1: # The LearningOnline Network
2: # TCP networking package
3: #
4: # Functions for use by content handlers:
5: #
6: # plaintext(short) : plain text explanation of short term
7: # fileembstyle(ext) : embed style in page for file extension
8: # filedescription(ext) : descriptor text for file extension
9: # allowed(short,url) : returns codes for allowed actions
10: # F: full access
11: # U,I,K: authentication modes (cxx only)
12: # '': forbidden
13: # 1: user needs to choose course
14: # 2: browse allowed
15: # definerole(rolename,sys,dom,cou) : define a custom role rolename
16: # set priviledges in format of lonTabs/roles.tab for
17: # system, domain and course level,
18: # assignrole(udom,uname,url,role,end,start) : give a role to a user for the
19: # level given by url. Optional start and end dates
20: # (leave empty string or zero for "no date")
21: # assigncustomrole (udom,uname,url,rdom,rnam,rolename,end,start) : give a
22: # custom role to a user for the level given by url.
23: # Specify name and domain of role author, and role name
24: # revokerole (udom,uname,url,role) : Revoke a role for url
25: # revokecustomrole (udom,uname,url,rdom,rnam,rolename) : Revoke a custom role
26: # appenv(hash) : adds hash to session environment
27: # delenv(varname) : deletes all environment entries starting with varname
28: # store(hash) : stores hash permanently for this url
29: # cstore(hash) : critical store
30: # restore : returns hash for this url
31: # eget(namesp,array) : returns hash with keys from array filled in from namesp
32: # get(namesp,array) : returns hash with keys from array filled in from namesp
33: # del(namesp,array) : deletes keys out of array from namesp
34: # put(namesp,hash) : stores hash in namesp
35: # cput(namesp,hash) : critical put
36: # dump(namesp) : dumps the complete namespace into a hash
37: # ssi(url,hash) : does a complete request cycle on url to localhost, posts
38: # hash
39: # coursedescription(id) : returns and caches course description for id
40: # repcopy(filename) : replicate file
41: # dirlist(url) : gets a directory listing
42: # directcondval(index) : reading condition value of single condition from
43: # state string
44: # condval(index) : value of condition index based on state
45: # EXT(name) : value of a variable
46: # symblist(map,hash) : Updates symbolic storage links
47: # symbread([filename]) : returns the data handle (filename optional)
48: # rndseed() : returns a random seed
49: # receipt() : returns a receipt to be given out to users
50: # getfile(filename) : returns the contents of filename, or a -1 if it can't
51: # be found, replicates and subscribes to the file
52: # filelocation(dir,file) : returns a farily clean absolute reference to file
53: # from the directory dir
54: # hreflocation(dir,file) : same as filelocation, but for hrefs
55: # log(domain,user,home,msg) : write to permanent log for user
56: # usection(domain,user,courseid) : output of section name/number or '' for
57: # "not in course" and '-1' for "no section"
58: # userenvironment(domain,user,what) : puts out any environment parameter
59: # for a user
60: # idput(domain,hash) : writes IDs for users from hash (name=>id,name=>id)
61: # idget(domain,array): returns hash with usernames (id=>name,id=>name) for
62: # an array of IDs
63: # idrget(domain,array): returns hash with IDs for usernames (name=>id,...) for
64: # an array of names
65: # metadata(file,entry): returns the metadata entry for a file. entry='keys'
66: # returns a comma separated list of keys
67: #
68: # 6/1/99,6/2,6/10,6/11,6/12,6/14,6/26,6/28,6/29,6/30,
69: # 7/1,7/2,7/9,7/10,7/12,7/14,7/15,7/19,
70: # 11/8,11/16,11/18,11/22,11/23,12/22,
71: # 01/06,01/13,02/24,02/28,02/29,
72: # 03/01,03/02,03/06,03/07,03/13,
73: # 04/05,05/29,05/31,06/01,
74: # 06/05,06/26 Gerd Kortemeyer
75: # 06/26 Ben Tyszka
76: # 06/30,07/15,07/17,07/18,07/20,07/21,07/22,07/25 Gerd Kortemeyer
77: # 08/14 Ben Tyszka
78: # 08/22,08/28,08/31,09/01,09/02,09/04,09/05,09/25,09/28,09/30 Gerd Kortemeyer
79: # 10/04 Gerd Kortemeyer
80: # 10/04 Guy Albertelli
81: # 10/06,10/09,10/10,10/11,10/14,10/20,10/23,10/25,10/26,10/27,10/28,10/29,
82: # 10/30,10/31,
83: # 11/2,11/14,11/15,11/16,11/20,11/21,11/22,11/25,11/27,
84: # 12/02,12/12,12/13,12/14 Gerd Kortemeyer
85:
86: package Apache::lonnet;
87:
88: use strict;
89: use Apache::File;
90: use LWP::UserAgent();
91: use HTTP::Headers;
92: use vars
93: qw(%perlvar %hostname %homecache %spareid %hostdom %libserv %pr %prp %fe %fd $readit %metacache);
94: use IO::Socket;
95: use GDBM_File;
96: use Apache::Constants qw(:common :http);
97: use HTML::TokeParser;
98:
99: # --------------------------------------------------------------------- Logging
100:
101: sub logthis {
102: my $message=shift;
103: my $execdir=$perlvar{'lonDaemons'};
104: my $now=time;
105: my $local=localtime($now);
106: my $fh=Apache::File->new(">>$execdir/logs/lonnet.log");
107: print $fh "$local ($$): $message\n";
108: return 1;
109: }
110:
111: sub logperm {
112: my $message=shift;
113: my $execdir=$perlvar{'lonDaemons'};
114: my $now=time;
115: my $local=localtime($now);
116: my $fh=Apache::File->new(">>$execdir/logs/lonnet.perm.log");
117: print $fh "$now:$message:$local\n";
118: return 1;
119: }
120:
121: # -------------------------------------------------- Non-critical communication
122: sub subreply {
123: my ($cmd,$server)=@_;
124: my $peerfile="$perlvar{'lonSockDir'}/$server";
125: my $client=IO::Socket::UNIX->new(Peer =>"$peerfile",
126: Type => SOCK_STREAM,
127: Timeout => 10)
128: or return "con_lost";
129: print $client "$cmd\n";
130: my $answer=<$client>;
131: if (!$answer) { $answer="con_lost"; }
132: chomp($answer);
133: return $answer;
134: }
135:
136: sub reply {
137: my ($cmd,$server)=@_;
138: my $answer=subreply($cmd,$server);
139: if ($answer eq 'con_lost') { $answer=subreply($cmd,$server); }
140: if (($answer=~/^refused/) || ($answer=~/^rejected/)) {
141: &logthis("<font color=blue>WARNING:".
142: " $cmd to $server returned $answer</font>");
143: }
144: return $answer;
145: }
146:
147: # ----------------------------------------------------------- Send USR1 to lonc
148:
149: sub reconlonc {
150: my $peerfile=shift;
151: &logthis("Trying to reconnect for $peerfile");
152: my $loncfile="$perlvar{'lonDaemons'}/logs/lonc.pid";
153: if (my $fh=Apache::File->new("$loncfile")) {
154: my $loncpid=<$fh>;
155: chomp($loncpid);
156: if (kill 0 => $loncpid) {
157: &logthis("lonc at pid $loncpid responding, sending USR1");
158: kill USR1 => $loncpid;
159: sleep 1;
160: if (-e "$peerfile") { return; }
161: &logthis("$peerfile still not there, give it another try");
162: sleep 5;
163: if (-e "$peerfile") { return; }
164: &logthis(
165: "<font color=blue>WARNING: $peerfile still not there, giving up</font>");
166: } else {
167: &logthis(
168: "<font color=blue>WARNING:".
169: " lonc at pid $loncpid not responding, giving up</font>");
170: }
171: } else {
172: &logthis('<font color=blue>WARNING: lonc not running, giving up</font>');
173: }
174: }
175:
176: # ------------------------------------------------------ Critical communication
177:
178: sub critical {
179: my ($cmd,$server)=@_;
180: my $answer=reply($cmd,$server);
181: if ($answer eq 'con_lost') {
182: my $pingreply=reply('ping',$server);
183: &reconlonc("$perlvar{'lonSockDir'}/$server");
184: my $pongreply=reply('pong',$server);
185: &logthis("Ping/Pong for $server: $pingreply/$pongreply");
186: $answer=reply($cmd,$server);
187: if ($answer eq 'con_lost') {
188: my $now=time;
189: my $middlename=$cmd;
190: $middlename=substr($middlename,0,16);
191: $middlename=~s/\W//g;
192: my $dfilename=
193: "$perlvar{'lonSockDir'}/delayed/$now.$middlename.$server";
194: {
195: my $dfh;
196: if ($dfh=Apache::File->new(">$dfilename")) {
197: print $dfh "$cmd\n";
198: }
199: }
200: sleep 2;
201: my $wcmd='';
202: {
203: my $dfh;
204: if ($dfh=Apache::File->new("$dfilename")) {
205: $wcmd=<$dfh>;
206: }
207: }
208: chomp($wcmd);
209: if ($wcmd eq $cmd) {
210: &logthis("<font color=blue>WARNING: ".
211: "Connection buffer $dfilename: $cmd</font>");
212: &logperm("D:$server:$cmd");
213: return 'con_delayed';
214: } else {
215: &logthis("<font color=red>CRITICAL:"
216: ." Critical connection failed: $server $cmd</font>");
217: &logperm("F:$server:$cmd");
218: return 'con_failed';
219: }
220: }
221: }
222: return $answer;
223: }
224:
225: # ---------------------------------------------------------- Append Environment
226:
227: sub appenv {
228: my %newenv=@_;
229: map {
230: if (($newenv{$_}=~/^user\.role/) || ($newenv{$_}=~/^user\.priv/)) {
231: &logthis("<font color=blue>WARNING: ".
232: "Attempt to modify environment ".$_." to ".$newenv{$_});
233: delete($newenv{$_});
234: } else {
235: $ENV{$_}=$newenv{$_};
236: }
237: } keys %newenv;
238: my @oldenv;
239: {
240: my $fh;
241: unless ($fh=Apache::File->new("$ENV{'user.environment'}")) {
242: return 'error';
243: }
244: @oldenv=<$fh>;
245: }
246: for (my $i=0; $i<=$#oldenv; $i++) {
247: chomp($oldenv[$i]);
248: if ($oldenv[$i] ne '') {
249: my ($name,$value)=split(/=/,$oldenv[$i]);
250: unless (defined($newenv{$name})) {
251: $newenv{$name}=$value;
252: }
253: }
254: }
255: {
256: my $fh;
257: unless ($fh=Apache::File->new(">$ENV{'user.environment'}")) {
258: return 'error';
259: }
260: my $newname;
261: foreach $newname (keys %newenv) {
262: print $fh "$newname=$newenv{$newname}\n";
263: }
264: }
265: return 'ok';
266: }
267: # ----------------------------------------------------- Delete from Environment
268:
269: sub delenv {
270: my $delthis=shift;
271: my %newenv=();
272: if (($delthis=~/user\.role/) || ($delthis=~/user\.priv/)) {
273: &logthis("<font color=blue>WARNING: ".
274: "Attempt to delete from environment ".$delthis);
275: return 'error';
276: }
277: my @oldenv;
278: {
279: my $fh;
280: unless ($fh=Apache::File->new("$ENV{'user.environment'}")) {
281: return 'error';
282: }
283: @oldenv=<$fh>;
284: }
285: {
286: my $fh;
287: unless ($fh=Apache::File->new(">$ENV{'user.environment'}")) {
288: return 'error';
289: }
290: map {
291: unless ($_=~/^$delthis/) { print $fh $_; }
292: } @oldenv;
293: }
294: return 'ok';
295: }
296:
297: # ------------------------------ Find server with least workload from spare.tab
298:
299: sub spareserver {
300: my $tryserver;
301: my $spareserver='';
302: my $lowestserver=100;
303: foreach $tryserver (keys %spareid) {
304: my $answer=reply('load',$tryserver);
305: if (($answer =~ /\d/) && ($answer<$lowestserver)) {
306: $spareserver="http://$hostname{$tryserver}";
307: $lowestserver=$answer;
308: }
309: }
310: return $spareserver;
311: }
312:
313: # --------- Try to authenticate user from domain's lib servers (first this one)
314:
315: sub authenticate {
316: my ($uname,$upass,$udom)=@_;
317: $upass=escape($upass);
318: if (($perlvar{'lonRole'} eq 'library') &&
319: ($udom eq $perlvar{'lonDefDomain'})) {
320: my $answer=reply("encrypt:auth:$udom:$uname:$upass",$perlvar{'lonHostID'});
321: if ($answer =~ /authorized/) {
322: if ($answer eq 'authorized') {
323: &logthis("User $uname at $udom authorized by local server");
324: return $perlvar{'lonHostID'};
325: }
326: if ($answer eq 'non_authorized') {
327: &logthis("User $uname at $udom rejected by local server");
328: return 'no_host';
329: }
330: }
331: }
332:
333: my $tryserver;
334: foreach $tryserver (keys %libserv) {
335: if ($hostdom{$tryserver} eq $udom) {
336: my $answer=reply("encrypt:auth:$udom:$uname:$upass",$tryserver);
337: if ($answer =~ /authorized/) {
338: if ($answer eq 'authorized') {
339: &logthis("User $uname at $udom authorized by $tryserver");
340: return $tryserver;
341: }
342: if ($answer eq 'non_authorized') {
343: &logthis("User $uname at $udom rejected by $tryserver");
344: return 'no_host';
345: }
346: }
347: }
348: }
349: &logthis("User $uname at $udom could not be authenticated");
350: return 'no_host';
351: }
352:
353: # ---------------------- Find the homebase for a user from domain's lib servers
354:
355: sub homeserver {
356: my ($uname,$udom)=@_;
357:
358: my $index="$uname:$udom";
359: if ($homecache{$index}) { return "$homecache{$index}"; }
360:
361: my $tryserver;
362: foreach $tryserver (keys %libserv) {
363: if ($hostdom{$tryserver} eq $udom) {
364: my $answer=reply("home:$udom:$uname",$tryserver);
365: if ($answer eq 'found') {
366: $homecache{$index}=$tryserver;
367: return $tryserver;
368: }
369: }
370: }
371: return 'no_host';
372: }
373:
374: # ------------------------------------- Find the usernames behind a list of IDs
375:
376: sub idget {
377: my ($udom,@ids)=@_;
378: my %returnhash=();
379:
380: my $tryserver;
381: foreach $tryserver (keys %libserv) {
382: if ($hostdom{$tryserver} eq $udom) {
383: my $idlist=join('&',@ids);
384: $idlist=~tr/A-Z/a-z/;
385: my $reply=&reply("idget:$udom:".$idlist,$tryserver);
386: my @answer=();
387: if (($reply ne 'con_lost') && ($reply!~/^error\:/)) {
388: @answer=split(/\&/,$reply);
389: } ;
390: my $i;
391: for ($i=0;$i<=$#ids;$i++) {
392: if ($answer[$i]) {
393: $returnhash{$ids[$i]}=$answer[$i];
394: }
395: }
396: }
397: }
398: return %returnhash;
399: }
400:
401: # ------------------------------------- Find the IDs behind a list of usernames
402:
403: sub idrget {
404: my ($udom,@unames)=@_;
405: my %returnhash=();
406: map {
407: $returnhash{$_}=(&userenvironment($udom,$_,'id'))[1];
408: } @unames;
409: return %returnhash;
410: }
411:
412: # ------------------------------- Store away a list of names and associated IDs
413:
414: sub idput {
415: my ($udom,%ids)=@_;
416: my %servers=();
417: map {
418: my $uhom=&homeserver($_,$udom);
419: if ($uhom ne 'no_host') {
420: my $id=&escape($ids{$_});
421: $id=~tr/A-Z/a-z/;
422: my $unam=&escape($_);
423: if ($servers{$uhom}) {
424: $servers{$uhom}.='&'.$id.'='.$unam;
425: } else {
426: $servers{$uhom}=$id.'='.$unam;
427: }
428: &critical('put:'.$udom.':'.$unam.':environment:id='.$id,$uhom);
429: }
430: } keys %ids;
431: map {
432: &critical('idput:'.$udom.':'.$servers{$_},$_);
433: } keys %servers;
434: }
435:
436: # ------------------------------------- Find the section of student in a course
437:
438: sub usection {
439: my ($udom,$unam,$courseid)=@_;
440: $courseid=~s/\_/\//g;
441: $courseid=~s/^(\w)/\/$1/;
442: map {
443: my ($key,$value)=split(/\=/,$_);
444: $key=&unescape($key);
445: if ($key=~/^$courseid(?:\/)*(\w+)*\_st$/) {
446: my $section=$1;
447: if ($key eq $courseid.'_st') { $section=''; }
448: my ($dummy,$end,$start)=split(/\_/,&unescape($value));
449: my $now=time;
450: my $notactive=0;
451: if ($start) {
452: if ($now<$start) { $notactive=1; }
453: }
454: if ($end) {
455: if ($now>$end) { $notactive=1; }
456: }
457: unless ($notactive) { return $section; }
458: }
459: } split(/\&/,&reply('dump:'.$udom.':'.$unam.':roles',
460: &homeserver($unam,$udom)));
461: return '-1';
462: }
463:
464: # ------------------------------------- Read an entry from a user's environment
465:
466: sub userenvironment {
467: my ($udom,$unam,@what)=@_;
468: my %returnhash=();
469: my @answer=split(/\&/,
470: &reply('get:'.$udom.':'.$unam.':environment:'.join('&',@what),
471: &homeserver($unam,$udom)));
472: my $i;
473: for ($i=0;$i<=$#what;$i++) {
474: $returnhash{$what[$i]}=&unescape($answer[$i]);
475: }
476: return %returnhash;
477: }
478:
479: # ----------------------------- Subscribe to a resource, return URL if possible
480:
481: sub subscribe {
482: my $fname=shift;
483: my $author=$fname;
484: $author=~s/\/home\/httpd\/html\/res\/([^\/]*)\/([^\/]*).*/$1\/$2/;
485: my ($udom,$uname)=split(/\//,$author);
486: my $home=homeserver($uname,$udom);
487: if (($home eq 'no_host') || ($home eq $perlvar{'lonHostID'})) {
488: return 'not_found';
489: }
490: my $answer=reply("sub:$fname",$home);
491: if (($answer eq 'con_lost') || ($answer eq 'rejected')) {
492: $answer.=' by '.$home;
493: }
494: return $answer;
495: }
496:
497: # -------------------------------------------------------------- Replicate file
498:
499: sub repcopy {
500: my $filename=shift;
501: $filename=~s/\/+/\//g;
502: my $transname="$filename.in.transfer";
503: if ((-e $filename) || (-e $transname)) { return OK; }
504: my $remoteurl=subscribe($filename);
505: if ($remoteurl =~ /^con_lost by/) {
506: &logthis("Subscribe returned $remoteurl: $filename");
507: return HTTP_SERVICE_UNAVAILABLE;
508: } elsif ($remoteurl eq 'not_found') {
509: &logthis("Subscribe returned not_found: $filename");
510: return HTTP_NOT_FOUND;
511: } elsif ($remoteurl =~ /^rejected by/) {
512: &logthis("Subscribe returned $remoteurl: $filename");
513: return FORBIDDEN;
514: } elsif ($remoteurl eq 'directory') {
515: return OK;
516: } else {
517: my @parts=split(/\//,$filename);
518: my $path="/$parts[1]/$parts[2]/$parts[3]/$parts[4]";
519: if ($path ne "$perlvar{'lonDocRoot'}/res") {
520: &logthis("Malconfiguration for replication: $filename");
521: return HTTP_BAD_REQUEST;
522: }
523: my $count;
524: for ($count=5;$count<$#parts;$count++) {
525: $path.="/$parts[$count]";
526: if ((-e $path)!=1) {
527: mkdir($path,0777);
528: }
529: }
530: my $ua=new LWP::UserAgent;
531: my $request=new HTTP::Request('GET',"$remoteurl");
532: my $response=$ua->request($request,$transname);
533: if ($response->is_error()) {
534: unlink($transname);
535: my $message=$response->status_line;
536: &logthis("<font color=blue>WARNING:"
537: ." LWP get: $message: $filename</font>");
538: return HTTP_SERVICE_UNAVAILABLE;
539: } else {
540: if ($remoteurl!~/\.meta$/) {
541: my $mrequest=new HTTP::Request('GET',$remoteurl.'.meta');
542: my $mresponse=$ua->request($mrequest,$filename.'.meta');
543: if ($mresponse->is_error()) {
544: unlink($filename.'.meta');
545: &logthis(
546: "<font color=yellow>INFO: No metadata: $filename</font>");
547: }
548: }
549: rename($transname,$filename);
550: return OK;
551: }
552: }
553: }
554:
555: # --------------------------------------------------------- Server Side Include
556:
557: sub ssi {
558:
559: my ($fn,%form)=@_;
560:
561: my $ua=new LWP::UserAgent;
562:
563: my $request;
564:
565: if (%form) {
566: $request=new HTTP::Request('POST',"http://".$ENV{'HTTP_HOST'}.$fn);
567: $request->content(join '&', map { "$_=$form{$_}" } keys %form);
568: } else {
569: $request=new HTTP::Request('GET',"http://".$ENV{'HTTP_HOST'}.$fn);
570: }
571:
572: $request->header(Cookie => $ENV{'HTTP_COOKIE'});
573: my $response=$ua->request($request);
574:
575: return $response->content;
576: }
577:
578: # ------------------------------------------------------------------------- Log
579:
580: sub log {
581: my ($dom,$nam,$hom,$what)=@_;
582: return critical("log:$dom:$nam:$what",$hom);
583: }
584:
585: # ----------------------------------------------------------------------- Store
586:
587: sub store {
588: my %storehash=@_;
589: my $symb;
590: unless ($symb=escape(&symbread())) { return ''; }
591: my $namespace;
592: unless ($namespace=$ENV{'request.course.id'}) { return ''; }
593: my $namevalue='';
594: map {
595: $namevalue.=escape($_).'='.escape($storehash{$_}).'&';
596: } keys %storehash;
597: $namevalue=~s/\&$//;
598: return reply(
599: "store:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$symb:$namevalue",
600: "$ENV{'user.home'}");
601: }
602:
603: # -------------------------------------------------------------- Critical Store
604:
605: sub cstore {
606: my %storehash=@_;
607: my $symb;
608: unless ($symb=escape(&symbread())) { return ''; }
609: my $namespace;
610: unless ($namespace=$ENV{'request.course.id'}) { return ''; }
611: my $namevalue='';
612: map {
613: $namevalue.=escape($_).'='.escape($storehash{$_}).'&';
614: } keys %storehash;
615: $namevalue=~s/\&$//;
616: return critical(
617: "store:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$symb:$namevalue",
618: "$ENV{'user.home'}");
619: }
620:
621: # --------------------------------------------------------------------- Restore
622:
623: sub restore {
624: my $symb;
625: unless ($symb=escape(&symbread())) { return ''; }
626: my $namespace;
627: unless ($namespace=$ENV{'request.course.id'}) { return ''; }
628: my $answer=reply(
629: "restore:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$symb",
630: "$ENV{'user.home'}");
631: my %returnhash=();
632: map {
633: my ($name,$value)=split(/\=/,$_);
634: $returnhash{&unescape($name)}=&unescape($value);
635: } split(/\&/,$answer);
636: my $version;
637: for ($version=1;$version<=$returnhash{'version'};$version++) {
638: map {
639: $returnhash{$_}=$returnhash{$version.':'.$_};
640: } split(/\:/,$returnhash{$version.':keys'});
641: }
642: return %returnhash;
643: }
644:
645: # ---------------------------------------------------------- Course Description
646:
647: sub coursedescription {
648: my $courseid=shift;
649: $courseid=~s/^\///;
650: $courseid=~s/\_/\//g;
651: my ($cdomain,$cnum)=split(/\//,$courseid);
652: my $chome=homeserver($cnum,$cdomain);
653: if ($chome ne 'no_host') {
654: my $rep=reply("dump:$cdomain:$cnum:environment",$chome);
655: if ($rep ne 'con_lost') {
656: my $normalid=$courseid;
657: $normalid=~s/\//\_/g;
658: my %envhash=();
659: my %returnhash=('home' => $chome,
660: 'domain' => $cdomain,
661: 'num' => $cnum);
662: map {
663: my ($name,$value)=split(/\=/,$_);
664: $name=&unescape($name);
665: $value=&unescape($value);
666: $returnhash{$name}=$value;
667: $envhash{'course.'.$normalid.'.'.$name}=$value;
668: } split(/\&/,$rep);
669: $returnhash{'url'}='/res/'.declutter($returnhash{'url'});
670: $returnhash{'fn'}=$perlvar{'lonDaemons'}.'/tmp/'.
671: $ENV{'user.name'}.'_'.$cdomain.'_'.$cnum;
672: $envhash{'course.'.$normalid.'.last_cache'}=time;
673: $envhash{'course.'.$normalid.'.home'}=$chome;
674: $envhash{'course.'.$normalid.'.domain'}=$cdomain;
675: $envhash{'course.'.$normalid.'.num'}=$cnum;
676: &appenv(%envhash);
677: return %returnhash;
678: }
679: }
680: return ();
681: }
682:
683: # -------------------------------------------------------- Get user priviledges
684:
685: sub rolesinit {
686: my ($domain,$username,$authhost)=@_;
687: my $rolesdump=reply("dump:$domain:$username:roles",$authhost);
688: if (($rolesdump eq 'con_lost') || ($rolesdump eq '')) { return ''; }
689: my %allroles=();
690: my %thesepriv=();
691: my $now=time;
692: my $userroles="user.login.time=$now\n";
693: my $thesestr;
694:
695: if ($rolesdump ne '') {
696: map {
697: if ($_!~/^rolesdef\&/) {
698: my ($area,$role)=split(/=/,$_);
699: $area=~s/\_\w\w$//;
700: my ($trole,$tend,$tstart)=split(/_/,$role);
701: $userroles.='user.role.'.$trole.'.'.$area.'='.
702: $tstart.'.'.$tend."\n";
703: if ($tend!=0) {
704: if ($tend<$now) {
705: $trole='';
706: }
707: }
708: if ($tstart!=0) {
709: if ($tstart>$now) {
710: $trole='';
711: }
712: }
713: if (($area ne '') && ($trole ne '')) {
714: my $spec=$trole.'.'.$area;
715: my ($tdummy,$tdomain,$trest)=split(/\//,$area);
716: if ($trole =~ /^cr\//) {
717: my ($rdummy,$rdomain,$rauthor,$rrole)=split(/\//,$trole);
718: my $homsvr=homeserver($rauthor,$rdomain);
719: if ($hostname{$homsvr} ne '') {
720: my $roledef=
721: reply("get:$rdomain:$rauthor:roles:rolesdef_$rrole",
722: $homsvr);
723: if (($roledef ne 'con_lost') && ($roledef ne '')) {
724: my ($syspriv,$dompriv,$coursepriv)=
725: split(/\_/,unescape($roledef));
726: $allroles{'cm./'}.=':'.$syspriv;
727: $allroles{$spec.'./'}.=':'.$syspriv;
728: if ($tdomain ne '') {
729: $allroles{'cm./'.$tdomain.'/'}.=':'.$dompriv;
730: $allroles{$spec.'./'.$tdomain.'/'}.=':'.$dompriv;
731: if ($trest ne '') {
732: $allroles{'cm.'.$area}.=':'.$coursepriv;
733: $allroles{$spec.'.'.$area}.=':'.$coursepriv;
734: }
735: }
736: }
737: }
738: } else {
739: $allroles{'cm./'}.=':'.$pr{$trole.':s'};
740: $allroles{$spec.'./'}.=':'.$pr{$trole.':s'};
741: if ($tdomain ne '') {
742: $allroles{'cm./'.$tdomain.'/'}.=':'.$pr{$trole.':d'};
743: $allroles{$spec.'./'.$tdomain.'/'}.=':'.$pr{$trole.':d'};
744: if ($trest ne '') {
745: $allroles{'cm.'.$area}.=':'.$pr{$trole.':c'};
746: $allroles{$spec.'.'.$area}.=':'.$pr{$trole.':c'};
747: }
748: }
749: }
750: }
751: }
752: } split(/&/,$rolesdump);
753: map {
754: %thesepriv=();
755: map {
756: if ($_ ne '') {
757: my ($priviledge,$restrictions)=split(/&/,$_);
758: if ($restrictions eq '') {
759: $thesepriv{$priviledge}='F';
760: } else {
761: if ($thesepriv{$priviledge} ne 'F') {
762: $thesepriv{$priviledge}.=$restrictions;
763: }
764: }
765: }
766: } split(/:/,$allroles{$_});
767: $thesestr='';
768: map { $thesestr.=':'.$_.'&'.$thesepriv{$_}; } keys %thesepriv;
769: $userroles.='user.priv.'.$_.'='.$thesestr."\n";
770: } keys %allroles;
771: }
772: return $userroles;
773: }
774:
775: # --------------------------------------------------------------- get interface
776:
777: sub get {
778: my ($namespace,@storearr)=@_;
779: my $items='';
780: map {
781: $items.=escape($_).'&';
782: } @storearr;
783: $items=~s/\&$//;
784: my $rep=reply("get:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
785: $ENV{'user.home'});
786: my @pairs=split(/\&/,$rep);
787: my %returnhash=();
788: my $i=0;
789: map {
790: $returnhash{$_}=unescape($pairs[$i]);
791: $i++;
792: } @storearr;
793: return %returnhash;
794: }
795:
796: # --------------------------------------------------------------- del interface
797:
798: sub del {
799: my ($namespace,@storearr)=@_;
800: my $items='';
801: map {
802: $items.=escape($_).'&';
803: } @storearr;
804: $items=~s/\&$//;
805: return reply("del:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
806: $ENV{'user.home'});
807: }
808:
809: # -------------------------------------------------------------- dump interface
810:
811: sub dump {
812: my $namespace=shift;
813: my $rep=reply("dump:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace",
814: $ENV{'user.home'});
815: my @pairs=split(/\&/,$rep);
816: my %returnhash=();
817: map {
818: my ($key,$value)=split(/=/,$_);
819: $returnhash{unescape($key)}=unescape($value);
820: } @pairs;
821: return %returnhash;
822: }
823:
824: # --------------------------------------------------------------- put interface
825:
826: sub put {
827: my ($namespace,%storehash)=@_;
828: my $items='';
829: map {
830: $items.=escape($_).'='.escape($storehash{$_}).'&';
831: } keys %storehash;
832: $items=~s/\&$//;
833: return reply("put:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
834: $ENV{'user.home'});
835: }
836:
837: # ------------------------------------------------------ critical put interface
838:
839: sub cput {
840: my ($namespace,%storehash)=@_;
841: my $items='';
842: map {
843: $items.=escape($_).'='.escape($storehash{$_}).'&';
844: } keys %storehash;
845: $items=~s/\&$//;
846: return critical
847: ("put:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
848: $ENV{'user.home'});
849: }
850:
851: # -------------------------------------------------------------- eget interface
852:
853: sub eget {
854: my ($namespace,@storearr)=@_;
855: my $items='';
856: map {
857: $items.=escape($_).'&';
858: } @storearr;
859: $items=~s/\&$//;
860: my $rep=reply("eget:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace:$items",
861: $ENV{'user.home'});
862: my @pairs=split(/\&/,$rep);
863: my %returnhash=();
864: my $i=0;
865: map {
866: $returnhash{$_}=unescape($pairs[$i]);
867: $i++;
868: } @storearr;
869: return %returnhash;
870: }
871:
872: # ------------------------------------------------- Check for a user priviledge
873:
874: sub allowed {
875: my ($priv,$uri)=@_;
876: $uri=&declutter($uri);
877:
878: # Free bre access to adm and meta resources
879:
880: if ((($uri=~/^adm\//) || ($uri=~/\.meta$/)) && ($priv eq 'bre')) {
881: return 'F';
882: }
883:
884: my $thisallowed='';
885: my $statecond=0;
886: my $courseprivid='';
887:
888: # Course
889:
890: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'}=~/$priv\&([^\:]*)/) {
891: $thisallowed.=$1;
892: }
893:
894: # Domain
895:
896: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'.(split(/\//,$uri))[0].'/'}
897: =~/$priv\&([^\:]*)/) {
898: $thisallowed.=$1;
899: }
900:
901: # Course: uri itself is a course
902: my $courseuri=$uri;
903: $courseuri=~s/\_(\d)/\/$1/;
904:
905: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'.$courseuri}
906: =~/$priv\&([^\:]*)/) {
907: $thisallowed.=$1;
908: }
909:
910: # Full access at system, domain or course-wide level? Exit.
911:
912: if ($thisallowed=~/F/) {
913: return 'F';
914: }
915:
916: # If this is generating or modifying users, exit with special codes
917:
918: if (':csu:cdc:ccc:cin:cta:cep:ccr:cst:cad:cli:cau:cdg:'=~/\:$priv\:/) {
919: return $thisallowed;
920: }
921: #
922: # Gathered so far: system, domain and course wide priviledges
923: #
924: # Course: See if uri or referer is an individual resource that is part of
925: # the course
926:
927: if ($ENV{'request.course.id'}) {
928: $courseprivid=$ENV{'request.course.id'};
929: if ($ENV{'request.course.sec'}) {
930: $courseprivid.='/'.$ENV{'request.course.sec'};
931: }
932: $courseprivid=~s/\_/\//;
933: my $checkreferer=1;
934: my @uriparts=split(/\//,$uri);
935: my $filename=$uriparts[$#uriparts];
936: my $pathname=$uri;
937: $pathname=~s/\/$filename$//;
938: if ($ENV{'acc.res.'.$ENV{'request.course.id'}.'.'.$pathname}=~
939: /\&$filename\:([\d\|]+)\&/) {
940: $statecond=$1;
941: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'.$courseprivid}
942: =~/$priv\&([^\:]*)/) {
943: $thisallowed.=$1;
944: $checkreferer=0;
945: }
946: }
947:
948: if (($ENV{'HTTP_REFERER'}) && ($checkreferer)) {
949: my $refuri=$ENV{'HTTP_REFERER'};
950: $refuri=~s/^http\:\/\/$ENV{'request.host'}//i;
951: $refuri=&declutter($refuri);
952: my @uriparts=split(/\//,$refuri);
953: my $filename=$uriparts[$#uriparts];
954: my $pathname=$refuri;
955: $pathname=~s/\/$filename$//;
956: my @filenameparts=split(/\./,$uri);
957: if (&fileembstyle($filenameparts[$#filenameparts]) ne 'ssi') {
958: if ($ENV{'acc.res.'.$ENV{'request.course.id'}.'.'.$pathname}=~
959: /\&$filename\:([\d\|]+)\&/) {
960: my $refstatecond=$1;
961: if ($ENV{'user.priv.'.$ENV{'request.role'}.'./'.$courseprivid}
962: =~/$priv\&([^\:]*)/) {
963: $thisallowed.=$1;
964: $uri=$refuri;
965: $statecond=$refstatecond;
966: }
967: }
968: }
969: }
970: }
971:
972: #
973: # Gathered now: all priviledges that could apply, and condition number
974: #
975: #
976: # Full or no access?
977: #
978:
979: if ($thisallowed=~/F/) {
980: return 'F';
981: }
982:
983: unless ($thisallowed) {
984: return '';
985: }
986:
987: # Restrictions exist, deal with them
988: #
989: # C:according to course preferences
990: # R:according to resource settings
991: # L:unless locked
992: # X:according to user session state
993: #
994:
995: # Possibly locked functionality, check all courses
996: # Locks might take effect only after 10 minutes cache expiration for other
997: # courses, and 2 minutes for current course
998:
999: my $envkey;
1000: if ($thisallowed=~/L/) {
1001: foreach $envkey (keys %ENV) {
1002: if ($envkey=~/^user\.role\.(st|ta)\.([^\.]*)/) {
1003: my $courseid=$2;
1004: my $roleid=$1.'.'.$2;
1005: my $expiretime=600;
1006: if ($ENV{'request.role'} eq $roleid) {
1007: $expiretime=120;
1008: }
1009: my ($cdom,$cnum,$csec)=split(/\//,$courseid);
1010: my $prefix='course.'.$cdom.'_'.$cnum.'.';
1011: if ((time-$ENV{$prefix.'last_cache'})>$expiretime) {
1012: &coursedescription($courseid);
1013: }
1014: if (($ENV{$prefix.'res.'.$uri.'.lock.sections'}=~/\,$csec\,/)
1015: || ($ENV{$prefix.'res.'.$uri.'.lock.sections'} eq 'all')) {
1016: if ($ENV{$prefix.'res.'.$uri.'.lock.expire'}>time) {
1017: &log($ENV{'user.domain'},$ENV{'user.name'},
1018: $ENV{'user.host'},
1019: 'Locked by res: '.$priv.' for '.$uri.' due to '.
1020: $cdom.'/'.$cnum.'/'.$csec.' expire '.
1021: $ENV{$prefix.'priv.'.$priv.'.lock.expire'});
1022: return '';
1023: }
1024: }
1025: if (($ENV{$prefix.'priv.'.$priv.'.lock.sections'}=~/\,$csec\,/)
1026: || ($ENV{$prefix.'priv.'.$priv.'.lock.sections'} eq 'all')) {
1027: if ($ENV{'priv.'.$priv.'.lock.expire'}>time) {
1028: &log($ENV{'user.domain'},$ENV{'user.name'},
1029: $ENV{'user.host'},
1030: 'Locked by priv: '.$priv.' for '.$uri.' due to '.
1031: $cdom.'/'.$cnum.'/'.$csec.' expire '.
1032: $ENV{$prefix.'priv.'.$priv.'.lock.expire'});
1033: return '';
1034: }
1035: }
1036: }
1037: }
1038: }
1039:
1040: #
1041: # Rest of the restrictions depend on selected course
1042: #
1043:
1044: unless ($ENV{'request.course.id'}) {
1045: return '1';
1046: }
1047:
1048: #
1049: # Now user is definitely in a course
1050: #
1051:
1052:
1053: # Course preferences
1054:
1055: if ($thisallowed=~/C/) {
1056: my $rolecode=(split(/\./,$ENV{'request.role'}))[0];
1057: if ($ENV{'course.'.$ENV{'request.course.id'}.'.'.$priv.'.roles.denied'}
1058: =~/\,$rolecode\,/) {
1059: &log($ENV{'user.domain'},$ENV{'user.name'},$ENV{'user.host'},
1060: 'Denied by role: '.$priv.' for '.$uri.' as '.$rolecode.' in '.
1061: $ENV{'request.course.id'});
1062: return '';
1063: }
1064: }
1065:
1066: # Resource preferences
1067:
1068: if ($thisallowed=~/R/) {
1069: my $rolecode=(split(/\./,$ENV{'request.role'}))[0];
1070: my $filename=$perlvar{'lonDocRoot'}.'/res/'.$uri.'.meta';
1071: if (-e $filename) {
1072: my @content;
1073: {
1074: my $fh=Apache::File->new($filename);
1075: @content=<$fh>;
1076: }
1077: if (join('',@content)=~
1078: /\<roledeny[^\>]*\>[^\<]*$rolecode[^\<]*\<\/roledeny\>/) {
1079: &log($ENV{'user.domain'},$ENV{'user.name'},$ENV{'user.host'},
1080: 'Denied by role: '.$priv.' for '.$uri.' as '.$rolecode);
1081: return '';
1082:
1083: }
1084: }
1085: }
1086:
1087: # Restricted by state?
1088:
1089: if ($thisallowed=~/X/) {
1090: if (&condval($statecond)) {
1091: return '2';
1092: } else {
1093: return '';
1094: }
1095: }
1096:
1097: return 'F';
1098: }
1099:
1100: # ----------------------------------------------------------------- Define Role
1101:
1102: sub definerole {
1103: if (allowed('mcr','/')) {
1104: my ($rolename,$sysrole,$domrole,$courole)=@_;
1105: map {
1106: my ($crole,$cqual)=split(/\&/,$_);
1107: if ($pr{'cr:s'}!~/$crole/) { return "refused:s:$crole"; }
1108: if ($pr{'cr:s'}=~/$crole\&/) {
1109: if ($pr{'cr:s'}!~/$crole\&\w*$cqual/) {
1110: return "refused:s:$crole&$cqual";
1111: }
1112: }
1113: } split('/',$sysrole);
1114: map {
1115: my ($crole,$cqual)=split(/\&/,$_);
1116: if ($pr{'cr:d'}!~/$crole/) { return "refused:d:$crole"; }
1117: if ($pr{'cr:d'}=~/$crole\&/) {
1118: if ($pr{'cr:d'}!~/$crole\&\w*$cqual/) {
1119: return "refused:d:$crole&$cqual";
1120: }
1121: }
1122: } split('/',$domrole);
1123: map {
1124: my ($crole,$cqual)=split(/\&/,$_);
1125: if ($pr{'cr:c'}!~/$crole/) { return "refused:c:$crole"; }
1126: if ($pr{'cr:c'}=~/$crole\&/) {
1127: if ($pr{'cr:c'}!~/$crole\&\w*$cqual/) {
1128: return "refused:c:$crole&$cqual";
1129: }
1130: }
1131: } split('/',$courole);
1132: my $command="encrypt:rolesput:$ENV{'user.domain'}:$ENV{'user.name'}:".
1133: "$ENV{'user.domain'}:$ENV{'user.name'}:".
1134: "rolesdef_$rolename=".
1135: escape($sysrole.'_'.$domrole.'_'.$courole);
1136: return reply($command,$ENV{'user.home'});
1137: } else {
1138: return 'refused';
1139: }
1140: }
1141:
1142: # ------------------------------------------------------------------ Plain Text
1143:
1144: sub plaintext {
1145: my $short=shift;
1146: return $prp{$short};
1147: }
1148:
1149: # ------------------------------------------------------------------ Plain Text
1150:
1151: sub fileembstyle {
1152: my $ending=shift;
1153: return $fe{$ending};
1154: }
1155:
1156: # ------------------------------------------------------------ Description Text
1157:
1158: sub filedescription {
1159: my $ending=shift;
1160: return $fd{$ending};
1161: }
1162:
1163: # ----------------------------------------------------------------- Assign Role
1164:
1165: sub assignrole {
1166: my ($udom,$uname,$url,$role,$end,$start)=@_;
1167: my $mrole;
1168: $url=declutter($url);
1169: if ($role =~ /^cr\//) {
1170: unless (&allowed('ccr',$url)) { return 'refused'; }
1171: $mrole='cr';
1172: } else {
1173: unless (&allowed('c'.$role,$url)) { return 'refused'; }
1174: $mrole=$role;
1175: }
1176: my $command="encrypt:rolesput:$ENV{'user.domain'}:$ENV{'user.name'}:".
1177: "$udom:$uname:$url".'_'."$mrole=$role";
1178: if ($end) { $command.='_'.$end; }
1179: if ($start) {
1180: if ($end) {
1181: $command.='_'.$start;
1182: } else {
1183: $command.='_0_'.$start;
1184: }
1185: }
1186: return &reply($command,&homeserver($uname,$udom));
1187: }
1188:
1189: # --------------------------------------------------------------- Modify a user
1190:
1191:
1192: sub modifyuser {
1193: my ($udom,$uname,$uid,$umode,$upass,$first,$middle,$last,$gene)=@_;
1194: &logthis('Call to modify user '.$udom.', '.$uname.', '.$uid.', '.
1195: $umode.', '.$first.', '.$middle.', '.
1196: $last.', '.$gene.' by '.
1197: $ENV{'user.name'}.' at '.$ENV{'user.domain'});
1198: my $uhome=&homeserver($uname,$udom);
1199: # ----------------------------------------------------------------- Create User
1200: if (($uhome eq 'no_host') && ($umode) && ($upass)) {
1201: my $unhome='';
1202: if ($ENV{'course.'.$ENV{'request.course.id'}.'.domain'} eq $udom) {
1203: $unhome=$ENV{'course.'.$ENV{'request.course.id'}.'.home'};
1204: } else {
1205: my $tryserver;
1206: my $loadm=10000000;
1207: foreach $tryserver (keys %libserv) {
1208: if ($hostdom{$tryserver} eq $udom) {
1209: my $answer=reply('load',$tryserver);
1210: if (($answer=~/\d+/) && ($answer<$loadm)) {
1211: $loadm=$answer;
1212: $unhome=$tryserver;
1213: }
1214: }
1215: }
1216: }
1217: if (($unhome eq '') || ($unhome eq 'no_host')) {
1218: return 'error: find home';
1219: }
1220: my $reply=&reply('encrypt:makeuser:'.$udom.':'.$uname.':'.$umode.':'.
1221: &escape($upass),$unhome);
1222: unless ($reply eq 'ok') {
1223: return 'error: '.$reply;
1224: }
1225: $uhome=&homeserver($uname,$udom);
1226: if (($uhome eq '') || ($uhome eq 'no_host') || ($uhome ne $unhome)) {
1227: return 'error: verify home';
1228: }
1229: }
1230: # ---------------------------------------------------------------------- Add ID
1231: if ($uid) {
1232: $uid=~tr/A-Z/a-z/;
1233: my %uidhash=&idrget($udom,$uname);
1234: if (($uidhash{$uname}) && ($uidhash{$uname}!~/error\:/)) {
1235: unless ($uid eq $uidhash{$uname}) {
1236: return 'error: mismatch '.$uidhash{$uname}.' versus '.$uid;
1237: }
1238: } else {
1239: &idput($udom,($uname => $uid));
1240: }
1241: }
1242: # -------------------------------------------------------------- Add names, etc
1243: my $names=&reply('get:'.$udom.':'.$uname.
1244: ':environment:firstname&middlename&lastname&generation',
1245: $uhome);
1246: my ($efirst,$emiddle,$elast,$egene)=split(/\&/,$names);
1247: if ($first) { $efirst = &escape($first); }
1248: if ($middle) { $emiddle = &escape($middle); }
1249: if ($last) { $elast = &escape($last); }
1250: if ($gene) { $egene = &escape($gene); }
1251: my $reply=&reply('put:'.$udom.':'.$uname.
1252: ':environment:firstname='.$efirst.
1253: '&middlename='.$emiddle.
1254: '&lastname='.$elast.
1255: '&generation='.$egene,$uhome);
1256: if ($reply ne 'ok') {
1257: return 'error: '.$reply;
1258: }
1259: &logthis('Success modifying user '.$udom.', '.$uname.', '.$uid.', '.
1260: $umode.', '.$first.', '.$middle.', '.
1261: $last.', '.$gene.' by '.
1262: $ENV{'user.name'}.' at '.$ENV{'user.domain'});
1263: return 'ok';
1264: }
1265:
1266: # -------------------------------------------------------------- Modify student
1267:
1268: sub modifystudent {
1269: my ($udom,$uname,$uid,$umode,$upass,$first,$middle,$last,$gene,$usec,
1270: $end,$start)=@_;
1271: my $cid='';
1272: unless ($cid=$ENV{'request.course.id'}) {
1273: return 'not_in_class';
1274: }
1275: # --------------------------------------------------------------- Make the user
1276: my $reply=&modifyuser
1277: ($udom,$uname,$uid,$umode,$upass,$first,$middle,$last,$gene);
1278: unless ($reply eq 'ok') { return $reply; }
1279: my $uhome=&homeserver($uname,$udom);
1280: if (($uhome eq '') || ($uhome eq 'no_host')) {
1281: return 'error: no such user';
1282: }
1283: # -------------------------------------------------- Add student to course list
1284: my $reply=critical('put:'.$ENV{'course.'.$cid.'.domain'}.':'.
1285: $ENV{'course.'.$cid.'.num'}.':classlist:'.
1286: &escape($uname.':'.$udom).'='.
1287: &escape($end.':'.$start),
1288: $ENV{'course.'.$cid.'.home'});
1289: unless (($reply eq 'ok') || ($reply eq 'delayed')) {
1290: return 'error: '.$reply;
1291: }
1292: # ---------------------------------------------------- Add student role to user
1293: my $uurl=$cid;
1294: $uurl=~s/\_/\//g;
1295: if ($usec) {
1296: $uurl.='/'.$usec;
1297: }
1298: return &assignrole($udom,$uname,$uurl,'st',$end,$start);
1299: }
1300:
1301: # ---------------------------------------------------------- Assign Custom Role
1302:
1303: sub assigncustomrole {
1304: my ($udom,$uname,$url,$rdom,$rnam,$rolename,$end,$start)=@_;
1305: return &assignrole($udom,$uname,$url,'cr/'.$rdom.'/'.$rnam.'/'.$rolename,
1306: $end,$start);
1307: }
1308:
1309: # ----------------------------------------------------------------- Revoke Role
1310:
1311: sub revokerole {
1312: my ($udom,$uname,$url,$role)=@_;
1313: my $now=time;
1314: return &assignrole($udom,$uname,$url,$role,$now);
1315: }
1316:
1317: # ---------------------------------------------------------- Revoke Custom Role
1318:
1319: sub revokecustomrole {
1320: my ($udom,$uname,$url,$rdom,$rnam,$rolename)=@_;
1321: my $now=time;
1322: return &assigncustomrole($udom,$uname,$url,$rdom,$rnam,$rolename,$now);
1323: }
1324:
1325: # ------------------------------------------------------------ Directory lister
1326:
1327: sub dirlist {
1328: my $uri=shift;
1329: $uri=~s/^\///;
1330: $uri=~s/\/$//;
1331: my ($res,$udom,$uname,@rest)=split(/\//,$uri);
1332: if ($udom) {
1333: if ($uname) {
1334: my $listing=reply('ls:'.$perlvar{'lonDocRoot'}.'/'.$uri,
1335: homeserver($uname,$udom));
1336: return split(/:/,$listing);
1337: } else {
1338: my $tryserver;
1339: my %allusers=();
1340: foreach $tryserver (keys %libserv) {
1341: if ($hostdom{$tryserver} eq $udom) {
1342: my $listing=reply('ls:'.$perlvar{'lonDocRoot'}.'/res/'.$udom,
1343: $tryserver);
1344: if (($listing ne 'no_such_dir') && ($listing ne 'empty')
1345: && ($listing ne 'con_lost')) {
1346: map {
1347: my ($entry,@stat)=split(/&/,$_);
1348: $allusers{$entry}=1;
1349: } split(/:/,$listing);
1350: }
1351: }
1352: }
1353: my $alluserstr='';
1354: map {
1355: $alluserstr.=$_.'&user:';
1356: } sort keys %allusers;
1357: $alluserstr=~s/:$//;
1358: return split(/:/,$alluserstr);
1359: }
1360: } else {
1361: my $tryserver;
1362: my %alldom=();
1363: foreach $tryserver (keys %libserv) {
1364: $alldom{$hostdom{$tryserver}}=1;
1365: }
1366: my $alldomstr='';
1367: map {
1368: $alldomstr.=$perlvar{'lonDocRoot'}.'/res/'.$_.'&domain:';
1369: } sort keys %alldom;
1370: $alldomstr=~s/:$//;
1371: return split(/:/,$alldomstr);
1372: }
1373: }
1374:
1375: # -------------------------------------------------------- Value of a Condition
1376:
1377: sub directcondval {
1378: my $number=shift;
1379: if ($ENV{'user.state.'.$ENV{'request.course.id'}}) {
1380: return substr($ENV{'user.state.'.$ENV{'request.course.id'}},$number,1);
1381: } else {
1382: return 2;
1383: }
1384: }
1385:
1386: sub condval {
1387: my $condidx=shift;
1388: my $result=0;
1389: my $allpathcond='';
1390: map {
1391: if (defined($ENV{'acc.cond.'.$ENV{'request.course.id'}.'.'.$_})) {
1392: $allpathcond.=
1393: '('.$ENV{'acc.cond.'.$ENV{'request.course.id'}.'.'.$_}.')|';
1394: }
1395: } split(/\|/,$condidx);
1396: $allpathcond=~s/\|$//;
1397: if ($ENV{'request.course.id'}) {
1398: if ($allpathcond) {
1399: my $operand='|';
1400: my @stack;
1401: map {
1402: if ($_ eq '(') {
1403: push @stack,($operand,$result)
1404: } elsif ($_ eq ')') {
1405: my $before=pop @stack;
1406: if (pop @stack eq '&') {
1407: $result=$result>$before?$before:$result;
1408: } else {
1409: $result=$result>$before?$result:$before;
1410: }
1411: } elsif (($_ eq '&') || ($_ eq '|')) {
1412: $operand=$_;
1413: } else {
1414: my $new=directcondval($_);
1415: if ($operand eq '&') {
1416: $result=$result>$new?$new:$result;
1417: } else {
1418: $result=$result>$new?$result:$new;
1419: }
1420: }
1421: } ($allpathcond=~/(\d+|\(|\)|\&|\|)/g);
1422: }
1423: }
1424: return $result;
1425: }
1426:
1427: # --------------------------------------------------------- Value of a Variable
1428:
1429: sub EXT {
1430: my $varname=shift;
1431: unless ($varname) { return ''; }
1432: my ($realm,$space,$qualifier,@therest)=split(/\./,$varname);
1433: my $rest;
1434: if ($therest[0]) {
1435: $rest=join('.',@therest);
1436: } else {
1437: $rest='';
1438: }
1439: my $qualifierrest=$qualifier;
1440: if ($rest) { $qualifierrest.='.'.$rest; }
1441: my $spacequalifierrest=$space;
1442: if ($qualifierrest) { $spacequalifierrest.='.'.$qualifierrest; }
1443: if ($realm eq 'user') {
1444: # --------------------------------------------------------------- user.resource
1445: if ($space eq 'resource') {
1446: my %restored=&restore;
1447: return $restored{$qualifierrest};
1448: # ----------------------------------------------------------------- user.access
1449: } elsif ($space eq 'access') {
1450: return &allowed($qualifier,$rest);
1451: # ------------------------------------------ user.preferences, user.environment
1452: } elsif (($space eq 'preferences') || ($space eq 'environment')) {
1453: return $ENV{join('.',('environment',$qualifierrest))};
1454: # ----------------------------------------------------------------- user.course
1455: } elsif ($space eq 'course') {
1456: return $ENV{join('.',('request.course',$qualifier))};
1457: # ------------------------------------------------------------------- user.role
1458: } elsif ($space eq 'role') {
1459: my ($role,$where)=split(/\./,$ENV{'request.role'});
1460: if ($qualifier eq 'value') {
1461: return $role;
1462: } elsif ($qualifier eq 'extent') {
1463: return $where;
1464: }
1465: # ----------------------------------------------------------------- user.domain
1466: } elsif ($space eq 'domain') {
1467: return $ENV{'user.domain'};
1468: # ------------------------------------------------------------------- user.name
1469: } elsif ($space eq 'name') {
1470: return $ENV{'user.name'};
1471: # ---------------------------------------------------- Any other user namespace
1472: } else {
1473: my $item=($rest)?$qualifier.'.'.$rest:$qualifier;
1474: my %reply=&get($space,$item);
1475: return $reply{$item};
1476: }
1477: } elsif ($realm eq 'request') {
1478: # ------------------------------------------------------------- request.browser
1479: if ($space eq 'browser') {
1480: return $ENV{'browser.'.$qualifier};
1481: # ------------------------------------------------------------ request.filename
1482: } else {
1483: return $ENV{'request.'.$spacequalifierrest};
1484: }
1485: } elsif ($realm eq 'course') {
1486: # ---------------------------------------------------------- course.description
1487: my $section='';
1488: if ($ENV{'request.course.sec'}) {
1489: $section='_'.$ENV{'request.course.sec'};
1490: }
1491: return $ENV{'course.'.$ENV{'request.course.id'}.$section.'.'.
1492: $spacequalifierrest};
1493: } elsif ($realm eq 'resource') {
1494: if ($ENV{'request.course.id'}) {
1495: # ----------------------------------------------------- Cascading lookup scheme
1496: my $symbp=&symbread();
1497: my $mapp=(split(/\_\_\_/,$symbp))[0];
1498:
1499: my $symbparm=$symbp.'.'.$spacequalifierrest;
1500: my $mapparm=$mapp.'___(all).'.$spacequalifierrest;
1501:
1502: my $seclevel=
1503: $ENV{'request.course.id'}.'.['.
1504: $ENV{'request.course.sec'}.'].'.$spacequalifierrest;
1505: my $seclevelr=
1506: $ENV{'request.course.id'}.'.['.
1507: $ENV{'request.course.sec'}.'].'.$symbparm;
1508: my $seclevelm=
1509: $ENV{'request.course.id'}.'.['.
1510: $ENV{'request.course.sec'}.'].'.$mapparm;
1511:
1512: my $courselevel=
1513: $ENV{'request.course.id'}.'.'.$spacequalifierrest;
1514: my $courselevelr=
1515: $ENV{'request.course.id'}.'.'.$symbparm;
1516: my $courselevelm=
1517: $ENV{'request.course.id'}.'.'.$mapparm;
1518:
1519:
1520: # ----------------------------------------------------------- first, check user
1521: my %resourcedata=get('resourcedata',
1522: ($courselevelr,$courselevelm,$courselevel));
1523: if ($resourcedata{$courselevelr}!~/^error\:/) {
1524:
1525: if ($resourcedata{$courselevelr}) {
1526: return $resourcedata{$courselevelr}; }
1527: if ($resourcedata{$courselevelm}) {
1528: return $resourcedata{$courselevelm}; }
1529: if ($resourcedata{$courselevel}) { return $resourcedata{$courselevel}; }
1530:
1531: }
1532: # -------------------------------------------------------- second, check course
1533: my $section='';
1534: if ($ENV{'request.course.sec'}) {
1535: $section='_'.$ENV{'request.course.sec'};
1536: }
1537: my $reply=&reply('get:'.
1538: $ENV{'course.'.$ENV{'request.course.id'}.$section.'.domain'}.':'.
1539: $ENV{'course.'.$ENV{'request.course.id'}.$section.'.num'}.
1540: ':resourcedata:'.
1541: &escape($seclevelr).'&'.&escape($seclevelm).'&'.&escape($seclevel).'&'.
1542: &escape($courselevelr).'&'.&escape($courselevelm).'&'.&escape($courselevel),
1543: $ENV{'course.'.$ENV{'request.course.id'}.$section.'.home'});
1544: if ($reply!~/^error\:/) {
1545: map {
1546: if ($_) { return &unescape($_); }
1547: } split(/\&/,$reply);
1548: }
1549:
1550: # ------------------------------------------------------ third, check map parms
1551: my %parmhash=();
1552: my $thisparm='';
1553: if (tie(%parmhash,'GDBM_File',
1554: $ENV{'request.course.fn'}.'_parms.db',&GDBM_READER,0640)) {
1555: $thisparm=$parmhash{$symbparm};
1556: untie(%parmhash);
1557: }
1558: if ($thisparm) { return $thisparm; }
1559: }
1560:
1561: # --------------------------------------------- last, look in resource metadata
1562:
1563: $spacequalifierrest=~s/\./\_/;
1564: my $metadata=&metadata($ENV{'request.filename'},$spacequalifierrest);
1565: if ($metadata) { return $metadata; }
1566: $metadata=&metadata($ENV{'request.filename'},
1567: 'parameter_'.$spacequalifierrest);
1568: if ($metadata) { return $metadata; }
1569:
1570: # ---------------------------------------------------- Any other user namespace
1571: } elsif ($realm eq 'environment') {
1572: # ----------------------------------------------------------------- environment
1573: return $ENV{$spacequalifierrest};
1574: } elsif ($realm eq 'system') {
1575: # ----------------------------------------------------------------- system.time
1576: if ($space eq 'time') {
1577: return time;
1578: }
1579: }
1580: return '';
1581: }
1582:
1583: # ---------------------------------------------------------------- Get metadata
1584:
1585: sub metadata {
1586: my ($uri,$what)=@_;
1587:
1588: $uri=&declutter($uri);
1589: my $filename=$uri;
1590: $uri=~s/\.meta$//;
1591: unless ($metacache{$uri.':keys'}) {
1592: unless ($filename=~/\.meta$/) { $filename.='.meta'; }
1593: my $metastring=&getfile($perlvar{'lonDocRoot'}.'/res/'.$filename);
1594: my $parser=HTML::TokeParser->new(\$metastring);
1595: my $token;
1596: while ($token=$parser->get_token) {
1597: if ($token->[0] eq 'S') {
1598: my $entry=$token->[1];
1599: my $unikey=$entry;
1600: if (defined($token->[2]->{'part'})) {
1601: $unikey.='_'.$token->[2]->{'part'};
1602: }
1603: if (defined($token->[2]->{'name'})) {
1604: $unikey.='_'.$token->[2]->{'name'};
1605: }
1606: if ($metacache{$uri.':keys'}) {
1607: $metacache{$uri.':keys'}.=','.$unikey;
1608: } else {
1609: $metacache{$uri.':keys'}=$unikey;
1610: }
1611: map {
1612: $metacache{$uri.':'.$unikey.'.'.$_}=$token->[2]->{$_};
1613: } @{$token->[3]};
1614: unless (
1615: $metacache{$uri.':'.$unikey}=$parser->get_text('/'.$entry)
1616: ) { $metacache{$uri.':'.$unikey}=
1617: $metacache{$uri.':'.$unikey.'.default'};
1618: }
1619: }
1620: }
1621: }
1622: return $metacache{$uri.':'.$what};
1623: }
1624:
1625: # ------------------------------------------------- Update symbolic store links
1626:
1627: sub symblist {
1628: my ($mapname,%newhash)=@_;
1629: $mapname=declutter($mapname);
1630: my %hash;
1631: if (($ENV{'request.course.fn'}) && (%newhash)) {
1632: if (tie(%hash,'GDBM_File',$ENV{'request.course.fn'}.'_symb.db',
1633: &GDBM_WRCREAT,0640)) {
1634: map {
1635: $hash{declutter($_)}=$mapname.'___'.$newhash{$_};
1636: } keys %newhash;
1637: if (untie(%hash)) {
1638: return 'ok';
1639: }
1640: }
1641: }
1642: return 'error';
1643: }
1644:
1645: # ------------------------------------------------------ Return symb list entry
1646:
1647: sub symbread {
1648: my $thisfn=shift;
1649: unless ($thisfn) {
1650: $thisfn=$ENV{'request.filename'};
1651: }
1652: $thisfn=declutter($thisfn);
1653: my %hash;
1654: my %bighash;
1655: my $syval='';
1656: if (($ENV{'request.course.fn'}) && ($thisfn)) {
1657: if (tie(%hash,'GDBM_File',$ENV{'request.course.fn'}.'_symb.db',
1658: &GDBM_READER,0640)) {
1659: $syval=$hash{$thisfn};
1660: untie(%hash);
1661: }
1662: # ---------------------------------------------------------- There was an entry
1663: if ($syval) {
1664: unless ($syval=~/\_\d+$/) {
1665: unless ($ENV{'form.request.prefix'}=~/\.(\d+)\_$/) {
1666: &appenv('request.ambiguous' => $thisfn);
1667: return '';
1668: }
1669: $syval.=$1;
1670: }
1671: } else {
1672: # ------------------------------------------------------- Was not in symb table
1673: if (tie(%bighash,'GDBM_File',$ENV{'request.course.fn'}.'.db',
1674: &GDBM_READER,0640)) {
1675: # ---------------------------------------------- Get ID(s) for current resource
1676: my $ids=$bighash{'ids_/res/'.$thisfn};
1677: unless ($ids) {
1678: $ids=$bighash{'ids_/'.$thisfn};
1679: }
1680: if ($ids) {
1681: # ------------------------------------------------------------------- Has ID(s)
1682: my @possibilities=split(/\,/,$ids);
1683: if ($#possibilities==0) {
1684: # ----------------------------------------------- There is only one possibility
1685: my ($mapid,$resid)=split(/\./,$ids);
1686: $syval=declutter($bighash{'map_id_'.$mapid}).'___'.$resid;
1687: } else {
1688: # ------------------------------------------ There is more than one possibility
1689: my $realpossible=0;
1690: map {
1691: my $file=$bighash{'src_'.$_};
1692: if (&allowed('bre',$file)) {
1693: my ($mapid,$resid)=split(/\./,$_);
1694: if ($bighash{'map_type_'.$mapid} ne 'page') {
1695: $realpossible++;
1696: $syval=declutter($bighash{'map_id_'.$mapid}).
1697: '___'.$resid;
1698: }
1699: }
1700: } @possibilities;
1701: if ($realpossible!=1) { $syval=''; }
1702: }
1703: }
1704: untie(%bighash)
1705: }
1706: }
1707: if ($syval) {
1708: return $syval.'___'.$thisfn;
1709: }
1710: }
1711: &appenv('request.ambiguous' => $thisfn);
1712: return '';
1713: }
1714:
1715: # ---------------------------------------------------------- Return random seed
1716:
1717: sub numval {
1718: my $txt=shift;
1719: $txt=~tr/A-J/0-9/;
1720: $txt=~tr/a-j/0-9/;
1721: $txt=~tr/K-T/0-9/;
1722: $txt=~tr/k-t/0-9/;
1723: $txt=~tr/U-Z/0-5/;
1724: $txt=~tr/u-z/0-5/;
1725: $txt=~s/\D//g;
1726: return int($txt);
1727: }
1728:
1729: sub rndseed {
1730: my $symb;
1731: unless ($symb=&symbread()) { return time; }
1732: my $symbchck=unpack("%32C*",$symb);
1733: my $symbseed=numval($symb)%$symbchck;
1734: my $namechck=unpack("%32C*",$ENV{'user.name'});
1735: my $nameseed=numval($ENV{'user.name'})%$namechck;
1736: return int( $symbseed
1737: .$nameseed
1738: .unpack("%32C*",$ENV{'user.domain'})
1739: .unpack("%32C*",$ENV{'request.course.id'})
1740: .$namechck
1741: .$symbchck);
1742: }
1743:
1744: sub ireceipt {
1745: my ($funame,$fudom,$fucourseid,$fusymb)=@_;
1746: my $cuname=unpack("%32C*",$funame);
1747: my $cudom=unpack("%32C*",$fudom);
1748: my $cucourseid=unpack("%32C*",$fucourseid);
1749: my $cusymb=unpack("%32C*",$fusymb);
1750: my $cunique=unpack("%32C*",$perlvar{'lonReceipt'});
1751: return unpack("%32C*",$perlvar{'lonHostID'}).'-'.
1752: ($cunique%$cuname+
1753: $cunique%$cudom+
1754: $cusymb%$cuname+
1755: $cusymb%$cudom+
1756: $cucourseid%$cuname+
1757: $cucourseid%$cudom);
1758: }
1759:
1760: sub receipt {
1761: return &ireceipt($ENV{'user.name'},$ENV{'user.domain'},
1762: $ENV{'request.course.id'},&symbread());
1763: }
1764:
1765: # ------------------------------------------------------------ Serves up a file
1766: # returns either the contents of the file or a -1
1767: sub getfile {
1768: my $file=shift;
1769: &repcopy($file);
1770: if (! -e $file ) { return -1; };
1771: my $fh=Apache::File->new($file);
1772: my $a='';
1773: while (<$fh>) { $a .=$_; }
1774: return $a
1775: }
1776:
1777: sub filelocation {
1778: my ($dir,$file) = @_;
1779: my $location;
1780: $file=~ s/^\s*(\S+)\s*$/$1/; ## strip off leading and trailing spaces
1781: if ($file=~m:^/~:) { # is a contruction space reference
1782: $location = $file;
1783: $location =~ s:/~(.*?)/(.*):/home/$1/public_html/$2:;
1784: } else {
1785: $file=~s/^$perlvar{'lonDocRoot'}//;
1786: $file=~s:^/*res::;
1787: if ( !( $file =~ m:^/:) ) {
1788: $location = $dir. '/'.$file;
1789: } else {
1790: $location = '/home/httpd/html/res'.$file;
1791: }
1792: }
1793: $location=~s://+:/:g; # remove duplicate /
1794: while ($location=~m:/\.\./:) {$location=~ s:/[^/]+/\.\./:/:g;} #remove dir/..
1795: return $location;
1796: }
1797:
1798: sub hreflocation {
1799: my ($dir,$file)=@_;
1800: unless (($_=~/^http:\/\//i) || ($_=~/^\//)) {
1801: my $finalpath=filelocation($dir,$file);
1802: $finalpath=~s/^\/home\/httpd\/html//;
1803: return $finalpath;
1804: } else {
1805: return $file;
1806: }
1807: }
1808:
1809: # ------------------------------------------------------------- Declutters URLs
1810:
1811: sub declutter {
1812: my $thisfn=shift;
1813: $thisfn=~s/^$perlvar{'lonDocRoot'}//;
1814: $thisfn=~s/^\///;
1815: $thisfn=~s/^res\///;
1816: return $thisfn;
1817: }
1818:
1819: # -------------------------------------------------------- Escape Special Chars
1820:
1821: sub escape {
1822: my $str=shift;
1823: $str =~ s/(\W)/"%".unpack('H2',$1)/eg;
1824: return $str;
1825: }
1826:
1827: # ----------------------------------------------------- Un-Escape Special Chars
1828:
1829: sub unescape {
1830: my $str=shift;
1831: $str =~ s/%([a-fA-F0-9][a-fA-F0-9])/pack("C",hex($1))/eg;
1832: return $str;
1833: }
1834:
1835: # ================================================================ Main Program
1836:
1837: sub BEGIN {
1838: if ($readit ne 'done') {
1839: # ------------------------------------------------------------ Read access.conf
1840: {
1841: my $config=Apache::File->new("/etc/httpd/conf/access.conf");
1842:
1843: while (my $configline=<$config>) {
1844: if ($configline =~ /PerlSetVar/) {
1845: my ($dummy,$varname,$varvalue)=split(/\s+/,$configline);
1846: chomp($varvalue);
1847: $perlvar{$varname}=$varvalue;
1848: }
1849: }
1850: }
1851:
1852: # ------------------------------------------------------------- Read hosts file
1853: {
1854: my $config=Apache::File->new("$perlvar{'lonTabDir'}/hosts.tab");
1855:
1856: while (my $configline=<$config>) {
1857: my ($id,$domain,$role,$name,$ip)=split(/:/,$configline);
1858: $hostname{$id}=$name;
1859: $hostdom{$id}=$domain;
1860: if ($role eq 'library') { $libserv{$id}=$name; }
1861: }
1862: }
1863:
1864: # ------------------------------------------------------ Read spare server file
1865: {
1866: my $config=Apache::File->new("$perlvar{'lonTabDir'}/spare.tab");
1867:
1868: while (my $configline=<$config>) {
1869: chomp($configline);
1870: if (($configline) && ($configline ne $perlvar{'lonHostID'})) {
1871: $spareid{$configline}=1;
1872: }
1873: }
1874: }
1875: # ------------------------------------------------------------ Read permissions
1876: {
1877: my $config=Apache::File->new("$perlvar{'lonTabDir'}/roles.tab");
1878:
1879: while (my $configline=<$config>) {
1880: chomp($configline);
1881: my ($role,$perm)=split(/ /,$configline);
1882: if ($perm ne '') { $pr{$role}=$perm; }
1883: }
1884: }
1885:
1886: # -------------------------------------------- Read plain texts for permissions
1887: {
1888: my $config=Apache::File->new("$perlvar{'lonTabDir'}/rolesplain.tab");
1889:
1890: while (my $configline=<$config>) {
1891: chomp($configline);
1892: my ($short,$plain)=split(/:/,$configline);
1893: if ($plain ne '') { $prp{$short}=$plain; }
1894: }
1895: }
1896:
1897: # ------------------------------------------------------------- Read file types
1898: {
1899: my $config=Apache::File->new("$perlvar{'lonTabDir'}/filetypes.tab");
1900:
1901: while (my $configline=<$config>) {
1902: chomp($configline);
1903: my ($ending,$emb,@descr)=split(/\s+/,$configline);
1904: if ($descr[0] ne '') {
1905: $fe{$ending}=$emb;
1906: $fd{$ending}=join(' ',@descr);
1907: }
1908: }
1909: }
1910:
1911: %metacache=();
1912:
1913: $readit='done';
1914: &logthis('<font color=yellow>INFO: Read configuration</font>');
1915: }
1916: }
1917: 1;
FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>