array('cn', 'uid', 'uidNumber'), 'host' => array('cn', 'uid', 'uidNumber') ) ); // unique array $_SESSION['cacheAttributes'] = array_unique ($_SESSION['cacheAttributes']); // Array with all attributes and type $basearray['attributes'] = array_merge ($basearray['attributes'], array ( 0 => array('cn', 'string', 'must'), 1 => array('uid', 'string', 'must'), 2 => array('uidNumber', 'string', 'must'), 3 => array('gidNumber', 'string', 'must'), 4 => array('homeDirectory', 'string', 'must'), 5 => array('loginShell', 'string', 'may'), 6 => array('gecos', 'string', 'may'), 7 => array('description', 'string', 'may'), 8 => array('userPassword', 'function', 'may'), 9 => array('userPassword_no', 'boolean', 'may') )); // unique array $basearray['attributes'] = array_unique($basearray['attributes']); // Add account type to object $this->type = $basearray['type']; $orig = array( 'cn' => '', 'uid' => '', 'uidNumber' => '', 'gidNumber' => '', 'homeDirectory' => '', 'loginShell' => '', 'gecos' => '', 'description' => '', 'enc_userPassword' => '' ); $this->alias = _('posixAccount'); } // Variables // Alias Name. This name is shown in the menu instead of posixAccount var $alias; // original name is userPassword. This variable is used to store the encrypted password var $enc_userPassword; // we can't read type from array so we have to store it also in object var $type; // Use a unix password? var $userPassword_no; // Lock account? var $userPassword_lock; // Array with all groups the user should also be member of var $groups; // LDAP attributes // These attributes have to be set in ldap var $cn; var $uid; var $uidNumber; var $gidNumber; var $homeDirectory; // These attributes doesn't have to be set in ldap var $loginShell; var $gecos; var $description; /* This function will return the unencrypted password when * called without a variable * If it's called with a new password, the * new password will be stored encrypted */ function userPassword($newpassword='') { // Read existing password if set if ($newpassword='') { if ($this->enc_userPassword != '') { $iv = base64_decode($_COOKIE["IV"]); $key = base64_decode($_COOKIE["Key"]); $password = mcrypt_decrypt(MCRYPT_RIJNDAEL_256, $key, base64_decode($this->enc_userPassword), MCRYPT_MODE_ECB, $iv); $password = str_replace(chr(00), '', $password); return $password; } else return ''; } // Write new password else { $iv = base64_decode($_COOKIE["IV"]); $key = base64_decode($_COOKIE["Key"]); $this->enc_userPassword = base64_encode(mcrypt_encrypt(MCRYPT_RIJNDAEL_256, $key, $newpassword, MCRYPT_MODE_ECB, $iv)); return 0; } } /* If an account was loaded all attributes are kept in this array * to compare it with new changed attributes */ var $orig; /* Write variables into object and do some regexp checks */ function proccess_attributes() { // Load attributes $this->uid = $_POST['form_posixAccount_uid']; // *** fixme how can this handeled better? $this->cn &= $this->uid; $this->uidNumber = $_POST['form_posixAccount_uidNumber']; $this->gidNumber = getgrnam($_POST['form_posixAccount_gidNumber']); $this->homeDirectory = $_POST['form_posixAccount_homeDirectory']; $this->loginShell = $_POST['form_posixAccount_loginShell']; $this->gecos = $_POST['form_posixAccount_gecos']; $this->description = $_POST['form_posixAccount_description']; if ($_POST['form_posixAccount_userPassword_no']; $this->userPassword_no=true; else $this->userPassword_no=false; if ($_POST['form_posixAccount_userPassword_lock']; $this->userPassword_lock=true; else $this->userPassword_lock=false; if (isset($_POST['form_posixAccount_userPassword'])) { if ($_POST['form_posixAccount_userPassword'] != $_POST['form_posixAccount_userPassword2']) { $errors[] = array('ERROR', _('Password'), _('Please enter the same password in both password-fields.')); unset ($_POST['form_posixAccount_userPassword2']); } else $this->userPassword($_POST['form_posixAccount_userPassword']); } if ($_POST['form_posixAccount_genpass']) $this->userPassword(genpasswd()); // Check if Username contains only valid characters if ( !ereg('^([a-z]|[A-Z]|[0-9]|[.]|[-]|[_])*$', $this->uid)) $errors[] = array('ERROR', _('Username'), _('Username contains invalid characters. Valid characters are: a-z, A-Z, 0-9 and .-_ !')); // Create automatic useraccount with number if original user already exists // Reset name to original name if new name is in use // *** fixme make incache modularized. Incache will return the found attribute // Set username back to original name if new username is in use if (incache($this,'uid', '*')!=$this->orig['uid'] && ($this->orig['uid']!='')) $this->uid = $this->orig['uid']; // Change uid to a new uid until a free uid is found while (incache($this, 'uid', '*')) { // Remove "$" at end of hostname if type is host if ($this->type=='host') $this->uid = substr($this->uid, 0, $this->uid-1); // get last character of username $lastchar = substr($this->uid, strlen($this->uid)-1, 1); // Last character is no number if ( !ereg('^([0-9])+$', $lastchar)) /* Last character is no number. Therefore we only have to * add "2" to it. */ if ($this->type=='host') $this->uid = $this->uid . '2$'; else $this->uid = $this->uid . '2'; else { /* Last character is a number -> we have to increase the number until we've * found a groupname with trailing number which is not in use. * * $i will show us were we have to split groupname so we get a part * with the groupname and a part with the trailing number */ $i=strlen($this->uid)-1; $mark = false; // Set $i to the last character which is a number in $account_new->general_username while (!$mark) { if (ereg('^([0-9])+$',substr($this->uid, $i, strlen($this->uid)-$i))) $i--; else $mark=true; } // increase last number with one $firstchars = substr($this->uid, 0, $i+1); $lastchars = substr($this->uid, $i+1, strlen($this->uid)-$i); // Put username together $this->uid = $firstchars . (intval($lastchars)+1); // Add $ name if type is host if ($this->type=='host') $this->uid .= '$'; } } // Show warning if lam has changed username if ($this->uid != $_POST['form_posixAccount_uid']) $errors[] = array('WARN', _('Username'), _('Username in use. Selected next free username.')); // Check if UID is valid. If none value was entered, the next useable value will be inserted // load min and may uidNumber if ($this->type=='user') { $minID = intval($_SESSION['config']->get_minUID()); $maxID = intval($_SESSION['config']->get_maxUID()); } else { $minID = intval($_SESSION['config']->get_minMachine()); $maxID = intval($_SESSION['config']->get_maxMachine()); } // *** fixme create getcache function $uids = getcache('uidNumber', 'posixAccount', '*'); if(is_array($uids)) sort ($uids, SORT_NUMERIC); if ($this->uidNumber=='') { // No id-number given if ($this->orig['uidNumber']=='') { // new account -> we have to find a free id-number if (count($uids)!=0) { // There are some uids // Store highest id-number $id = $uids[count($uids)-1]; // Return minimum allowed id-number if all found id-numbers are too low if ($id < $minID) $this->uidNumber = $minID; // Return higesht used id-number + 1 if it's still in valid range if ($id < $maxID) $this->uidNumber = $id+1; /* If this function is still running we have to fid a free id-number between * the used id-numbers */ $i = intval($minID); while (in_array($i, $uids)) $i++; if ($i>$maxID) $errors[] = array('ERROR', _('ID-Number'), _('No free ID-Number!'))))); else { $this->uidNumber = $i; $errors[] = array('WARN', _('ID-Number'), _('It is possible that this ID-number is reused. This can cause several problems because files with old permissions might still exist. To avoid this warning set maxUID to a higher value.')); } } else $this->uidNumber = $minID; // return minimum allowed id-number if no id-numbers are found } else $this->uidNumber = $this->orig['uidNumber']; // old account -> return id-number which has been used } else { // Check manual ID // id-number is out of valid range if ( $this->uidNumber < $minID || $this->uidNumber > $maxID) $errors[] = array('ERROR', _('ID-Number'), sprintf(_('Please enter a value between %s and %s!'), $minID, $maxID)); // $uids is allways an array but not if no entries were found if (is_array($uids)) { // id-number is in use and account is a new account if ((in_array($this->uidNumber, $uids)) && $this->orig['uidNumber']=='') $errors[] = array('ERROR', _('ID-Number'), _('ID is already in use')); // id-number is in use, account is existing account and id-number is not used by itself if ((in_array($this->uidNumber, $uids)) && $this->orig['uidNumber']!='' && ($this->orig['uidNumber'] != $this->uidNumber) ) { $errors[] = array('ERROR', _('ID-Number'), _('ID is already in use')); $this->uidNumber = $this->orig['uidNumber']; } } } // Check if Homedir is valid $this->homeDirectory = str_replace('$group', getgrnam($this->gidNumber), $this->homeDirectory); if ($this->uid != '') $this->homeDirectory = str_replace('$user', $this->uid, $this->homeDirectory); if ($this->homeDirectory != $_POST['form_posixAccount_homeDirectory']) $errors[] = array('INFO', _('Home directory'), _('Replaced $user or $group in homedir.')); if ( !ereg('^[/]([a-z]|[A-Z])([a-z]|[A-Z]|[0-9]|[.]|[-]|[_])*([/]([a-z]|[A-Z])([a-z]|[A-Z]|[0-9]|[.]|[-]|[_])*)*$', $this->homeDirectory )) $errors[] = array('ERROR', _('Home directory'), _('Homedirectory contains invalid characters.')); // Check if Name-length is OK. minLength=3, maxLength=20 if ( !ereg('.{3,20}', $this->uid)) $errors[] = array('ERROR', _('Name'), _('Name must contain between 3 and 20 characters.')); // Check if Name starts with letter if ( !ereg('^([a-z]|[A-Z]).*$', $this->uid)) $errors[] = array('ERROR', _('Name'), _('Name contains invalid characters. First character must be a letter')); // Check if password is OK if (!ereg('^([a-z]|[A-Z]|[0-9]|[\|]|[\#]|[\*]|[\,]|[\.]|[\;]|[\:]|[\_]|[\-]|[\+]|[\!]|[\%]|[\&]|[\/]|[\?]|[\{]|[\[]|[\(]|[\)]|[\]]|[\}])*$', $this->userPassword())) $errors[] = array('ERROR', _('Password'), _('Password contains invalid characters. Valid characters are: a-z, A-Z, 0-9 and #*,.;:_-+!$%&/|?{[()]}= !')); // Display errir-messages if (is_array($errors)) { for ($i=0; $i array($attr), 'remove' => array($attr), 'modify' => array($attr) ) * add are attributes which have to be added to ldap entry * remove are attributes which have to be removed from ldap entry * modify are attributes which have to been modified in ldap entry */ function save_attributes() { } /* This function returns all ldap attributes * which are part of posixAccount and returns * also their values. */ function get_attributes() { } /* This function will create the html-page * to show a page with all attributes. * It will output a complete html-table */ function display_html_attributes() { $groups = findgroups(); // list of all groupnames $shelllist = getshells(); // list of all valid shells echo "\n\n"; echo '\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; if ($this->type=='user') { echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; } echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; if ($this->type=='user') { if (count($shelllist)!=0) { echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; } echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; } echo "
' . _('Username') . "*uid\">" . _('Help') . "
" . _('UID number') . "uidNumber\">" . _('Help') . "
" . _('Primary group') . "*" . _('Help') . "
" . _('Additional groups') . "" . _('Help') . "
" . _('Home directory') . "*homeDirectory\">" . _('Help') . "
" . _('Gecos') . "gecos\">" . _('Help') . "
" . _('Description') . "description\">" . _('Help') . "
" . _('Login shell') . "*" . _('Help') . "
" . _('Password') . "userPassword()\">
" . _('Repeat password') . "userPassword(); echo "\">
" . _('Use no password') . "userPassword_no) echo " checked "; echo ">" . _('Help') . "
\n"; return 0; } function display_html_group() { // load list with all groups $groups = getcache('uidNumber', 'posixGroup', 'group'); // sort groups sort($groups, SORT_STRING); // remove groups the user is member of from grouplist $groups = array_delete($this->groups, $groups); // *** fixme primary group mut also be removed if it has changed after setting additional groups // Remove primary group from grouplist $groups = array_flip($groups); if (isset($groups[getgrnam($this->gidNumber)])) unset ($groups[getgrnam($this->gidNumber)]); $groups = array_flip($groups); echo "\n\n"; echo "
"; echo "" . _("Additional groups") . "\n"; echo "\n\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "
"; echo "
"; echo "" . _("Selected groups") . "\n"; // Show all groups the user is additional member of if (count($this->groups)!=0) { echo "\n"; } echo "
"; echo " "; echo "\">

"; echo ""._('Help')."
\n"; echo "
"; echo "" . _('Available groups') . "\n"; // show all groups expect these the user is member of if (count($groups)!=0) { echo "\n"; } echo "
\n"; echo "\n"; echo "
\n"; echo "
\n"; return 0; } function process_groups() { do { // X-Or, only one if() can be true if (isset($_POST['form_posixAccount_addgroups']) && isset($_POST['form_posixAccount_addgroups_button'])) { // Add groups to list // Add new group $this->groups = @array_merge($this->groups, $_POST['allgroups']); // remove doubles $this->groups = @array_flip($this->groups); array_unique($this->groups); $this->groups = @array_flip($this->groups); // sort groups sort($this->groups); break; } if (isset($_POST['form_posixAccount_removegroups']) && isset($_POST['form_posixAccount_removegroups_button'])) { // remove groups from list $this->groups = array_delete($_POST['form_posixAccount_removegroups'], $this->groups); break; } } while(0); return 0; } } ?>