 1392: my $courselevel=
1393: $ENV{'request.course.id'}.'.'.$spacequalifierrest;
1.69 www 1394: my $courselevelr=
1395: $ENV{'request.course.id'}.'.'.$symbparm;
1396: my $courselevelm=
1397: $ENV{'request.course.id'}.'.'.$mapparm;
1398:
1.60 www 1399:
1400: # ----------------------------------------------------------- first, check user
1.69 www 1401: my %resourcedata=get('resourcedata',
1402: ($courselevelr,$courselevelm,$courselevel));
1403: if ($resourcedata{$courselevelr}!~/^error\:/) {
1404:
1405: if ($resourcedata{$courselevelr}) {
1406: return $resourcedata{$courselevelr}; }
1407: if ($resourcedata{$courselevelm}) {
1408: return $resourcedata{$courselevelm}; }
1.60 www 1409: if ($resourcedata{$courselevel}) { return $resourcedata{$courselevel}; }
1.69 www 1410:
1.63 www 1411: }
1.60 www 1412: # -------------------------------------------------------- second, check course
1413: my $section='';
1414: if ($ENV{'request.course.sec'}) {
1415: $section='_'.$ENV{'request.course.sec'};
1416: }
1417: my $reply=&reply('get:'.
1418: $ENV{'course.'.$ENV{'request.course.id'}.$section.'.domain'}.':'.
1419: $ENV{'course.'.$ENV{'request.course.id'}.$section.'.num'}.
1420: ':resourcedata:'.
1.69 www 1421: escape($seclevelr).':'.escape($seclevelm).':'.escape($seclevel).':'.
1422: escape($courselevelr).':'.escape($courselevelm).':'.escape($courselevel),
1.60 www 1423: $ENV{'course.'.$ENV{'request.course.id'}.$section.'.home'});
1.63 www 1424: if ($reply!~/^error\:/) {
1.60 www 1425: map {
1426: my ($name,$value)=split(/\=/,$_);
1427: $resourcedata{unescape($name)}=unescape($value);
1428: } split(/\&/,$reply);
1.69 www 1429:
1430: if ($resourcedata{$seclevelr}) { return $resourcedata{$seclevelr}; }
1431: if ($resourcedata{$seclevelm}) { return $resourcedata{$seclevelm}; }
1432: if ($resourcedata{$seclevel}) { return $resourcedata{$seclevel}; }
1433:
1434: if ($resourcedata{$courselevelr}) {
1435: return $resourcedata{$courselevelr}; }
1436: if ($resourcedata{$courselevelm}) {
1437: return $resourcedata{$courselevelm}; }
1.60 www 1438: if ($resourcedata{$courselevel}) { return $resourcedata{$courselevel}; }
1.69 www 1439:
1.63 www 1440: }
1.60 www 1441:
1442: # ------------------------------------------------------ third, check map parms
1.65 www 1443: my %parmhash=();
1444: my $thisparm='';
1445: if (tie(%parmhash,'GDBM_File',
1446: $ENV{'request.course.fn'}.'_parms.db',&GDBM_READER,0640)) {
1447: $thisparm=$parmhash{$symbparm};
1448: untie(%parmhash);
1.60 www 1449: }
1.65 www 1450: if ($thisparm) { return $thisparm; }
1.60 www 1451: }
1452:
1453: # --------------------------------------------- last, look in resource metadata
1.57 www 1454: my $uri=&declutter($ENV{'request.filename'});
1.67 www 1455: my $filename=$perlvar{'lonDocRoot'}.'/res/'.$uri.'.meta';
1.57 www 1456: if (-e $filename) {
1457: my @content;
1458: {
1459: my $fh=Apache::File->new($filename);
1460: @content=<$fh>;
1461: }
1462: if (join('',@content)=~
1463: /\<$space[^\>]*\>([^\<]*)\<\/$space\>/) {
1464: return $1;
1.60 www 1465: }
1466: }
1.48 www 1467: # ---------------------------------------------------- Any other user namespace
1468: } elsif ($realm eq 'environment') {
1469: # ----------------------------------------------------------------- environment
1.57 www 1470: return $ENV{$spacequalifierrest};
1.28 www 1471: } elsif ($realm eq 'system') {
1.48 www 1472: # ----------------------------------------------------------------- system.time
1473: if ($space eq 'time') {
1474: return time;
1475: }
1.28 www 1476: }
1.48 www 1477: return '';
1.61 www 1478: }
1479:
1.31 www 1480: # ------------------------------------------------- Update symbolic store links
1481:
1482: sub symblist {
1483: my ($mapname,%newhash)=@_;
1484: $mapname=declutter($mapname);
1485: my %hash;
1486: if (($ENV{'request.course.fn'}) && (%newhash)) {
1487: if (tie(%hash,'GDBM_File',$ENV{'request.course.fn'}.'_symb.db',
1488: &GDBM_WRCREAT,0640)) {
1489: map {
1490: $hash{declutter($_)}=$mapname.'___'.$newhash{$_};
1491: } keys %newhash;
1492: if (untie(%hash)) {
1493: return 'ok';
1494: }
1495: }
1496: }
1497: return 'error';
1498: }
1499:
1500: # ------------------------------------------------------ Return symb list entry
1501:
1502: sub symbread {
1.44 www 1503: my $thisfn=shift;
1504: unless ($thisfn) {
1505: $thisfn=$ENV{'request.filename'};
1506: }
1507: $thisfn=declutter($thisfn);
1.31 www 1508: my %hash;
1.37 www 1509: my %bighash;
1510: my $syval='';
1.45 www 1511: if (($ENV{'request.course.fn'}) && ($thisfn)) {
1.31 www 1512: if (tie(%hash,'GDBM_File',$ENV{'request.course.fn'}.'_symb.db',
1513: &GDBM_READER,0640)) {
1514: $syval=$hash{$thisfn};
1.37 www 1515: untie(%hash);
1516: }
1517: # ---------------------------------------------------------- There was an entry
1518: if ($syval) {
1519: unless ($syval=~/\_\d+$/) {
1520: unless ($ENV{'form.request.prefix'}=~/\.(\d+)\_$/) {
1.44 www 1521: &appenv('request.ambiguous' => $thisfn);
1.37 www 1522: return '';
1523: }
1524: $syval.=$1;
1525: }
1526: } else {
1527: # ------------------------------------------------------- Was not in symb table
1528: if (tie(%bighash,'GDBM_File',$ENV{'request.course.fn'}.'.db',
1529: &GDBM_READER,0640)) {
1530: # ---------------------------------------------- Get ID(s) for current resource
1531: my $ids=$bighash{'ids_/res/'.$thisfn};
1.65 www 1532: unless ($ids) {
1533: $ids=$bighash{'ids_/'.$thisfn};
1534: }
1.37 www 1535: if ($ids) {
1536: # ------------------------------------------------------------------- Has ID(s)
1537: my @possibilities=split(/\,/,$ids);
1.39 www 1538: if ($#possibilities==0) {
1539: # ----------------------------------------------- There is only one possibility
1.37 www 1540: my ($mapid,$resid)=split(/\./,$ids);
1541: $syval=declutter($bighash{'map_id_'.$mapid}).'___'.$resid;
1542: } else {
1.39 www 1543: # ------------------------------------------ There is more than one possibility
1544: my $realpossible=0;
1545: map {
1546: my $file=$bighash{'src_'.$_};
1547: if (&allowed('bre',$file)) {
1548: my ($mapid,$resid)=split(/\./,$_);
1549: if ($bighash{'map_type_'.$mapid} ne 'page') {
1550: $realpossible++;
1551: $syval=declutter($bighash{'map_id_'.$mapid}).
1552: '___'.$resid;
1553: }
1554: }
1555: } @possibilities;
1556: if ($realpossible!=1) { $syval=''; }
1.37 www 1557: }
1558: }
1559: untie(%bighash)
1560: }
1.31 www 1561: }
1.62 www 1562: if ($syval) {
1563: return $syval.'___'.$thisfn;
1564: }
1.31 www 1565: }
1.44 www 1566: &appenv('request.ambiguous' => $thisfn);
1.31 www 1567: return '';
1568: }
1569:
1570: # ---------------------------------------------------------- Return random seed
1571:
1.32 www 1572: sub numval {
1573: my $txt=shift;
1574: $txt=~tr/A-J/0-9/;
1575: $txt=~tr/a-j/0-9/;
1576: $txt=~tr/K-T/0-9/;
1577: $txt=~tr/k-t/0-9/;
1578: $txt=~tr/U-Z/0-5/;
1579: $txt=~tr/u-z/0-5/;
1580: $txt=~s/\D//g;
1581: return int($txt);
1582: }
1583:
1.31 www 1584: sub rndseed {
1585: my $symb;
1.44 www 1586: unless ($symb=&symbread()) { return time; }
1.32 www 1587: my $symbchck=unpack("%32C*",$symb);
1588: my $symbseed=numval($symb)%$symbchck;
1589: my $namechck=unpack("%32C*",$ENV{'user.name'});
1590: my $nameseed=numval($ENV{'user.name'})%$namechck;
1591: return int( $symbseed
1592: .$nameseed
1593: .unpack("%32C*",$ENV{'user.domain'})
1.33 www 1594: .unpack("%32C*",$ENV{'request.course.id'})
1.32 www 1595: .$namechck
1596: .$symbchck);
1.36 albertel 1597: }
1598:
1599: # ------------------------------------------------------------ Serves up a file
1600: # returns either the contents of the file or a -1
1601: sub getfile {
1602: my $file=shift;
1.37 www 1603: &repcopy($file);
1.36 albertel 1604: if (! -e $file ) { return -1; };
1605: my $fh=Apache::File->new($file);
1606: my $a='';
1607: while (<$fh>) { $a .=$_; }
1608: return $a
1609: }
1610:
1611: sub filelocation {
1612: my ($dir,$file) = @_;
1613: my $location;
1614: $file=~ s/^\s*(\S+)\s*$/$1/; ## strip off leading and trailing spaces
1.59 albertel 1615: if ($file=~m:^/~:) { # is a contruction space reference
1616: $location = $file;
1617: $location =~ s:/~(.*?)/(.*):/home/$1/public_html/$2:;
1.36 albertel 1618: } else {
1.59 albertel 1619: $file=~s/^$perlvar{'lonDocRoot'}//;
1620: $file=~s:^/*res::;
1621: if ( !( $file =~ m:^/:) ) {
1622: $location = $dir. '/'.$file;
1623: } else {
1624: $location = '/home/httpd/html/res'.$file;
1625: }
1.36 albertel 1626: }
1627: $location=~s://+:/:g; # remove duplicate /
1.46 www 1628: while ($location=~m:/\.\./:) {$location=~ s:/[^/]+/\.\./:/:g;} #remove dir/..
1629: return $location;
1630: }
1.36 albertel 1631:
1.46 www 1632: sub hreflocation {
1633: my ($dir,$file)=@_;
1634: unless (($_=~/^http:\/\//i) || ($_=~/^\//)) {
1635: my $finalpath=filelocation($dir,$file);
1636: $finalpath=~s/^\/home\/httpd\/html//;
1637: return $finalpath;
1638: } else {
1639: return $file;
1640: }
1.31 www 1641: }
1642:
1643: # ------------------------------------------------------------- Declutters URLs
1644:
1645: sub declutter {
1646: my $thisfn=shift;
1647: $thisfn=~s/^$perlvar{'lonDocRoot'}//;
1648: $thisfn=~s/^\///;
1649: $thisfn=~s/^res\///;
1650: return $thisfn;
1.12 www 1651: }
1652:
1653: # -------------------------------------------------------- Escape Special Chars
1654:
1655: sub escape {
1656: my $str=shift;
1657: $str =~ s/(\W)/"%".unpack('H2',$1)/eg;
1658: return $str;
1659: }
1660:
1661: # ----------------------------------------------------- Un-Escape Special Chars
1662:
1663: sub unescape {
1664: my $str=shift;
1665: $str =~ s/%([a-fA-F0-9][a-fA-F0-9])/pack("C",hex($1))/eg;
1666: return $str;
1667: }
1.11 www 1668:
1.1 albertel 1669: # ================================================================ Main Program
1670:
1671: sub BEGIN {
1672: if ($readit ne 'done') {
1673: # ------------------------------------------------------------ Read access.conf
1674: {
1675: my $config=Apache::File->new("/etc/httpd/conf/access.conf");
1676:
1677: while (my $configline=<$config>) {
1678: if ($configline =~ /PerlSetVar/) {
1679: my ($dummy,$varname,$varvalue)=split(/\s+/,$configline);
1.8 www 1680: chomp($varvalue);
1.1 albertel 1681: $perlvar{$varname}=$varvalue;
1682: }
1683: }
1684: }
1685:
1686: # ------------------------------------------------------------- Read hosts file
1687: {
1688: my $config=Apache::File->new("$perlvar{'lonTabDir'}/hosts.tab");
1689:
1690: while (my $configline=<$config>) {
1691: my ($id,$domain,$role,$name,$ip)=split(/:/,$configline);
1692: $hostname{$id}=$name;
1693: $hostdom{$id}=$domain;
1694: if ($role eq 'library') { $libserv{$id}=$name; }
1695: }
1696: }
1697:
1698: # ------------------------------------------------------ Read spare server file
1699: {
1700: my $config=Apache::File->new("$perlvar{'lonTabDir'}/spare.tab");
1701:
1702: while (my $configline=<$config>) {
1703: chomp($configline);
1704: if (($configline) && ($configline ne $perlvar{'lonHostID'})) {
1705: $spareid{$configline}=1;
1706: }
1707: }
1708: }
1.11 www 1709: # ------------------------------------------------------------ Read permissions
1710: {
1711: my $config=Apache::File->new("$perlvar{'lonTabDir'}/roles.tab");
1712:
1713: while (my $configline=<$config>) {
1714: chomp($configline);
1715: my ($role,$perm)=split(/ /,$configline);
1716: if ($perm ne '') { $pr{$role}=$perm; }
1717: }
1718: }
1719:
1720: # -------------------------------------------- Read plain texts for permissions
1721: {
1722: my $config=Apache::File->new("$perlvar{'lonTabDir'}/rolesplain.tab");
1723:
1724: while (my $configline=<$config>) {
1725: chomp($configline);
1726: my ($short,$plain)=split(/:/,$configline);
1727: if ($plain ne '') { $prp{$short}=$plain; }
1.25 www 1728: }
1729: }
1730:
1731: # ------------------------------------------------------------- Read file types
1732: {
1733: my $config=Apache::File->new("$perlvar{'lonTabDir'}/filetypes.tab");
1734:
1735: while (my $configline=<$config>) {
1736: chomp($configline);
1737: my ($ending,$emb,@descr)=split(/\s+/,$configline);
1738: if ($descr[0] ne '') {
1739: $fe{$ending}=$emb;
1740: $fd{$ending}=join(' ',@descr);
1741: }
1.11 www 1742: }
1743: }
1744:
1.22 www 1745:
1.1 albertel 1746: $readit='done';
1.12 www 1747: &logthis('<font color=yellow>INFO: Read configuration</font>');
1.1 albertel 1748: }
1749: }
1750: 1;
FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>