#include "webserver.h"
#include <ctype.h>
+extern uint32_t hashlittle( const void *key, size_t length, uint32_t initval);
void display_reg(int during_login);
-
/*
* Display the login screen
* mesg = the error message if last attempt failed.
void become_logged_in(const StrBuf *user, const StrBuf *pass, StrBuf *serv_response)
{
wcsession *WCC = WC;
- char buf[SIZ];
+ StrBuf *Buf;
StrBuf *FloorDiv;
- WC->logged_in = 1;
+ WCC->logged_in = 1;
if (WCC->wc_fullname == NULL)
WCC->wc_fullname = NewStrBufPlain(NULL, StrLength(serv_response));
load_preferences();
+ Buf = NewStrBuf();
serv_puts("CHEK");
- serv_getln(buf, sizeof buf);
- if (buf[0] == '2') {
- WC->new_mail = extract_int(&buf[4], 0);
- WC->need_regi = extract_int(&buf[4], 1);
- WC->need_vali = extract_int(&buf[4], 2);
- extract_token(WC->cs_inet_email, &buf[4], 3, '|', sizeof WC->cs_inet_email);
+ StrBuf_ServGetln(Buf);
+ if (GetServerStatus(Buf, NULL) == 2) {
+ const char *pch;
+
+ pch = ChrPtr(Buf) + 4;
+ WCC->new_mail = StrBufExtractNext_long(Buf, &pch, '|');
+ WCC->need_regi = StrBufExtractNext_long(Buf, &pch, '|');
+ WCC->need_vali = StrBufExtractNext_long(Buf, &pch, '|');
+ if (WCC->cs_inet_email == NULL)
+ WCC->cs_inet_email = NewStrBuf();
+ StrBufExtract_NextToken(WCC->cs_inet_email, Buf, &pch, '|');
}
-
get_preference("floordiv_expanded", &FloorDiv);
- WC->floordiv_expanded = FloorDiv;
+ WCC->floordiv_expanded = FloorDiv;
+ FreeStrBuf(&Buf);
}
}
}
if (WCC->logged_in) {
- set_preference("language", NewStrBufPlain(bstr("language"), -1), 1);
if (WCC->need_regi) {
display_reg(1);
} else if (WCC->need_vali) {
snprintf(buf, sizeof buf,
"OIDS %s|%s://%s/finalize_openid_login|%s://%s",
bstr("openid_url"),
- (is_https ? "https" : "http"), ChrPtr(WCC->http_host),
- (is_https ? "https" : "http"), ChrPtr(WCC->http_host)
+ (is_https ? "https" : "http"), ChrPtr(WCC->Hdr->HR.http_host),
+ (is_https ? "https" : "http"), ChrPtr(WCC->Hdr->HR.http_host)
);
serv_puts(buf);
const char *HKey;
HashPos *Cursor;
- Cursor = GetNewHashPos (WCC->urlstrings, 0);
- while (GetNextHashPos(WCC->urlstrings, Cursor, &HKLen, &HKey, &U)) {
+ Cursor = GetNewHashPos (WCC->Hdr->urlstrings, 0);
+ while (GetNextHashPos(WCC->Hdr->urlstrings, Cursor, &HKLen, &HKey, &U)) {
u = (urlcontent*) U;
if (!strncasecmp(u->url_key, "openid.", 7)) {
serv_printf("%s|%s", &u->url_key[7], ChrPtr(u->url_data));
*/
if (!get_preference("startpage", &Buf)) {
Buf = NewStrBuf ();
- StrBufPrintf(Buf, "dotskip&room=_BASEROOM_");
+ StrBufPrintf(Buf, "dotskip?room=_BASEROOM_");
set_preference("startpage", Buf, 1);
}
if (ChrPtr(Buf)[0] == '/') {
StrBufCutLeft(Buf, 1);
}
- if (StrLength(Buf) == 0)
+ if (StrLength(Buf) == 0) {
StrBufAppendBufPlain(Buf, "dotgoto?room=_BASEROOM_", -1, 0);
+ }
+ lprintf(9, "Redirecting to user's start page: %s\n", ChrPtr(Buf));
http_redirect(ChrPtr(Buf));
}
*/
void do_logout(void)
{
+ wcsession *WCC = WC;
char buf[SIZ];
- FlushStrBuf(WC->wc_username);
- FlushStrBuf(WC->wc_password);
- FlushStrBuf(WC->wc_roomname);
- FlushStrBuf(WC->wc_fullname);
+ FlushStrBuf(WCC->wc_username);
+ FlushStrBuf(WCC->wc_password);
+ FlushStrBuf(WCC->wc_roomname);
+ FlushStrBuf(WCC->wc_fullname);
/* FIXME: this is to suppress the iconbar displaying, because we aren't
actually logged out yet */
- WC->logged_in = 0;
+ WCC->logged_in = 0;
/** Calling output_headers() this way causes the cookies to be un-set */
output_headers(1, 1, 0, 1, 0, 0);
serv_puts("MESG goodbye");
serv_getln(buf, sizeof buf);
- if (WC->serv_sock >= 0) {
+ if (WCC->serv_sock >= 0) {
if (buf[0] == '1') {
fmout("CENTER");
} else {
wprintf("<hr /><div class=\"buttons\"> "
"<span class=\"button_link\"><a href=\".\">");
wprintf(_("Log in again"));
- wprintf("</a></span> <span class=\"button_link\">"
+ wprintf("</a></span>");
+
+ /* The "close window" link is commented out because some browsers don't
+ * allow it to work.
+ *
+ wprintf(" <span class=\"button_link\">"
"<a href=\"javascript:window.close();\">");
wprintf(_("Close window"));
- wprintf("</a></span></div></div></div></div>\n");
+ wprintf("</a></span>");
+ */
+
+ wprintf("</div></div></div></div>\n");
wDumpContent(2);
end_webcit_session();
}
*/
void display_reg(int during_login)
{
+ StrBuf *Buf;
+ message_summary *VCMsg = NULL;
+ wc_mime_attachment *VCAtt = NULL;
long vcard_msgnum;
- if (goto_config_room() != 0) {
- if (during_login) do_welcome();
- else display_main_menu();
+ Buf = NewStrBuf();
+ if (goto_config_room(Buf) != 0) {
+ lprintf(9, "display_reg() exiting because goto_config_room() failed\n");
+ if (during_login) {
+ do_welcome();
+ }
+ else {
+ display_main_menu();
+ }
+ FreeStrBuf(&Buf);
return;
}
- vcard_msgnum = locate_user_vcard_in_this_room();
+ FreeStrBuf(&Buf);
+ vcard_msgnum = locate_user_vcard_in_this_room(&VCMsg, &VCAtt);
if (vcard_msgnum < 0L) {
- if (during_login) do_welcome();
- else display_main_menu();
+ lprintf(9, "display_reg() exiting because locate_user_vcard_in_this_room() failed\n");
+ if (during_login) {
+ do_welcome();
+ }
+ else {
+ display_main_menu();
+ }
return;
}
if (during_login) {
- do_edit_vcard(vcard_msgnum, "1", "do_welcome", USERCONFIGROOM);
+ do_edit_vcard(vcard_msgnum, "1", VCMsg, VCAtt, "do_welcome", USERCONFIGROOM);
}
else {
- do_edit_vcard(vcard_msgnum, "1", "display_main_menu", USERCONFIGROOM);
+ StrBuf *ReturnTo;
+ ReturnTo = NewStrBufPlain(NULL, 256);
+ StrBufUrlescAppend(ReturnTo, NULL, "display_main_menu?gotofirst=");
+ StrBufUrlescAppend(ReturnTo, WC->wc_roomname, NULL);
+ lprintf(9, "\e[32mwc_roomname: %s\e[0m\n", ChrPtr(WC->wc_roomname));
+ lprintf(9, "\e[31m ReturnTo: %s\e[0m\n", ChrPtr(ReturnTo));
+ do_edit_vcard(vcard_msgnum, "1", VCMsg, VCAtt, ChrPtr(ReturnTo), USERCONFIGROOM);
+ FreeStrBuf(&ReturnTo);
}
+ /*
+ FIXME
+ 1. don't we have to free VCMsg and VCAtt ??
+ 2. Fix bug 268
+ */
+
}
int ConditionalAide(StrBuf *Target, WCTemplputParams *TP)
{
- return (WC->is_aide == 0);
+ wcsession *WCC = WC;
+ return (WCC != NULL)? (WC->is_aide == 0) : 0;
}
int ConditionalRoomAide(StrBuf *Target, WCTemplputParams *TP)
{
- return (WC->is_room_aide == 0);
+ wcsession *WCC = WC;
+ return (WCC != NULL)? (WCC->is_room_aide == 0) : 0;
}
-int ConditionalIsLoggedIn(StrBuf *Target, WCTemplputParams *TP) {
- return (WC->logged_in == 0);
+
+int ConditionalIsLoggedIn(StrBuf *Target, WCTemplputParams *TP)
+{
+ wcsession *WCC = WC;
+ return (WCC != NULL)? (WCC->logged_in == 0) : 0;
}
+
+
int ConditionalRoomAcessDelete(StrBuf *Target, WCTemplputParams *TP)
{
wcsession *WCC = WC;
- return ( (WCC->is_room_aide) || (WCC->is_mailbox) || (WCC->room_flags2 & QR2_COLLABDEL) );
+ return (WCC != NULL)? ( (WCC->is_room_aide) || (WCC->is_mailbox) || (WCC->room_flags2 & QR2_COLLABDEL) ) : 0;
+}
+
+
+void _display_openid_login(void) {
+ display_openid_login(NULL);
+}
+
+
+void _display_reg(void) {
+ display_reg(0);
+}
+
+
+void Header_HandleAuth(StrBuf *Line, ParsedHttpHdrs *hdr)
+{
+ if (hdr->HR.got_auth == NO_AUTH) /* don't override cookie auth... */
+ {
+ if (strncasecmp(ChrPtr(Line), "Basic", 5) == 0) {
+ StrBufCutLeft(Line, 6);
+ StrBufDecodeBase64(Line);
+ hdr->HR.plainauth = Line;
+ hdr->HR.got_auth = AUTH_BASIC;
+ }
+ else
+ lprintf(1, "Authentication scheme not supported! [%s]\n", ChrPtr(Line));
+ }
}
+void CheckAuthBasic(ParsedHttpHdrs *hdr)
+{
+/*
+ todo: enable this if we can have other sessions than authenticated ones.
+ if (hdr->DontNeedAuth)
+ return;
+*/
+ StrBufAppendBufPlain(hdr->HR.plainauth, HKEY(":"), 0);
+ StrBufAppendBuf(hdr->HR.plainauth, hdr->HR.user_agent, 0);
+ hdr->HR.SessionKey = hashlittle(SKEY(hdr->HR.plainauth), 89479832);
+
+}
+
+void GetAuthBasic(ParsedHttpHdrs *hdr)
+{
+ const char *Pos = NULL;
+ if (hdr->c_username == NULL)
+ hdr->c_username = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_USER));
+ if (hdr->c_password == NULL)
+ hdr->c_password = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_PASS));
+ StrBufExtract_NextToken(hdr->c_username, hdr->HR.plainauth, &Pos, ':');
+ StrBufExtract_NextToken(hdr->c_password, hdr->HR.plainauth, &Pos, ':');
+}
+
+void Header_HandleCookie(StrBuf *Line, ParsedHttpHdrs *hdr)
+{
+ const char *pch;
+/*
+ todo: enable this if we can have other sessions than authenticated ones.
+ if (hdr->DontNeedAuth)
+ return;
+*/
+ pch = strstr(ChrPtr(Line), "webcit=");
+ if (pch == NULL) {
+ return;
+ }
+ hdr->HR.RawCookie = Line;
+ StrBufCutLeft(hdr->HR.RawCookie, (pch - ChrPtr(hdr->HR.RawCookie)) + 7);
+ StrBufDecodeHex(hdr->HR.RawCookie);
+
+ cookie_to_stuff(Line, &hdr->HR.desired_session,
+ hdr->c_username,
+ hdr->c_password,
+ hdr->c_roomname,
+ hdr->c_language
+ );
+ hdr->HR.got_auth = AUTH_COOKIE;
+}
-void _display_openid_login(void) {display_openid_login(NULL);}
-void _display_reg(void) {display_reg(0);}
+void
+HttpNewModule_AUTH
+(ParsedHttpHdrs *httpreq)
+{
+ httpreq->c_username = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_USER));
+ httpreq->c_password = NewStrBufPlain(HKEY(DEFAULT_HTTPAUTH_PASS));
+ httpreq->c_roomname = NewStrBuf();
+ httpreq->c_language = NewStrBuf();
+}
+void
+HttpDetachModule_AUTH
+(ParsedHttpHdrs *httpreq)
+{
+ FLUSHStrBuf(httpreq->c_username);
+ FLUSHStrBuf(httpreq->c_password);
+ FLUSHStrBuf(httpreq->c_roomname);
+ FLUSHStrBuf(httpreq->c_language);
+}
+void
+HttpDestroyModule_AUTH
+(ParsedHttpHdrs *httpreq)
+{
+ FreeStrBuf(&httpreq->c_username);
+ FreeStrBuf(&httpreq->c_password);
+ FreeStrBuf(&httpreq->c_roomname);
+ FreeStrBuf(&httpreq->c_language);
+}
void
InitModule_AUTH
(void)
{
- WebcitAddUrlHandler(HKEY("do_welcome"), do_welcome, ANONYMOUS);
- WebcitAddUrlHandler(HKEY("login"), do_login, ANONYMOUS);
+ RegisterHeaderHandler(HKEY("COOKIE"), Header_HandleCookie);
+ RegisterHeaderHandler(HKEY("AUTHORIZATION"), Header_HandleAuth);
+
+ WebcitAddUrlHandler(HKEY(""), do_welcome, ANONYMOUS|COOKIEUNNEEDED); /* no url pattern at all? Show login. */
+ WebcitAddUrlHandler(HKEY("do_welcome"), do_welcome, ANONYMOUS|COOKIEUNNEEDED);
+ WebcitAddUrlHandler(HKEY("login"), do_login, ANONYMOUS|COOKIEUNNEEDED);
WebcitAddUrlHandler(HKEY("display_openid_login"), _display_openid_login, ANONYMOUS);
WebcitAddUrlHandler(HKEY("openid_login"), do_openid_login, ANONYMOUS);
WebcitAddUrlHandler(HKEY("finalize_openid_login"), finalize_openid_login, ANONYMOUS);
WebcitAddUrlHandler(HKEY("openid_manual_create"), openid_manual_create, ANONYMOUS);
- WebcitAddUrlHandler(HKEY("do_logout"), do_logout, 0);
+ WebcitAddUrlHandler(HKEY("do_logout"), do_logout, ANONYMOUS|COOKIEUNNEEDED|FORCE_SESSIONCLOSE);
WebcitAddUrlHandler(HKEY("validate"), validate, 0);
WebcitAddUrlHandler(HKEY("display_reg"), _display_reg, 0);
WebcitAddUrlHandler(HKEY("display_changepw"), display_changepw, 0);
return ;
}
+
+
+void
+SessionDestroyModule_AUTH
+(wcsession *sess)
+{
+ FreeStrBuf(&sess->wc_username);
+ FreeStrBuf(&sess->wc_fullname);
+ FreeStrBuf(&sess->wc_password);
+ FreeStrBuf(&sess->wc_roomname);
+ FreeStrBuf(&sess->httpauth_pass);
+ FreeStrBuf(&sess->cs_inet_email);
+}