#include "webserver.h"
#include <ctype.h>
+extern uint32_t hashlittle( const void *key, size_t length, uint32_t initval);
void display_reg(int during_login);
-
/*
* Display the login screen
* mesg = the error message if last attempt failed.
void become_logged_in(const StrBuf *user, const StrBuf *pass, StrBuf *serv_response)
{
wcsession *WCC = WC;
- char buf[SIZ];
+ StrBuf *Buf;
StrBuf *FloorDiv;
- StrBuf *Language = NULL;
- WC->logged_in = 1;
+ WCC->logged_in = 1;
if (WCC->wc_fullname == NULL)
WCC->wc_fullname = NewStrBufPlain(NULL, StrLength(serv_response));
load_preferences();
+ Buf = NewStrBuf();
serv_puts("CHEK");
- serv_getln(buf, sizeof buf);
- if (buf[0] == '2') {
- WC->new_mail = extract_int(&buf[4], 0);
- WC->need_regi = extract_int(&buf[4], 1);
- WC->need_vali = extract_int(&buf[4], 2);
- extract_token(WC->cs_inet_email, &buf[4], 3, '|', sizeof WC->cs_inet_email);
- }
- if (havebstr("language"))
- set_preference("language", NewStrBufDup(SBSTR("language")), 1);
- else {
- get_preference("language", &Language);
- if (Language != NULL) {
- set_selected_language(ChrPtr(Language));
- go_selected_language(); /* set locale */
- }
+ StrBuf_ServGetln(Buf);
+ if (GetServerStatus(Buf, NULL) == 2) {
+ const char *pch;
+
+ pch = ChrPtr(Buf) + 4;
+ WCC->new_mail = StrBufExtractNext_long(Buf, &pch, '|');
+ WCC->need_regi = StrBufExtractNext_long(Buf, &pch, '|');
+ WCC->need_vali = StrBufExtractNext_long(Buf, &pch, '|');
+ if (WCC->cs_inet_email == NULL)
+ WCC->cs_inet_email = NewStrBuf();
+ StrBufExtract_NextToken(WCC->cs_inet_email, Buf, &pch, '|');
}
get_preference("floordiv_expanded", &FloorDiv);
- WC->floordiv_expanded = FloorDiv;
+ WCC->floordiv_expanded = FloorDiv;
+ FreeStrBuf(&Buf);
}
wcsession *WCC = WC;
StrBuf *Buf;
+ lprintf(9, "SELECTED LANGUAGE: '%s'\n", bstr("language"));
+
if (havebstr("language")) {
set_selected_language(bstr("language"));
go_selected_language();
snprintf(buf, sizeof buf,
"OIDS %s|%s://%s/finalize_openid_login|%s://%s",
bstr("openid_url"),
- (is_https ? "https" : "http"), ChrPtr(WCC->http_host),
- (is_https ? "https" : "http"), ChrPtr(WCC->http_host)
+ (is_https ? "https" : "http"), ChrPtr(WCC->Hdr->http_host),
+ (is_https ? "https" : "http"), ChrPtr(WCC->Hdr->http_host)
);
serv_puts(buf);
const char *HKey;
HashPos *Cursor;
- Cursor = GetNewHashPos (WCC->urlstrings, 0);
- while (GetNextHashPos(WCC->urlstrings, Cursor, &HKLen, &HKey, &U)) {
+ Cursor = GetNewHashPos (WCC->Hdr->urlstrings, 0);
+ while (GetNextHashPos(WCC->Hdr->urlstrings, Cursor, &HKLen, &HKey, &U)) {
u = (urlcontent*) U;
if (!strncasecmp(u->url_key, "openid.", 7)) {
serv_printf("%s|%s", &u->url_key[7], ChrPtr(u->url_data));
wprintf("<hr /><div class=\"buttons\"> "
"<span class=\"button_link\"><a href=\".\">");
wprintf(_("Log in again"));
- wprintf("</a></span> <span class=\"button_link\">"
+ wprintf("</a></span>");
+
+ /* The "close window" link is commented out because some browsers don't
+ * allow it to work.
+ *
+ wprintf(" <span class=\"button_link\">"
"<a href=\"javascript:window.close();\">");
wprintf(_("Close window"));
- wprintf("</a></span></div></div></div></div>\n");
+ wprintf("</a></span>");
+ */
+
+ wprintf("</div></div></div></div>\n");
wDumpContent(2);
end_webcit_session();
}
*/
void display_reg(int during_login)
{
+ StrBuf *Buf;
+ message_summary *VCMsg;
+ wc_mime_attachment *VCAtt;
long vcard_msgnum;
- if (goto_config_room() != 0) {
+ Buf = NewStrBuf();
+ if (goto_config_room(Buf) != 0) {
if (during_login) do_welcome();
else display_main_menu();
+ FreeStrBuf(&Buf);
return;
}
- vcard_msgnum = locate_user_vcard_in_this_room();
+ FreeStrBuf(&Buf);
+ vcard_msgnum = locate_user_vcard_in_this_room(&VCMsg, &VCAtt);
if (vcard_msgnum < 0L) {
if (during_login) do_welcome();
else display_main_menu();
}
if (during_login) {
- do_edit_vcard(vcard_msgnum, "1", "do_welcome", USERCONFIGROOM);
+ do_edit_vcard(vcard_msgnum, "1", VCMsg, VCAtt, "do_welcome", USERCONFIGROOM);
}
else {
- do_edit_vcard(vcard_msgnum, "1", "display_main_menu", USERCONFIGROOM);
+ do_edit_vcard(vcard_msgnum, "1", VCMsg, VCAtt, "display_main_menu", USERCONFIGROOM);
}
}
void _display_openid_login(void) {display_openid_login(NULL);}
void _display_reg(void) {display_reg(0);}
+void Header_HandleAuth(StrBuf *Line, ParsedHttpHdrs *hdr)
+{
+ if (hdr->got_auth == NO_AUTH) /* don't override cookie auth... */
+ {
+ if (strncasecmp(ChrPtr(Line), "Basic", 5) == 0) {
+ StrBufCutLeft(Line, 6);
+ StrBufDecodeBase64(Line);
+ hdr->plainauth = Line;
+ hdr->got_auth = AUTH_BASIC;
+ }
+ else
+ lprintf(1, "Authentication scheme not supported! [%s]\n", ChrPtr(Line));
+ }
+}
+
+void CheckAuthBasic(ParsedHttpHdrs *hdr)
+{
+/*
+ todo: enable this if we can have other sessions than authenticated ones.
+ if (hdr->DontNeedAuth)
+ return;
+*/
+ StrBufAppendBufPlain(hdr->plainauth, HKEY(":"), 0);
+ StrBufAppendBuf(hdr->plainauth, hdr->user_agent, 0);
+ hdr->SessionKey = hashlittle(SKEY(hdr->plainauth), 89479832);
+
+}
+
+void GetAuthBasic(ParsedHttpHdrs *hdr)
+{
+ const char *Pos = NULL;
+ if (hdr->c_username == NULL)
+ hdr->c_username = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_USER));
+ if (hdr->c_password == NULL)
+ hdr->c_password = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_PASS));
+ StrBufExtract_NextToken(hdr->c_username, hdr->plainauth, &Pos, ':');
+ StrBufExtract_NextToken(hdr->c_password, hdr->plainauth, &Pos, ':');
+}
+
+void Header_HandleCookie(StrBuf *Line, ParsedHttpHdrs *hdr)
+{
+ const char *pch;
+/*
+ todo: enable this if we can have other sessions than authenticated ones.
+ if (hdr->DontNeedAuth)
+ return;
+*/
+ pch = strstr(ChrPtr(Line), "webcit=");
+ if (pch == NULL) {
+ return;
+ }
+
+ hdr->RawCookie = Line;
+ StrBufCutLeft(hdr->RawCookie, (pch - ChrPtr(hdr->RawCookie)) + 7);
+ StrBufDecodeHex(hdr->RawCookie);
+
+ if (hdr->c_username == NULL)
+ hdr->c_username = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_USER));
+ if (hdr->c_password == NULL)
+ hdr->c_password = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_PASS));
+ if (hdr->c_roomname == NULL)
+ hdr->c_roomname = NewStrBuf();
+ if (hdr->c_language == NULL)
+ hdr->c_language = NewStrBuf();
+ cookie_to_stuff(Line, &hdr->desired_session,
+ hdr->c_username,
+ hdr->c_password,
+ hdr->c_roomname,
+ hdr->c_language
+ );
+ hdr->got_auth = AUTH_COOKIE;
+}
+
+
void
InitModule_AUTH
(void)
{
- WebcitAddUrlHandler(HKEY("do_welcome"), do_welcome, ANONYMOUS);
- WebcitAddUrlHandler(HKEY("login"), do_login, ANONYMOUS);
+ RegisterHeaderHandler(HKEY("COOKIE"), Header_HandleCookie);
+ RegisterHeaderHandler(HKEY("AUTHORIZATION"), Header_HandleAuth);
+
+ WebcitAddUrlHandler(HKEY(""), do_welcome, ANONYMOUS|COOKIEUNNEEDED); /* no url pattern at all? Show login. */
+ WebcitAddUrlHandler(HKEY("do_welcome"), do_welcome, ANONYMOUS|COOKIEUNNEEDED);
+ WebcitAddUrlHandler(HKEY("login"), do_login, ANONYMOUS|COOKIEUNNEEDED);
WebcitAddUrlHandler(HKEY("display_openid_login"), _display_openid_login, ANONYMOUS);
WebcitAddUrlHandler(HKEY("openid_login"), do_openid_login, ANONYMOUS);
WebcitAddUrlHandler(HKEY("finalize_openid_login"), finalize_openid_login, ANONYMOUS);
WebcitAddUrlHandler(HKEY("openid_manual_create"), openid_manual_create, ANONYMOUS);
- WebcitAddUrlHandler(HKEY("do_logout"), do_logout, 0);
+ WebcitAddUrlHandler(HKEY("do_logout"), do_logout, ANONYMOUS|COOKIEUNNEEDED|FORCE_SESSIONCLOSE);
WebcitAddUrlHandler(HKEY("validate"), validate, 0);
WebcitAddUrlHandler(HKEY("display_reg"), _display_reg, 0);
WebcitAddUrlHandler(HKEY("display_changepw"), display_changepw, 0);
return ;
}
+
+
+void
+SessionDestroyModule_AUTH
+(wcsession *sess)
+{
+ FreeStrBuf(&sess->wc_username);
+ FreeStrBuf(&sess->wc_fullname);
+ FreeStrBuf(&sess->wc_password);
+ FreeStrBuf(&sess->wc_roomname);
+ FreeStrBuf(&sess->httpauth_pass);
+ FreeStrBuf(&sess->cs_inet_email);
+}