/*
- * auth.c
+ * $Id$
*
- * This file contains code which relates to authentication of users to Citadel.
+ * Handles authentication of users to a Citadel server.
*
- * $Id$
*/
{
char buf[SIZ];
- output_headers(3);
+ output_headers(1, 1, 2, 0, 0, 0, 0);
+ //wprintf("<div id=\"content\">\n");
+ wprintf("<div style=\"position:absolute; top:20px; left:20px; right:20px\">\n");
if (mesg != NULL) if (strlen(mesg) > 0) {
stresc(buf, mesg, 0, 0);
do_template("login");
- clear_local_substs();
- wDumpContent(0); /* No menu here; not logged in yet! */
+ wDumpContent(2);
}
}
}
if (!strcasecmp(bstr("action"), "New User")) {
+ if (strlen(bstr("pass")) == 0) {
+ display_login("Blank passwords are not allowed.");
+ return;
+ }
serv_printf("NEWU %s", bstr("name"));
serv_gets(buf);
if (buf[0] == '2') {
set_preference("startpage", startpage);
}
- svprintf("STARTPAGE", WCS_STRING, startpage);
-
- do_template("mainframeset");
- clear_local_substs();
+ http_redirect(startpage);
}
strcpy(WC->wc_password, "");
strcpy(WC->wc_roomname, "");
- output_headers(2); /* note "2" causes cookies to be unset */
+ /* Calling output_headers() this way causes the cookies to be un-set */
+ output_headers(1, 1, 0, 1, 0, 0, 0);
- wprintf("<CENTER>");
+ wprintf("<center>");
serv_puts("MESG goodbye");
serv_gets(buf);
);
}
- wprintf("<HR><A HREF=\"/\">Log in again</A> "
- "<A HREF=\"javascript:window.close();\">Close window</A>"
- "</CENTER>\n");
+ wprintf("<hr /><a href=\"/\">Log in again</A> "
+ "<a href=\"javascript:window.close();\">Close window</A>"
+ "</center>\n");
wDumpContent(2);
end_webcit_session();
}
-
/*
* validate new users
*/
char buf[SIZ];
int a;
- output_headers(3);
-
+ output_headers(1, 1, 2, 0, 0, 0, 0);
+ wprintf("<div id=\"banner\">\n"
+ "<TABLE WIDTH=100%% BORDER=0 BGCOLOR=\"#444455\"><TR><TD>"
+ "<SPAN CLASS=\"titlebar\">Validate new users</SPAN>"
+ "</TD></TR></TABLE>\n"
+ "</div>\n<div id=\"content\">\n"
+ );
+
strcpy(buf, bstr("user"));
if (strlen(buf) > 0)
- if (strlen(bstr("WC->axlevel")) > 0) {
- serv_printf("VALI %s|%s", buf, bstr("WC->axlevel"));
+ if (strlen(bstr("axlevel")) > 0) {
+ serv_printf("VALI %s|%s", buf, bstr("axlevel"));
serv_gets(buf);
if (buf[0] != '2') {
- wprintf("<EM>%s</EM><BR>\n", &buf[4]);
+ wprintf("<b>%s</b><br />\n", &buf[4]);
}
}
serv_puts("GNUR");
serv_gets(buf);
if (buf[0] != '3') {
- wprintf("<EM>%s</EM><BR>\n", &buf[4]);
+ wprintf("<b>%s</b><br />\n", &buf[4]);
wDumpContent(1);
return;
}
+
+ wprintf("<div id=\"fix_scrollbar_bug\">"
+ "<table border=0 width=100%% bgcolor=\"#ffffff\"><tr><td>\n");
+ wprintf("<center>");
+
strcpy(user, &buf[4]);
serv_printf("GREG %s", user);
serv_gets(cmd);
serv_gets(buf);
++a;
if (a == 1)
- wprintf("User #%s<BR><H1>%s</H1>",
+ wprintf("User #%s<br /><H1>%s</H1>",
buf, &cmd[4]);
if (a == 2)
- wprintf("PW: %s<BR>\n", buf);
+ wprintf("PW: %s<br />\n", buf);
if (a == 3)
- wprintf("%s<BR>\n", buf);
+ wprintf("%s<br />\n", buf);
if (a == 4)
- wprintf("%s<BR>\n", buf);
+ wprintf("%s<br />\n", buf);
if (a == 5)
wprintf("%s, ", buf);
if (a == 6)
wprintf("%s ", buf);
if (a == 7)
- wprintf("%s<BR>\n", buf);
+ wprintf("%s<br />\n", buf);
if (a == 8)
- wprintf("%s<BR>\n", buf);
+ wprintf("%s<br />\n", buf);
if (a == 9)
wprintf("Current access level: %d (%s)\n",
atoi(buf), axdefs[atoi(buf)]);
} while (strcmp(buf, "000"));
} else {
- wprintf("<H1>%s</H1>%s<BR>\n", user, &cmd[4]);
+ wprintf("<H1>%s</H1>%s<br />\n", user, &cmd[4]);
}
- wprintf("<CENTER><TABLE border><CAPTION>Select access level:");
- wprintf("</CAPTION><TR>");
+ wprintf("<hr />Select access level for this user:<br />\n");
for (a = 0; a <= 6; ++a) {
- wprintf("<TD><A HREF=\"/validate&user=");
+ wprintf("<A HREF=\"/validate&user=");
urlescputs(user);
- wprintf("&WC->axlevel=%d\">%s</A></TD>\n",
+ wprintf("&axlevel=%d\">%s</A> \n",
a, axdefs[a]);
}
- wprintf("</TR></TABLE><CENTER><BR>\n");
+ wprintf("<br />\n");
+
+ wprintf("</CENTER>\n");
+ wprintf("</td></tr></table></div>\n");
wDumpContent(1);
}
{
char buf[SIZ];
- output_headers(3);
+ output_headers(1, 1, 2, 0, 0, 0, 0);
+ wprintf("<div id=\"banner\">\n"
+ "<TABLE WIDTH=100%% BORDER=0 BGCOLOR=\"#444455\"><TR><TD>"
+ "<SPAN CLASS=\"titlebar\">Change your password</SPAN>"
+ "</TD></TR></TABLE>\n"
+ "</div>\n<div id=\"content\">\n"
+ );
+
+ if (strlen(WC->ImportantMessage) > 0) {
+ do_template("beginbox_nt");
+ wprintf("<SPAN CLASS=\"errormsg\">"
+ "%s</SPAN><br />\n", WC->ImportantMessage);
+ do_template("endbox");
+ strcpy(WC->ImportantMessage, "");
+ }
+
+ wprintf("<div id=\"fix_scrollbar_bug\">"
+ "<table border=0 width=100%% bgcolor=\"#ffffff\"><tr><td>\n");
- svprintf("BOXTITLE", WCS_STRING, "Change your password");
- do_template("beginbox");
- wprintf("<CENTER><BR>");
+ wprintf("<CENTER><br />");
serv_puts("MESG changepw");
serv_gets(buf);
if (buf[0] == '1') {
fmout(NULL, "CENTER");
}
- wprintf("<FORM ACTION=\"changepw\" METHOD=\"POST\">\n");
+ wprintf("<form name=\"changepwform\" action=\"changepw\" method=\"post\">\n");
wprintf("<CENTER>"
"<table border=\"0\" cellspacing=\"5\" cellpadding=\"5\" "
"BGCOLOR=\"#EEEEEE\">"
wprintf("<TD><INPUT TYPE=\"password\" NAME=\"newpass1\" VALUE=\"\" MAXLENGTH=\"20\"></TD></TR>\n");
wprintf("<TR><TD>Enter it again to confirm:</TD>\n");
wprintf("<TD><INPUT TYPE=\"password\" NAME=\"newpass2\" VALUE=\"\" MAXLENGTH=\"20\"></TD></TR>\n");
- wprintf("</TABLE><BR>\n");
- wprintf("<INPUT type=\"submit\" NAME=\"action\" VALUE=\"Change\">\n"
+
+ wprintf("</TABLE><br />\n");
+ wprintf("<INPUT type=\"submit\" name=\"action\" value=\"Change\">"
" "
- "<INPUT type=\"submit\" NAME=\"action\" VALUE=\"Cancel\">\n");
- wprintf("</CENTER>\n");
- do_template("endbox");
+ "<INPUT type=\"submit\" name=\"action\" value=\"Cancel\">\n");
+ wprintf("</form></center>\n");
+ wprintf("</td></tr></table></div>\n");
wDumpContent(1);
}
display_main_menu();
return;
}
+
strcpy(newpass1, bstr("newpass1"));
strcpy(newpass2, bstr("newpass2"));
if (strcasecmp(newpass1, newpass2)) {
strcpy(WC->ImportantMessage,
"They don't match. Password was not changed.");
- display_main_menu();
+ display_changepw();
+ return;
+ }
+
+ if (strlen(newpass1) == 0) {
+ strcpy(WC->ImportantMessage,
+ "Blank passwords are not allowed.");
+ display_changepw();
return;
}
+
serv_printf("SETP %s", newpass1);
serv_gets(buf);
- strcpy(WC->ImportantMessage, &buf[4]);
- display_main_menu();
+ sprintf(WC->ImportantMessage, "%s", &buf[4]);
+ if (buf[0] == '2') {
+ safestrncpy(WC->wc_password, buf, sizeof WC->wc_password);
+ display_main_menu();
+ }
+ else {
+ display_changepw();
+ }
}