2003-04-23 21:01:18 +00:00
< ? php
2003-03-13 19:48:49 +00:00
/*
$Id $
This code is part of LDAP Account Manager ( http :// www . sourceforge . net / projects / lam )
Copyright ( C ) 2003 Michael Duergner
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation ; either version 2 of the License , or
( at your option ) any later version .
2003-03-14 11:32:28 +00:00
2003-03-13 19:48:49 +00:00
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
2003-03-14 11:32:28 +00:00
2003-03-13 19:48:49 +00:00
You should have received a copy of the GNU General Public License
along with this program ; if not , write to the Free Software
Foundation , Inc . , 59 Temple Place , Suite 330 , Boston , MA 02111 - 1307 USA
2003-03-14 11:32:28 +00:00
2003-04-23 22:00:42 +00:00
LDAP Account Manager checking login datas .
2003-03-13 19:48:49 +00:00
*/
2003-03-18 20:55:43 +00:00
2003-04-23 21:01:18 +00:00
include_once ( " ../lib/config.inc " ); // Include config.inc which provides Config class
2003-03-23 14:41:15 +00:00
2003-05-03 15:47:42 +00:00
session_save_path ( " ../sess " ); // Set session save path
2003-03-23 14:41:15 +00:00
@ session_start (); // Start LDAP Account Manager session
2003-04-23 21:01:18 +00:00
2003-07-20 18:28:38 +00:00
function display_LoginPage ( $config_object , $profile )
2003-04-23 21:01:18 +00:00
{
2003-05-12 20:46:58 +00:00
global $error_message ;
2003-04-23 21:01:18 +00:00
// generate 256 bit key and initialization vector for user/passwd-encryption
2003-10-02 17:54:04 +00:00
// check if we can use /dev/random otherwise use /dev/urandom or rand()
2003-10-18 11:26:49 +00:00
if ( function_exists ( mcrypt_create_iv )) {
$key = @ mcrypt_create_iv ( 32 , MCRYPT_DEV_RANDOM );
if ( ! $key ) $key = @ mcrypt_create_iv ( 32 , MCRYPT_DEV_URANDOM );
if ( ! $key ) {
srand (( double ) microtime () * 1234567 );
$key = mcrypt_create_iv ( 32 , MCRYPT_RAND );
}
$iv = @ mcrypt_create_iv ( 32 , MCRYPT_DEV_RANDOM );
if ( ! $iv ) $iv = @ mcrypt_create_iv ( 32 , MCRYPT_DEV_URANDOM );
if ( ! $iv ) {
srand (( double ) microtime () * 1234567 );
$iv = mcrypt_create_iv ( 32 , MCRYPT_RAND );
}
2003-10-02 17:54:04 +00:00
}
2003-04-23 21:01:18 +00:00
// save both in cookie
setcookie ( " Key " , base64_encode ( $key ), 0 , " / " );
setcookie ( " IV " , base64_encode ( $iv ), 0 , " / " );
2003-07-20 18:28:38 +00:00
$_SESSION [ 'language' ] = $config_object -> get_defaultLanguage ();
2003-08-08 13:30:23 +00:00
$current_language = explode ( " : " , $_SESSION [ 'language' ]);
2003-11-17 15:47:53 +00:00
$_SESSION [ 'header' ] = " <?xml version= \" 1.0 \" encoding= \" " . $current_language [ 1 ] . " \" ?> \n " ;
2003-11-17 15:50:52 +00:00
$_SESSION [ 'header' ] .= " <!DOCTYPE HTML PUBLIC \" -//W3C//DTD HTML 4.01 Transitional//EN \" \" http://www.w3.org/TR/html4/loose.dtd \" > \n \n " ;
2003-11-17 15:47:53 +00:00
$_SESSION [ 'header' ] .= " <html> \n <head> \n " ;
$_SESSION [ 'header' ] .= " <meta http-equiv= \" content-type \" content= \" text/html; charset= " . $current_language [ 1 ] . " \" > \n " ;
$_SESSION [ 'header' ] .= " <meta http-equiv= \" pragma \" content= \" no-cache \" > \n <meta http-equiv= \" cache-control \" content= \" no-cache \" > " ;
2003-05-12 20:46:58 +00:00
2003-04-23 21:01:18 +00:00
// loading available languages from language.conf file
2003-07-14 21:59:09 +00:00
$languagefile = " ../config/language " ;
2003-04-23 21:01:18 +00:00
if ( is_file ( $languagefile ) == True )
{
$file = fopen ( $languagefile , " r " );
$i = 0 ;
while ( ! feof ( $file ))
{
$line = fgets ( $file , 1024 );
2003-05-12 20:46:58 +00:00
if ( $line == " " || $line == " \n " || $line [ 0 ] == " # " ) continue ; // ignore comment and empty lines
2003-04-23 21:01:18 +00:00
$value = explode ( " : " , $line );
$languages [ $i ][ " link " ] = $value [ 0 ] . " : " . $value [ 1 ];
$languages [ $i ][ " descr " ] = $value [ 2 ];
2003-05-12 20:46:58 +00:00
if ( rtrim ( $line ) == $_SESSION [ " language " ])
{
$languages [ $i ][ " default " ] = " YES " ;
}
else
{
$languages [ $i ][ " default " ] = " NO " ;
}
2003-04-23 21:01:18 +00:00
$i ++ ;
}
fclose ( $file );
}
else
{
2003-05-03 15:47:42 +00:00
$message = _ ( " Unable to load available languages. Setting English as default language. For further instructions please contact the Admin of this site. " );
2003-04-23 21:01:18 +00:00
}
2003-07-14 21:59:09 +00:00
$profiles = getConfigProfiles ();
2003-05-07 19:53:58 +00:00
setlanguage (); // setting correct language
2003-07-23 08:08:25 +00:00
echo $_SESSION [ " header " ];
?>
< title > LDAP Account Manager - Login -</ title >
< link rel = " stylesheet " type = " text/css " href = " ../style/layout.css " >
</ head >
< body >
< p align = " center " >
2003-11-17 15:57:08 +00:00
< a href = " http://lam.sf.net " target = " _blank " >< img src = " ../graphics/banner.jpg " border = " 1 " alt = " LDAP Account Manager " ></ a >
2003-07-23 08:08:25 +00:00
</ p >
< table width = " 100% " border = " 0 " >
< tr >
< td width = " 100% " align = " right " >
< a href = " ./config/conflogin.php " target = " _self " >< ? php echo _ ( " Configuration Login " ); ?> </a>
</ td >
</ tr >
</ table >
< hr >< br >< br >
2003-10-18 11:26:49 +00:00
< ? php
if ( ! function_exists ( 'mcrypt_create_iv' )) {
StatusMessage ( " ERROR " , " Your PHP does not support MCrypt, you will not be able to log in! Please install the required package. " , " See http://lam.sf.net/documentation/faq.html#2 for Suse/RedHat " );
?>
</ body >
</ html >
< ? php
exit ;
}
if ( ! function_exists ( 'mHash' )) {
StatusMessage ( " WARN " , " Your PHP does not support MHash, you will only be able to use CRYPT/PLAIN for user passwords! Please install the required package. " , " See http://lam.sf.net/documentation/faq.html#2 for Suse/RedHat " );
}
?>
2003-07-23 08:08:25 +00:00
< p align = " center " >
2003-08-16 17:30:20 +00:00
< b >< ? php echo _ ( " Enter Username and Password for Account " ) . " : " ; ?> </b>
2003-07-23 08:08:25 +00:00
</ p >
< ? php
if ( $error_message != " " ) {
?>
< p align = " center " >
< ? php
echo $error_message ;
?>
</ p >
< ? php
}
?>
< form action = " login.php " method = " post " >
< input type = " hidden " name = " action " value = " checklogin " >
< table width = " 500 " align = " center " border = " 0 " >
2003-04-23 21:01:18 +00:00
< tr >
2003-07-23 08:08:25 +00:00
< td width = " 45% " align = " right " >
< ? php
2003-08-16 17:30:20 +00:00
echo _ ( " Username " ) . " : " ;
2003-07-23 08:08:25 +00:00
?>
</ td >
< td width = " 10% " >
</ td >
< td width = " 45% " align = " left " >
< select name = " username " size = " 1 " >
< ? php
2003-09-21 20:08:36 +00:00
$admins = $config_object -> get_Admins ();
2003-09-21 20:03:40 +00:00
for ( $i = 0 ; $i < count ( $admins ); $i ++ ) {
$text = explode ( " , " , $admins [ $i ]);
2003-07-23 08:08:25 +00:00
$text = explode ( " = " , $text [ 0 ]);
?>
2003-09-21 20:07:15 +00:00
< option value = " <?php echo $admins[$i] ; ?> " >< ? php echo $text [ 1 ]; ?> </option>
2003-07-23 08:08:25 +00:00
< ? php
}
?>
</ select >
2003-04-23 21:01:18 +00:00
</ td >
</ tr >
2003-07-23 08:08:25 +00:00
< tr >
< td width = " 45% " align = " right " >
< ? php
2003-08-16 17:30:20 +00:00
echo _ ( " Password " ) . " : " ;
2003-07-23 08:08:25 +00:00
?>
</ td >
< td width = " 10% " >
</ td >
< td width = " 45% " align = " left " >
< input type = " password " name = " passwd " >
</ td >
</ tr >
< tr >
< ? php
if ( $message != " " ) {
?>
< td width = " 100% " colspan = " 3 " align = " center " >
< ? php
echo $message ;
?>
2003-08-16 17:30:20 +00:00
< input type = " hidden " name = " language " value = " english " >
2003-07-23 08:08:25 +00:00
</ td >
< ? php
2003-04-23 21:01:18 +00:00
}
2003-07-23 08:08:25 +00:00
else
{
?>
< td width = " 45% " align = " right " >
< ? php
2003-08-16 17:30:20 +00:00
echo _ ( " Your Language " ) . " : " ;
2003-07-23 08:08:25 +00:00
?>
</ td >
< td width = " 10% " >
</ td >
< td width = " 45% " align = " left " >
< select name = " language " size = " 1 " >
< ? php
for ( $i = 0 ; $i < count ( $languages ); $i ++ ) {
if ( $languages [ $i ][ " default " ] == " YES " ) {
?>
< option selected value = " <?php echo $languages[$i] [ " link " ] . " : " . $languages[$i] [ " descr " ]; ?> " >< ? php echo $languages [ $i ][ " descr " ]; ?> </option>
< ? php
2003-04-23 21:01:18 +00:00
}
else
{
2003-07-23 08:08:25 +00:00
?>
< option value = " <?php echo $languages[$i] [ " link " ] . " : " . $languages[$i] [ " descr " ]; ?> " >< ? php echo $languages [ $i ][ " descr " ]; ?> </option>
< ? php
2003-04-23 21:01:18 +00:00
}
2003-07-23 08:08:25 +00:00
}
?>
</ select >
</ td >
< ? php
}
?>
</ tr >
< tr >
< td width = " 100% " colspan = " 3 " align = " center " >
< input type = " submit " name = " submit " value = " <?php echo _( " Login " ); ?> " >
</ td >
</ tr >
</ table >
< br >< br >
< table width = " 345 " align = " center " bgcolor = " #C7E7C7 " border = " 0 " >
< tr >
< td width = " 100% " align = " center " >
< ? php
2003-08-16 17:30:20 +00:00
echo _ ( " You are connecting to ServerURL " ) . " : " ;
2003-07-23 08:08:25 +00:00
?>
< b >< ? php echo $config_object -> get_ServerURL (); ?> </b>
</ td >
</ tr >
</ table >
</ form >
< br >< br >
< form action = " ./login.php " method = " post " enctype = " plain/text " >
< input type = " hidden " name = " action " value = " profileChange " >
< p align = " center " >
< ? php
2003-08-16 17:30:20 +00:00
echo _ ( " You are currently using Profile " ) . " : " ;
2003-07-23 08:08:25 +00:00
if ( ! $_POST [ 'profile' ]) {
$_POST [ 'profile' ] = $profile ;
}
?>
< b >< ? php echo $_POST [ 'profile' ]; ?> </b>
< br >
< select name = " profile " size = " 1 " >
< ? php
for ( $i = 0 ; $i < count ( $profiles ); $i ++ ) {
?>
< option value = " <?php echo $profiles[$i] ; ?> " >< ? php echo $profiles [ $i ]; ?> </option>
< ? php
}
?>
</ select >
< input type = " submit " value = " <?php echo _( " Change Profile " ); ?> " >
</ p >
</ form >
</ body >
</ html >
< ? php
2003-04-23 21:01:18 +00:00
}
2003-03-14 11:32:28 +00:00
// checking if the submitted username/password is correct.
2003-05-03 15:47:42 +00:00
if ( $_POST [ 'action' ] == " checklogin " )
2003-03-14 11:32:28 +00:00
{
2003-10-18 11:26:49 +00:00
$_SESSION [ 'lampath' ] = realpath ( '../' ) . " / " ; // Save full path to lam in session
$_SESSION [ 'lamurl' ] = substr ( $_SERVER [ 'HTTP_REFERER' ], 0 , strlen ( $_SERVER [ 'HTTP_REFERER' ]) - 19 ); // Save full URI to lam in session
2003-04-23 21:01:18 +00:00
include_once ( " ../lib/ldap.inc " ); // Include ldap.php which provides Ldap class
2003-03-20 16:41:52 +00:00
2003-08-13 19:21:36 +00:00
$_SESSION [ 'ldap' ] = new Ldap ( $_SESSION [ 'config' ]); // Create new Ldap object
2003-10-18 11:26:49 +00:00
2003-05-18 18:59:02 +00:00
if ( $_POST [ 'passwd' ] == " " )
2003-03-14 11:32:28 +00:00
{
2003-05-18 18:59:02 +00:00
$error_message = _ ( " Empty Password submitted. Try again. " );
2003-07-20 18:28:38 +00:00
display_LoginPage ( $_SESSION [ 'config' ], " " ); // Empty password submitted. Return to login page.
2003-03-14 11:32:28 +00:00
}
2003-03-15 12:13:49 +00:00
else
2003-03-14 11:32:28 +00:00
{
2003-07-20 18:36:39 +00:00
$result = $_SESSION [ 'ldap' ] -> connect ( $_POST [ 'username' ], $_POST [ 'passwd' ]); // Connect to LDAP server for verifing username/password
2003-10-18 11:26:49 +00:00
2003-05-18 18:59:02 +00:00
if ( $result == True ) // Username/password correct. Do some configuration and load main frame.
2003-03-15 12:13:49 +00:00
{
2003-10-22 17:42:12 +00:00
$_SESSION [ 'loggedIn' ] = true ;
2003-07-20 18:28:38 +00:00
$_SESSION [ 'language' ] = $_POST [ 'language' ]; // Write selected language in session
2003-08-08 15:07:47 +00:00
$current_language = explode ( " : " , $_SESSION [ 'language' ]);
2003-11-17 15:47:53 +00:00
$_SESSION [ 'header' ] = " <?xml version= \" 1.0 \" encoding= \" " . $current_language [ 1 ] . " \" ?> \n " ;
2003-11-17 15:50:52 +00:00
$_SESSION [ 'header' ] .= " <!DOCTYPE HTML PUBLIC \" -//W3C//DTD HTML 4.01 Transitional//EN \" \" http://www.w3.org/TR/html4/loose.dtd \" > \n \n " ;
2003-11-17 15:47:53 +00:00
$_SESSION [ 'header' ] .= " <html> \n <head> \n " ;
$_SESSION [ 'header' ] .= " <meta http-equiv= \" content-type \" content= \" text/html; charset= " . $current_language [ 1 ] . " \" > \n " ;
$_SESSION [ 'header' ] .= " <meta http-equiv= \" pragma \" content= \" no-cache \" > \n <meta http-equiv= \" cache-control \" content= \" no-cache \" > " ;
2003-07-20 18:28:38 +00:00
2003-05-18 18:59:02 +00:00
include ( " ./main.php " ); // Load main frame
2003-03-15 12:13:49 +00:00
}
else
{
2003-05-18 18:59:02 +00:00
if ( $ldap -> server )
{
2003-09-10 19:10:13 +00:00
$error_message = _ ( " Wrong Password/Username combination. Try again. " );
2003-07-20 18:28:38 +00:00
display_LoginPage ( $_SESSION [ 'config' ], " " ); // Username/password invalid. Return to login page.
2003-05-18 18:59:02 +00:00
}
else
{
$error_message = _ ( " Cannot connect to specified LDAP-Server. Try again. " );
2003-07-20 18:28:38 +00:00
display_LoginPage ( $_SESSION [ 'config' ], " " ); // Username/password invalid. Return to login page.
2003-05-18 18:59:02 +00:00
}
2003-03-15 12:13:49 +00:00
}
2003-03-14 11:32:28 +00:00
}
}
2003-07-14 21:59:09 +00:00
// Reload loginpage after a profile change
elseif ( $_POST [ 'action' ] == " profileChange " ) {
2003-08-13 19:18:56 +00:00
$_SESSION [ 'config' ] = new Config ( $_POST [ 'profile' ]); // Recreate the config object with the submited
2003-07-14 21:59:09 +00:00
2003-08-13 19:18:56 +00:00
display_LoginPage ( $_SESSION [ 'config' ], " " ); // Load login page
2003-07-14 21:59:09 +00:00
}
2003-03-23 14:41:15 +00:00
// Load login page
2003-03-14 11:32:28 +00:00
else
{
2003-10-22 17:42:12 +00:00
$_SESSION [ 'loggedIn' ] = false ;
2003-07-14 21:59:09 +00:00
$default_Config = new CfgMain ();
$default_Profile = $default_Config -> default ;
2003-07-20 18:28:38 +00:00
$_SESSION [ " config " ] = new Config ( $default_Profile ); // Create new Config object
2003-03-20 16:37:20 +00:00
2003-07-20 18:28:38 +00:00
display_LoginPage ( $_SESSION [ " config " ], $default_Profile ); // Load Login page
2003-03-14 11:32:28 +00:00
}
2003-08-16 17:30:20 +00:00
?>