# along with this program. If not, see <http://www.gnu.org/licenses/>.
use strict;
-use warnings;
+use warnings FATAL => 'all';
package CGI::Auth::Flexible;
require Exporter;
my ($p) = @_;
my @p;
foreach my $k (keys %$p) {
+ next if $k eq '';
foreach my $v (@{ $p->{$k} }) {
push @p, $k, $v;
}
my $username_params = $r->{S}{username_param_names};
my $username = $r->_ch('get_param',$username_params->[0]);
my $password = $r->_rp('password_param_name');
- return $r->_ch('username_password_ok', $username, $password);
+ return undef unless $r->_ch('username_password_ok', $username, $password);
+ return $username;
}
sub do_redirect_cgi ($$$$) {
'<a href="'.escapeHTML($new_url).'">',
$r->_gt("If you aren't redirected, click to continue."),
"</a>",
- $c->_ch('gen_end_html'));
+ $r->_ch('gen_end_html'));
}
-sub gen_plain_login_form ($$) {
- my ($c,$r, $params) = @_;
+sub gen_some_form ($$) {
+ my ($r, $params, $bodyfn) = @_;
+ # Calls $bodyfn->($c,$r) which returns @formbits
+ my $c = $r->{Cgi};
my @form;
+ my $pathinfo = '';
+ $pathinfo .= $params->{''}[0] if $params->{''};
push @form, ('<form method="POST" action="'.
- escapeHTML($r->_ch('get_url')).'">'.
- '<table>');
- my $sz = 'size="'.$r->{S}{form_entry_size}.'"';
- foreach my $up (@{ $r->{S}{username_param_names}}) {
- push @form, ('<tr><td>',$r->_gt(ucfirst $up),'</td>',
- '<td><input type="text" '.$sz.
- ' name='.$up.'></td></tr>');
- }
- push @form, ('<tr><td>'.$r->_gt('Password').'</td>',
- '<td><input type="password" '.$sz.
- ' name="'.$r->{S}{password_param_name}.'"></td></tr>');
- push @form, ('<tr><td colspan="2">',
- '<input type="submit"'.
- ' name="'.$r->{S}{login_submit_name}[0].'"'.
- ' value="'.$r->_gt('Login').'"></td></tr>',
- '</table>');
+ escapeHTML($r->_ch('get_url').$pathinfo).'">');
+ push @form, $bodyfn->($c,$r);
foreach my $n (keys %$params) {
- push @form, ('<input type="hidden"'.
- ' name="'.$n.'"'.
- ' value="'.$params->{$n}.'">');
+ next if $n eq '';
+ foreach my $val (@{ $params->{$n} }) {
+ push @form, ('<input type="hidden"'.
+ ' name="'.escapeHTML($n).'"'.
+ ' value="'.escapeHTML($val).'">');
+ }
}
push @form, ('</form>');
return join "\n", @form;
}
-sub gen_login_link ($$) {
+sub gen_plain_login_form ($$) {
+ my ($c,$r, $params) = @_;
+ return $r->gen_some_form($params, sub {
+ my @form;
+ push @form, ('<table>');
+ my $sz = 'size="'.$r->{S}{form_entry_size}.'"';
+ foreach my $up (@{ $r->{S}{username_param_names}}) {
+ push @form, ('<tr><td>',$r->_gt(ucfirst $up),'</td>',
+ '<td><input type="text" '.$sz.
+ ' name='.$up.'></td></tr>');
+ }
+ push @form, ('<tr><td>'.$r->_gt('Password').'</td>',
+ '<td><input type="password" '.$sz.
+ ' name="'.$r->{S}{password_param_name}.'"></td></tr>');
+ push @form, ('<tr><td colspan="2">',
+ '<input type="submit"'.
+ ' name="'.$r->{S}{dummy_param_name_prefix}.'login"'.
+ ' value="'.$r->_gt('Login').'"></td></tr>',
+ '</table>');
+ return @form;
+ });
+}
+
+sub gen_postmainpage_form ($$$) {
+ my ($c,$r, $params) = @_;
+ return $r->gen_some_form($params, sub {
+ my @form;
+ push @form, ('<input type="submit"',
+ ' name="'.$r->{S}{dummy_param_name_prefix}.'submit"'.
+ ' value="'.$r->_gt('Continue').'">');
+ return @form;
+ });
+}
+
+sub gen_plain_login_link ($$) {
my ($c,$r, $params) = @_;
my $url = $r->url_with_query_params($params);
return ('<a href="'.escapeHTML($url).'">'.
login_form_timeout => 3600, # seconds
key_rollover => 86400, # seconds
assoc_param_name => 'caf_assochash',
+ dummy_param_name_prefix => 'caf__',
cookie_name => "caf_assocsecret",
password_param_name => 'password',
username_param_names => [qw(username)],
form_entry_size => 60,
logout_param_names => [qw(caf_logout)],
- login_submit_name => [qw(caf_login)],
loggedout_param_names => [qw(caf_loggedout)],
promise_check_mutate => 0,
get_param => sub { $_[0]->param($_[2]) },
get_params => sub { $_[1]->get_params() },
+ get_path_info => sub { $_[0]->path_info() },
get_cookie => sub { $_[0]->cookie($_[1]->{S}{cookie_name}) },
get_method => sub { $_[0]->request_method() },
get_url => sub { $_[0]->url(); },
gen_end_html => sub { $_[0]->end_html(); },
gen_login_form => \&gen_plain_login_form,
gen_login_link => \&gen_plain_login_link,
+ gen_postmainpage_form => \&gen_postmainpage_form,
gettext => sub { gettext($_[2]); },
print => sub { print $_[2] or die $!; },
},
print STDERR "DT commit ok\n";
1;
}) {
-print STDERR "DT commit eval ok $rv\n";
+print STDERR "DT commit eval ok ",Dumper($rv);
return $rv;
}
print STDERR "DT commit throw?\n";
my $cookh = defined $cooks ? $r->hash($cooks) : undef;
my ($cookt,$cooku) = $r->_identify($cookh, $cooks);
- my $parmt = $r->_identify($parmh, undef);
+ my $parms = (defined $cooks && defined $parmh && $parmh eq $cookh)
+ ? $cooks : undef;
+ my ($parmt) = $r->_identify($parmh, $parms);
print STDERR "_c_d_c cookt=$cookt parmt=$parmt\n";
return ({ Kind => 'SMALLPAGE-NOCOOKIE',
Message => "You do not seem to have cookies enabled. ".
"You must enable cookies as we use them for login.",
- CookieSecret => $r->_fresh_secret(),
- Params => $r->_chain_params() })
+ CookieSecret => $r->_fresh_secret(),
+ Params => $r->chain_params() })
}
if (!$cookt || $cookt eq 'n' || $cookh ne $parmh) {
$r->_db_revoke($cookh);
return ({ Kind => 'LOGIN-BAD',
Message => "Incorrect username/password.",
CookieSecret => $cooks,
- Params => $r->_chain_params() })
+ Params => $r->chain_params() })
}
$r->_db_record_login_ok($parmh,$username);
return ({ Kind => 'REDIRECT-LOGGEDIN',
Message => "Logging in...",
CookieSecret => $cooks,
- Params => $r->_chain_params() });
+ Params => $r->chain_params() });
}
if ($cookt eq 't') {
$cookt = '';
my $news = $r->_fresh_secret();
if ($meth eq 'GET') {
return ({ Kind => 'LOGIN-INCOMINGLINK',
- Message => "You need to log in again.",
+ Message => "You need to log in.",
CookieSecret => $news,
- Params => $r->_chain_params() });
+ Params => $r->chain_params() });
} else {
$r->_db_revoke($parmh);
return ({ Kind => 'LOGIN-FRESH',
- Message => "You need to log in again.",
+ Message => "You need to log in.",
CookieSecret => $news,
Params => { } });
}
}
die unless $cookt eq 'y';
- die unless $parmt eq 'y';
- die unless $cookh eq $parmh;
+ unless ($r->{S}{promise_check_mutate} && $meth eq 'GET') {
+ die unless $parmt eq 'y';
+ die unless $cookh eq $parmh;
+ }
$r->{AssocSecret} = $cooks;
$r->{UserOK} = $cooku;
print STDERR "C-D-C OK\n";
return undef;
}
-sub _chain_params ($) {
+sub chain_params ($) {
my ($r) = @_;
my %p = %{ $r->_ch('get_params') };
foreach my $pncn (keys %{ $r->{S} }) {
delete $p{$name};
}
}
+ my $dummy_prefix = $r->{S}{dummy_param_name_prefix};
+ foreach my $name (grep /^$dummy_prefix/, keys %p) {
+ delete $p{$name};
+ }
+ die if exists $p{''};
+ $p{''} = [ $r->_ch('get_path_info') ];
return \%p;
}
# where $t is one of "t" "y" "n", or "" (for -)
# either $s must be undef, or $h eq $r->hash($s)
+print STDERR "_identify\n";
return '' unless defined $h && length $h;
+print STDERR "_identify h=$h s=".(defined $s ? $s : '<undef>')."\n";
my $dbh = $r->{Dbh};
" FROM $r->{S}{assocdb_table}".
" WHERE assochash = ?", {}, $h);
if (defined $row) {
+print STDERR "_identify h=$h s=$s YES @$row\n";
my ($nusername, $nlast) = @$row;
return ('y', $nusername);
}
my ($keyt, $signature, $message, $noncet, $nonce) =
$s =~ m/^(\d+)\.(\w+)\.((\d+)\.(\w+))$/ or die;
- return 'n' if time > $noncet + $r->{S}{form_timeout};
+ return 'n' if time > $noncet + $r->{S}{login_form_timeout};
+
+print STDERR "_identify noncet=$noncet ok\n";
my $keys = $r->_open_keys();
while (my ($rkeyt, $rkey, $line) = $r->_read_key($keys)) {
+print STDERR "_identify search rkeyt=$rkeyt rkey=$rkey\n";
last if $rkeyt < $keyt; # too far down in the file
my $trysignature = $r->_hmac($rkey, $message);
+print STDERR "_identify search rkeyt=$rkeyt rkey=$rkey trysig=$trysignature\n";
return 't' if $trysignature eq $signature;
}
# oh well
+print STDERR "_identify NO\n";
$keys->error and die $!;
return 'n';
$r->_db_revoke($h);
my $dbh = $r->{Dbh};
$dbh->do("INSERT INTO $r->{S}{assocdb_table}".
- " (associd, username, last) VALUES (?,?,?)", {},
+ " (assochash, username, last) VALUES (?,?,?)", {},
$h, $user, time);
}
sub url_with_query_params ($$) {
my ($r, $params) = @_;
+print STDERR "PARAMS ",Dumper($params);
my $uri = URI->new($r->_ch('get_url'));
+ $uri->path($uri->path() . $params->{''}[0]) if $params->{''};
$uri->query_form(flatten_params($params));
return $uri->as_string();
}
my $params = $divert->{Params};
my $cookie = $r->construct_cookie($cookiesecret);
- if (defined $cookiesecret) {
- $params->{$r->{S}{assoc_param_name}} = $r->hash($cookiesecret);
- }
-
if ($kind =~ m/^REDIRECT-/) {
# for redirects, we honour stored NextParams and SetCookie,
# as we would for non-divert
if ($kind eq 'REDIRECT-LOGGEDOUT') {
- $params->{$r->{S}{loggedout_param_names}[0]} = 1;
+ $params->{$r->{S}{loggedout_param_names}[0]} = [ 1 ];
} elsif ($kind eq 'REDIRECT-LOGOUT') {
- $params->{$r->{S}{logout_param_names}[0]} = 1;
+ $params->{$r->{S}{logout_param_names}[0]} = [ 1 ];
} elsif ($kind eq 'REDIRECT-LOGGEDIN') {
} else {
die;
return 0;
}
+ if (defined $cookiesecret) {
+ $params->{$r->{S}{assoc_param_name}} = [ $r->hash($cookiesecret) ];
+ }
+
my ($title, @body);
if ($kind =~ m/^LOGIN-/) {
$title = $r->_gt('Login');
} elsif ($kind =~ m/^SMALLPAGE-/) {
$title = $r->_gt('Not logged in');
push @body, $r->_gt($divert->{Message});
- push @body, $r->_ch('gen_login_link');
+ push @body, $r->_ch('gen_login_link', $params);
+ } elsif ($kind =~ m/^MAINPAGEONLY$/) {
+ $title = $r->_gt('Entering secure site.');
+ push @body, $r->_gt($divert->{Message});
+ push @body, $r->_ch('gen_postmainpage_form', $params);
} else {
die $kind;
}
sub hash ($$) {
my ($r, $message) = @_;
my $alg = $r->{S}{hash_algorithm};
-print STDERR "hash $alg";
+print STDERR "hash $alg\n";
my $digest = new Digest $alg;
$digest->add($message);
return $digest->hexdigest();
die "unchecked" unless exists $r->{Divert};
}
+sub _is_post ($) {
+ my ($r) = @_;
+ my $meth = $r->_ch('get_method');
+ return $meth eq 'POST';
+}
+
+sub _must_be_post ($) {
+ my ($r) = @_;
+ my $meth = $r->_ch('get_method');
+ die "mutating non-POST" if $meth ne 'POST';
+}
+
sub check_mutate ($) {
my ($r) = @_;
$r->_assert_checked();
die if $r->{Divert};
- my $meth = $r->_ch('get_method');
- die "mutating non-POST" if $meth ne 'POST';
+ $r->_must_be_post();
+}
+
+sub mutate_ok ($) {
+ my ($r) = @_;
+ $r->_assert_checked();
+ die if $r->{Divert};
+ return $r->_is_post();
}
#---------- output ----------
sub secret_hidden_val ($) {
my ($r) = @_;
$r->_assert_checked();
- return defined $r->{AssocSecret} ? r->hash($r->{AssocSecret}) : '';
+ return defined $r->{AssocSecret} ? $r->hash($r->{AssocSecret}) : '';
}
sub secret_hidden_html ($) {