Subversion Repositories wimsdev

Rev

Rev 5108 | Rev 12845 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log | RSS feed

Rev Author Line No. Line
23 reyssat 1
!if $auth_password=*wims_site_manager
2
 !if $wims_ismanager<2
3
  auth_password=
4
 !else
5
  !goto auth_ok
6
 !endif
7
!endif
8
 
4360 guerimand 9
!if $save_logincgu!=$empty
10
 !if $agreecgu=yes
5100 bpr 11
  !read adm/class/userdef wimshome/log/classes,$class,$save_logincgu
12
  !setdef !set user_agreecgu=yes in $userdef
13
  !readdef $userdef
14
  !reset error
15
  !if $auth_test=OK
16
     !goto auth_ok2
17
  !endif
4360 guerimand 18
 !endif
5100 bpr 19
 !!!reset $save_logincgu
4360 guerimand 20
!endif
21
 
23 reyssat 22
!read adm/class/authchars
23
auth_user=!word 1 of $auth_user
24
auth_password=!word 1 of $auth_password
633 bpr 25
 
5015 bpr 26
# new variables to keep original data (used only in external authentication)
633 bpr 27
auth_user_connection=$auth_user
28
auth_password_connection=$auth_password
29
 
4993 bpr 30
##### EXTERNAL connection - part 1 #####
5028 bpr 31
!!default sclass=$class
633 bpr 32
 
5028 bpr 33
!if ($auth_user notsametext supervisor or $class_type>0) and $auth_method isitemof $auth_method_list
5015 bpr 34
 authdef=wimshome/log/classes/$superclass/.def
5028 bpr 35
 
633 bpr 36
 # don't use auth_user and auth_password, some characters are unvailable
4993 bpr 37
 # parameters are empty for auth-cas
633 bpr 38
 !readproc adm/class/auth-$auth_method $auth_user_connection,$auth_password_connection
39
 
40
!endif
4993 bpr 41
##### end of EXTERNAL connection - part 1 #####
633 bpr 42
# now we can run the script
5015 bpr 43
!if $auth_method isitemof $auth_method_list and $auth_user!=supervisor
5034 czzmrn 44
  auth_user=!lookup $auth_user_orig in wimshome/log/classes/$superclass/.userlist_external
45
  !if $auth_user=$empty
46
    auth_user=!lookup $auth_user_orig in wimshome/log/classes/$superclass/.teacherlist_external
47
  !endif
4993 bpr 48
!endif
23 reyssat 49
auth_user=!translate internal . to @ in $auth_user
50
auth_user=!text select $char_login in $auth_user
51
auth_password=!text select $char_passwd in $auth_password
52
now=$wims_now
53
logfile=wimshome/log/classes/$class/.log.auth
54
logfiles=wimshome/log/classes/$class/.log
55
logline=$now $auth_user  	$$passwd	$httpd_REMOTE_ADDR
56
 
57
!read adm/class/userdef classes,$class,$auth_user
58
 
59
pass=!defof user_password in $userdef
5015 bpr 60
FIXME ### Have to check that sclass is no yet useful
61
sclass=!defof class_superclass in wimshome/log/classes/$class/.def
62
!if $superclass!=$empty and $superclass!=$class
23 reyssat 63
 upartic=!defof user_participate in $userdef
64
 usuperv=!defof user_supervise in $userdef
65
 pclass=!defof class_parent in wimshome/log/classes/$class/.def
66
 !if / isin $pclass and ../$pclass/ isin ../$class
67
  ss=!defof class_ocourses in wimshome/log/classes/$pclass/.def
68
  !if $ss!=$empty
69
   ss=!makelist $wims_superclass/xx for xx in $ss
70
   upartic=!append item $ss to $upartic
71
  !endif
72
 !endif
73
 coursecheck=!defof user_class in wimshome/log/classes/$class/.users/$auth_user
74
 !if $coursecheck!=$empty
75
  upartic=!append item $class to $upartic
76
 !endif
5108 bpr 77
 !!check mandatory course
78
 dcourse=!record 0 of wimshome/log/classes/$pclass/courses
79
 dcourse=!column 1 of $dcourse
80
 !if $dcourse!=$empty
81
     dcourse=!makelist $wims_superclass/xx for xx in $dcourse
82
     upartic=!append item $dcourse to $upartic
83
 !endif
84
 upartic=!listuniq $upartic
23 reyssat 85
 !if $auth_user=supervisor and $wims_user=supervisor
86
  ctype=!defof class_typename in wimshome/log/classes/$class/.def
87
  prog=!defof sharing_exam in wimshome/log/classes/$class/neighbors
88
  !if $ctype iswordof course icourse and $prog=$wims_class
89
   pass=$current_pass
90
  !endif
91
 !endif
10171 bpr 92
!!upartic : no more authentification should check for optional courses ?
5001 bpr 93
 !if $class notitemof $upartic and $auth_user!=supervisor and $wims_user!=supervisor
23 reyssat 94
  pass=
95
 !endif
96
# These lines should be opened later to close this possibility.
97
# !if $auth_user=supervisor and $wims_user=$empty
98
#  pass=
99
# !endif
100
!endif
101
 
5001 bpr 102
!if $auth_user=supervisor
103
 !goto wimsauth
104
!endif
105
 
4993 bpr 106
##### final test of external connection #####
107
# finaly, we must check if user is allowed in class
633 bpr 108
 
23 reyssat 109
exist_check=!defof user_exists in $userdef
5016 bpr 110
 
5015 bpr 111
!if OK iswordof $auth_test and $auth_method isitemof $auth_method_list
4993 bpr 112
 !if $exist_check issametext yes
113
   !goto auth_ok
114
 !else
115
   !setdef user_auth=$auth_user_orig in wimshome/$wims_sesdir/var.stat
5001 bpr 116
   !goto end
4993 bpr 117
 !endif
23 reyssat 118
!endif
4993 bpr 119
##### end of final test of external connection #####
5001 bpr 120
:wimsauth
5015 bpr 121
 
23 reyssat 122
pass=!passcrypt $pass
123
!if $pass=$empty
5092 bpr 124
  !if $auth_user_connection=$empty
5045 bpr 125
    !exit
126
  !endif
23 reyssat 127
 passwd=????
128
 !appendfile $logfile $logline
5092 bpr 129
 auth_user=$auth_user_connection
23 reyssat 130
 error=bad_password
131
 !exit
132
!endif
133
 
134
!if $wims_superclass!=$empty and $wims_user!=supervisor and $auth_user!=$wims_user
135
 supervisable=!defof user_supervisable in wimshome/log/classes/$wims_superclass/.users/$wims_user
136
 !if $supervisable!=yes
137
  current_pass=
138
 !endif
139
!endif
140
 
141
cps=!passcrypt $current_pass
142
!if ($auth_user!=$empty and $class $auth_user isitemof $wims_otherclass) or \
143
	($current_pass!=$empty and $cps iswordof $pass) or \
144
	($auth_user=$wims_user and $class isitemof $wims_participate) or \
145
	($auth_user=supervisor and $wims_user=supervisor and \
5015 bpr 146
		(../$wims_class/ isin ../$class/ or $superclass=$wims_class)) or \
23 reyssat 147
	($auth_user=supervisor and $class isitemof $wims_supervise)
148
 !goto auth_ok
149
!endif
150
 
151
!if $auth_password=$empty
152
 !exit
153
!endif
154
 
155
!read adm/class/authdelay
156
!if $auth_password notwordof $pass
5045 bpr 157
  !if $auth_user_orig=$empty and $auth_password=$empty
158
    !exit
159
  !endif
23 reyssat 160
 passwd=??????
161
 !appendfile $logfile $logline
3494 bpr 162
 auth_user=$auth_user_orig
23 reyssat 163
 error=bad_password
164
 !exit
165
!endif
166
 
167
:auth_ok
168
!if $auth_user=supervisor and $wims_user!=$empty and $wims_user!=supervisor and \
169
	$class notitemof $wims_supervise
170
 userdef_save=$userdef
171
 !read adm/class/userdef classes,$wims_class,$wims_user
172
 !exchange userdef_save,userdef
173
 spv=!defof user_supervisable in $userdef_save
174
 !if $spv=yes
175
  wims_supervise=!append item $class to $wims_supervise
176
  !setdef !set user_supervise=$wims_supervise in $userdef_save
177
 !endif
178
!endif
179
n=!positionof word $auth_password in $pass
180
n=!item 1 of $n
181
!if $n!=$empty
182
 passwd=OK$n   $
183
!else
184
 passwd=$wims_class
185
!endif
186
# one-time password
187
!if $n!=$empty and $n>1
188
 pass=!replace word $auth_password by $ in $pass
189
 pass=!singlespace $pass
190
 pass=!trim $pass
191
 !setdef !set user_password=$pass in $userdef
192
!endif
5100 bpr 193
:auth_ok2
23 reyssat 194
 
195
!defread $userdef
196
ctype=!defof class_type in wimshome/log/classes/$class/.def
197
!if $ctype=4 and $auth_user!=supervisor and $user_supervisable!=yes\
198
  and (/ notin $wims_class or ../$wims_superclass/ notin ../$wims_class/)
199
 utest=!itemcnt $user_participate
200
 !if $utest=1 and / isin $user_participate
201
  class=!item 1 of $user_participate
202
  !defread wimshome/log/classes/$class/.def
203
 !endif
204
!endif
205
clang=!defof class_lang in wimshome/log/classes/$class/.def
206
 
4360 guerimand 207
 
208
 
23 reyssat 209
!if $auth_user=supervisor
210
 sech=!defof class_secure in wimshome/log/classes/$class/.def
211
 sech=!trim $sech
212
 !if $sech=$empty
213
  t=0
214
 !else
215
  t=!checkhost $sech
216
  !if $t<1
217
   t=-1
218
  !endif
219
 !endif
220
 sup_secure=$t
221
!else
222
 !read adm/class/raftest
223
 !if $raftest>$lastallow
224
  error=recent_rafale
225
  !exit
226
 !endif
227
 sup_secure=-1
5100 bpr 228
 !if $user_agreecgu notwordof yes external and $agreecgu!=yes
4360 guerimand 229
  error=no_cgu
230
  !exit
231
 !endif
23 reyssat 232
!endif
233
 
234
!read adm/class/authprep $class,$auth_user
235
 
236
!if $logfile!=$empty
237
 !if $auth_user=supervisor
238
  !appendfile $logfiles $now $httpd_REMOTE_ADDR   	supervisor login
239
 !else
240
  !appendfile $logfile $logline
241
 !endif
242
!endif
243
 
244
!if $class_lock=7 and $auth_user!=supervisor
245
 !usererror class_closed
246
 !exit
247
!endif
248
 
249
!if $class_lock iswordof 2 4 6
250
 !set wims_protocol=https
251
!endif
252
!if $wims_user=$empty and $changesession!=no
253
 !writefile wimshome/$wims_sesdir/var.class.prep $classdef
254
 random=!randint 10^5,10^9
255
 !restart session=new.$random&lang=$clang&old_session=$wims_session&module=home
256
!else
257
 !setdef $classdef in wimshome/$wims_sesdir/var.stat
258
 !sh cd $wims_home\
259
 	rm -Rf $(wims_sesdir)_*\
260
	mkdir -p log/classes/$class/score $wims_sesdir/getfile\
261
	rm -f $wims_sesdir/exam*\
262
	rm -f $wims_sesdir/getfile/oefimages\
263
	ln -s $wims_home/log/classes/$class/src/images $wims_sesdir/getfile/oefimages
264
 !restart lang=$clang&module=home
265
!endif
266
 
10171 bpr 267
:end