#include "webserver.h"
#include <ctype.h>
+extern uint32_t hashlittle( const void *key, size_t length, uint32_t initval);
void display_reg(int during_login);
-
/*
* Display the login screen
* mesg = the error message if last attempt failed.
wcsession *WCC = WC;
StrBuf *Buf;
StrBuf *FloorDiv;
- StrBuf *Language = NULL;
WCC->logged_in = 1;
WCC->cs_inet_email = NewStrBuf();
StrBufExtract_NextToken(WCC->cs_inet_email, Buf, &pch, '|');
}
- if (havebstr("language"))
- set_preference("language", NewStrBufDup(SBSTR("language")), 1);
- else {
- get_preference("language", &Language);
- if (Language != NULL) {
- set_selected_language(ChrPtr(Language));
- go_selected_language(); /* set locale */
- }
- }
get_preference("floordiv_expanded", &FloorDiv);
WCC->floordiv_expanded = FloorDiv;
FreeStrBuf(&Buf);
wcsession *WCC = WC;
StrBuf *Buf;
+ lprintf(9, "SELECTED LANGUAGE: '%s'\n", bstr("language"));
+
if (havebstr("language")) {
set_selected_language(bstr("language"));
go_selected_language();
snprintf(buf, sizeof buf,
"OIDS %s|%s://%s/finalize_openid_login|%s://%s",
bstr("openid_url"),
- (is_https ? "https" : "http"), ChrPtr(WCC->http_host),
- (is_https ? "https" : "http"), ChrPtr(WCC->http_host)
+ (is_https ? "https" : "http"), ChrPtr(WCC->Hdr->http_host),
+ (is_https ? "https" : "http"), ChrPtr(WCC->Hdr->http_host)
);
serv_puts(buf);
const char *HKey;
HashPos *Cursor;
- Cursor = GetNewHashPos (WCC->urlstrings, 0);
- while (GetNextHashPos(WCC->urlstrings, Cursor, &HKLen, &HKey, &U)) {
+ Cursor = GetNewHashPos (WCC->Hdr->urlstrings, 0);
+ while (GetNextHashPos(WCC->Hdr->urlstrings, Cursor, &HKLen, &HKey, &U)) {
u = (urlcontent*) U;
if (!strncasecmp(u->url_key, "openid.", 7)) {
serv_printf("%s|%s", &u->url_key[7], ChrPtr(u->url_data));
wprintf("<hr /><div class=\"buttons\"> "
"<span class=\"button_link\"><a href=\".\">");
wprintf(_("Log in again"));
- wprintf("</a></span> <span class=\"button_link\">"
+ wprintf("</a></span>");
+
+ /* The "close window" link is commented out because some browsers don't
+ * allow it to work.
+ *
+ wprintf(" <span class=\"button_link\">"
"<a href=\"javascript:window.close();\">");
wprintf(_("Close window"));
- wprintf("</a></span></div></div></div></div>\n");
+ wprintf("</a></span>");
+ */
+
+ wprintf("</div></div></div></div>\n");
wDumpContent(2);
end_webcit_session();
}
*/
void display_reg(int during_login)
{
+ StrBuf *Buf;
message_summary *VCMsg;
wc_mime_attachment *VCAtt;
long vcard_msgnum;
- if (goto_config_room() != 0) {
+ Buf = NewStrBuf();
+ if (goto_config_room(Buf) != 0) {
if (during_login) do_welcome();
else display_main_menu();
+ FreeStrBuf(&Buf);
return;
}
+ FreeStrBuf(&Buf);
vcard_msgnum = locate_user_vcard_in_this_room(&VCMsg, &VCAtt);
if (vcard_msgnum < 0L) {
if (during_login) do_welcome();
void _display_openid_login(void) {display_openid_login(NULL);}
void _display_reg(void) {display_reg(0);}
+void Header_HandleAuth(StrBuf *Line, ParsedHttpHdrs *hdr)
+{
+ if (hdr->got_auth == NO_AUTH) /* don't override cookie auth... */
+ {
+ if (strncasecmp(ChrPtr(Line), "Basic", 5) == 0) {
+ StrBufCutLeft(Line, 6);
+ StrBufDecodeBase64(Line);
+ hdr->plainauth = Line;
+ hdr->got_auth = AUTH_BASIC;
+ }
+ else
+ lprintf(1, "Authentication scheme not supported! [%s]\n", ChrPtr(Line));
+ }
+}
+
+void CheckAuthBasic(ParsedHttpHdrs *hdr)
+{
+/*
+ todo: enable this if we can have other sessions than authenticated ones.
+ if (hdr->DontNeedAuth)
+ return;
+*/
+ StrBufAppendBufPlain(hdr->plainauth, HKEY(":"), 0);
+ StrBufAppendBuf(hdr->plainauth, hdr->user_agent, 0);
+ hdr->SessionKey = hashlittle(SKEY(hdr->plainauth), 89479832);
+
+}
+
+void GetAuthBasic(ParsedHttpHdrs *hdr)
+{
+ const char *Pos = NULL;
+ if (hdr->c_username == NULL)
+ hdr->c_username = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_USER));
+ if (hdr->c_password == NULL)
+ hdr->c_password = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_PASS));
+ StrBufExtract_NextToken(hdr->c_username, hdr->plainauth, &Pos, ':');
+ StrBufExtract_NextToken(hdr->c_password, hdr->plainauth, &Pos, ':');
+}
+
+void Header_HandleCookie(StrBuf *Line, ParsedHttpHdrs *hdr)
+{
+ const char *pch;
+/*
+ todo: enable this if we can have other sessions than authenticated ones.
+ if (hdr->DontNeedAuth)
+ return;
+*/
+ pch = strstr(ChrPtr(Line), "webcit=");
+ if (pch == NULL) {
+ return;
+ }
+
+ hdr->RawCookie = Line;
+ StrBufCutLeft(hdr->RawCookie, (pch - ChrPtr(hdr->RawCookie)) + 7);
+ StrBufDecodeHex(hdr->RawCookie);
+
+ if (hdr->c_username == NULL)
+ hdr->c_username = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_USER));
+ if (hdr->c_password == NULL)
+ hdr->c_password = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_PASS));
+ if (hdr->c_roomname == NULL)
+ hdr->c_roomname = NewStrBuf();
+ if (hdr->c_language == NULL)
+ hdr->c_language = NewStrBuf();
+ cookie_to_stuff(Line, &hdr->desired_session,
+ hdr->c_username,
+ hdr->c_password,
+ hdr->c_roomname,
+ hdr->c_language
+ );
+ hdr->got_auth = AUTH_COOKIE;
+}
+
+
void
InitModule_AUTH
(void)
{
- WebcitAddUrlHandler(HKEY("do_welcome"), do_welcome, ANONYMOUS);
- WebcitAddUrlHandler(HKEY("login"), do_login, ANONYMOUS);
+ RegisterHeaderHandler(HKEY("COOKIE"), Header_HandleCookie);
+ RegisterHeaderHandler(HKEY("AUTHORIZATION"), Header_HandleAuth);
+
+ WebcitAddUrlHandler(HKEY(""), do_welcome, ANONYMOUS|COOKIEUNNEEDED); /* no url pattern at all? Show login. */
+ WebcitAddUrlHandler(HKEY("do_welcome"), do_welcome, ANONYMOUS|COOKIEUNNEEDED);
+ WebcitAddUrlHandler(HKEY("login"), do_login, ANONYMOUS|COOKIEUNNEEDED);
WebcitAddUrlHandler(HKEY("display_openid_login"), _display_openid_login, ANONYMOUS);
WebcitAddUrlHandler(HKEY("openid_login"), do_openid_login, ANONYMOUS);
WebcitAddUrlHandler(HKEY("finalize_openid_login"), finalize_openid_login, ANONYMOUS);
WebcitAddUrlHandler(HKEY("openid_manual_create"), openid_manual_create, ANONYMOUS);
- WebcitAddUrlHandler(HKEY("do_logout"), do_logout, 0);
+ WebcitAddUrlHandler(HKEY("do_logout"), do_logout, ANONYMOUS|COOKIEUNNEEDED|FORCE_SESSIONCLOSE);
WebcitAddUrlHandler(HKEY("validate"), validate, 0);
WebcitAddUrlHandler(HKEY("display_reg"), _display_reg, 0);
WebcitAddUrlHandler(HKEY("display_changepw"), display_changepw, 0);
return ;
}
+
+
+void
+SessionDestroyModule_AUTH
+(wcsession *sess)
+{
+ FreeStrBuf(&sess->wc_username);
+ FreeStrBuf(&sess->wc_fullname);
+ FreeStrBuf(&sess->wc_password);
+ FreeStrBuf(&sess->wc_roomname);
+ FreeStrBuf(&sess->httpauth_pass);
+ FreeStrBuf(&sess->cs_inet_email);
+}