From 13b940c109b60f8de45794021b14b66950bbd19a Mon Sep 17 00:00:00 2001 From: Bradley M. Froehle Date: Tue, 22 Feb 2011 15:34:02 -0800 Subject: [PATCH] 1059942 - 16 --- cas.module | 118 ++++++++++++++++++++++++++++++++--------------------------- 1 files changed, 64 insertions(+), 54 deletions(-) diff --git cas.module cas.module index 5b05224..dd586d0 100644 --- cas.module +++ cas.module @@ -61,7 +61,7 @@ function cas_menu_logout_check() { * */ function cas_login_check() { - global $user, $account; + global $user; if ($user->uid) { //Don't Login because we already are return; @@ -154,7 +154,7 @@ function cas_login_check() { // We're done cause we're not logged in. if (!$logged_in) return; - } + } else { phpCAS::forceAuthentication(); } @@ -169,7 +169,10 @@ function cas_login_check() { // Bail out if a module denied login access for this user or unset the user name. if (empty($cas_user['login']) || empty($cas_user['name'])) { - drupal_set_message(t('The user account %name is not available on this site.', array('%name' => $cas_name)), 'error'); + // Only set a warning if we forced login. + if ($cas_force_login) { + drupal_set_message(t('The user account %name is not available on this site.', array('%name' => $cas_name)), 'error'); + } return; } @@ -177,31 +180,31 @@ function cas_login_check() { $cas_name = $cas_user['name']; // blocked user check + $blocked = FALSE; if (($cas_authmap == CAS_AUTHMAP_INTERNAL) && user_is_blocked($cas_name)) { // blocked in user administration - drupal_set_message(t('The username %name has been blocked.', array('%name' => $cas_name)), 'error'); - return; + $blocked = 'The username %cas_name has been blocked.'; } - - - // this is because users can change their name. - if (($cas_authmap == CAS_AUTHMAP_EXTERNAL) && _cas_external_user_is_blocked($cas_name)) { - - // blocked in user administration - drupal_set_message(t('The username %name has been blocked.', array('%name' => $cas_name)), 'error'); - return; + // this is because users can change their name. + // users are external; use cas_user table for associating external users + elseif (($cas_authmap == CAS_AUTHMAP_EXTERNAL) && _cas_external_user_is_blocked($cas_name)) { + $blocked = 'The username %cas_name has been blocked.'; } - - - if (drupal_is_denied('user', $cas_name)) { - - - // denied by access controls - drupal_set_message(t('The name %name is a reserved username.', array('%name' => $cas_name)), 'error'); + // @todo The D7 equivalent here must have been renamed. + // elseif (drupal_is_denied('user', $cas_name)) { + // // denied by access controls + // return 'The name %cas_name is a reserved username.'; + // } + + if ($blocked) { + // Only display error messages only if the user intended to log in. + if ($cas_force_login) { + watchdog('cas', $blocked, array('%cas_name' => $cas_name), WATCHDOG_WARNING); + drupal_set_message(t($blocked, array('%cas_name' => $cas_name)), 'error'); + } return; - } + } - // try to log into Drupal if ($cas_authmap == CAS_AUTHMAP_INTERNAL) { // users are coming from Drupal; no need to use the external_load and the authmap @@ -213,7 +216,7 @@ function cas_login_check() { if ($uid) { $acct = user_load($uid); } - if (empty($acct) && variable_get('cas_hijack_user', 0)) { + if (empty($acct) && $cas_force_login && variable_get('cas_hijack_user', 0)) { $acct = user_load_by_name($cas_name); if (isset($acct->uid)) { @@ -227,7 +230,6 @@ function cas_login_check() { } } - // If we don't have a user register them. if (empty($acct) || !$acct->uid ) { if ($cas_user['register']) { @@ -264,28 +266,29 @@ function cas_login_check() { // final check to make sure we have a good user if (!empty($acct) && $acct->uid > 0) { - - // Save single sign out information - if (!empty($_SESSION['cas_ticket']) && variable_get('cas_signout', FALSE)) { - _cas_single_sign_out_save_token($acct); - } + // Save single sign out information + if (!empty($_SESSION['cas_ticket']) && variable_get('cas_signout', FALSE)) { + _cas_single_sign_out_save_token($acct); + } - // Populate $edit with some basic properties. - $edit['cas_user'] = $cas_user; - $edit['roles'] = $acct->roles + $cas_roles; - if (module_exists('persistent_login') && $_SESSION['cas_remember']) { - $edit['persistent_login'] = 1; - } - cas_user_module_invoke('presave', $edit, $acct); - $user = user_save($acct, $edit); - user_login_finalize($edit); - drupal_set_message(t(variable_get('cas_login_message', 'Logged in via CAS as %cas_username.'), array('%cas_username' => $user->name))); - if (!empty($edit['persistent_login']) && $edit['persistent_login']== 1) { - drupal_set_message(t('You will remain logged in on this computer even after you close your browser.')); - } - // We can't count on the menu because we're changing login states. - - cas_login_page(); + // Populate $edit with some basic properties. + $edit['cas_user'] = $cas_user; + $edit['roles'] = $acct->roles + $cas_roles; + if (module_exists('persistent_login') && $_SESSION['cas_remember']) { + $edit['persistent_login'] = 1; + } + // Allow other modules to make their own custom changes. + cas_user_module_invoke('presave', $edit, $acct); + + // Save the user account and log the user in. + $user = user_save($acct, $edit); + user_login_finalize($edit); + drupal_set_message(t(variable_get('cas_login_message', 'Logged in via CAS as %cas_username.'), array('%cas_username' => $user->name))); + if (!empty($edit['persistent_login']) && $edit['persistent_login']== 1) { + drupal_set_message(t('You will remain logged in on this computer even after you close your browser.')); + } + + cas_login_page(); } // if we have a good user else { @@ -293,7 +296,10 @@ function cas_login_check() { // tests? //session_destroy(); $user = drupal_anonymous_user(); - drupal_set_message(t('No account found for %cas_name.', array('%cas_name' => $cas_name))); + // Only display error messages only if the user intended to log in. + if ($cas_force_login) { + drupal_set_message(t('No account found for %cas_name.', array('%cas_name' => $cas_name))); + } } } // End if user is already logged in else @@ -881,17 +887,21 @@ function _cas_single_sign_out_save_ticket() { } } -function _cas_external_user_is_blocked($name) { - $deny=FALSE; - $result = db_query("SELECT u.name FROM {users} u JOIN {cas_user} c ON u.uid=c.uid WHERE status = 0 AND c.cas_name = LOWER(:uid)", array(':uid' => $name)); - foreach ($result as $record) { - if ($record->name) $deny = TRUE; - } - return $deny; +/** + * Determine whether a CAS user is blocked. + * + * @param $cas_name + * The CAS user name. + * + * @return + * Boolean TRUE if the user is blocked, FALSE if the user is active. + */ +function _cas_external_user_is_blocked($cas_name) { + return db_query("SELECT name FROM {users} u JOIN {cas_user} c ON u.uid = c.uid WHERE u.status = 0 AND c.cas_name = :cas_name", array(':cas_name' => $cas_name))->fetchField(); } /** - * Invokes hook_cas_user() in every module. + * Invokes hook_cas_user_TYPE() in every module. * * We cannot use module_invoke() because the arguments need to be passed by * reference. -- 1.7.3.5