Store IP as uint instead of strings.
[platal.git] / include / xorg.misc.inc.php
CommitLineData
0337d704 1<?php
2/***************************************************************************
179afa7f 3 * Copyright (C) 2003-2008 Polytechnique.org *
0337d704 4 * http://opensource.polytechnique.org/ *
5 * *
6 * This program is free software; you can redistribute it and/or modify *
7 * it under the terms of the GNU General Public License as published by *
8 * the Free Software Foundation; either version 2 of the License, or *
9 * (at your option) any later version. *
10 * *
11 * This program is distributed in the hope that it will be useful, *
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
14 * GNU General Public License for more details. *
15 * *
16 * You should have received a copy of the GNU General Public License *
17 * along with this program; if not, write to the Free Software *
18 * Foundation, Inc., *
19 * 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA *
20 ***************************************************************************/
21
db3bd146 22function quoted_printable_encode($input, $line_max = 76)
23{
0337d704 24 $lines = preg_split("/(?:\r\n|\r|\n)/", $input);
25 $eol = "\n";
26 $linebreak = "=0D=0A=\n ";
27 $escape = "=";
28 $output = "";
29
30 foreach ($lines as $j => $line) {
d36e55a1 31 $linlen = strlen($line);
32 $newline = "";
33 for($i = 0; $i < $linlen; $i++) {
34 $c = $line{$i};
35 $dec = ord($c);
36 if ( ($dec == 32) && ($i == ($linlen - 1)) ) {
37 // convert space at eol only
38 $c = "=20";
39 } elseif ( ($dec == 61) || ($dec < 32 ) || ($dec > 126) ) {
40 // always encode "\t", which is *not* required
41 $c = $escape.strtoupper(sprintf("%02x",$dec));
42 }
43 if ( (strlen($newline) + strlen($c)) >= $line_max ) { // CRLF is not counted
44 $output .= $newline.$escape.$eol;
45 $newline = " ";
46 }
47 $newline .= $c;
48 } // end of for
49 $output .= $newline;
50 if ($j<count($lines)-1) $output .= $linebreak;
0337d704 51 }
52 return trim($output);
53}
54
eaf30d86 55/** vérifie si une adresse email convient comme adresse de redirection
0337d704 56 * @param $email l'adresse email a verifier
57 * @return BOOL
58 */
d36e55a1 59function isvalid_email_redirection($email)
60{
eaf30d86 61 return isvalid_email($email) &&
d36e55a1 62 !preg_match("/@(polytechnique\.(org|edu)|melix\.(org|net)|m4x\.org)$/", $email);
0337d704 63}
64
d0631eab 65/** genere une chaine aleatoire de 22 caracteres ou moins
66 * @param $len longueur souhaitée, 22 par défaut
67 * @return la chaine aleatoire qui contient les caractères [A-Za-z0-9+/]
68 */
69function rand_token($len = 22)
70{
71 $len = max(2, $len);
72 $len = min(50, $len);
73 $fp = fopen('/dev/urandom', 'r');
74 // $len * 2 is certainly an overkill,
75 // but HEY, reading 40 bytes from /dev/urandom is not that slow !
76 $token = fread($fp, $len * 2);
77 fclose($fp);
78 $token = base64_encode($token);
79 $token = preg_replace("![Il10O+/]!", "", $token);
80 $token = substr($token,0,$len);
81 return $token;
82}
83
84/** genere une chaine aleatoire convenable pour une url
85 * @param $len longueur souhaitée, 22 par défaut
eaf30d86 86 * @return la chaine aleatoire
d0631eab 87 */
88function rand_url_id($len = 22)
89{
90 return rand_token($len);
91}
92
93
94/** genere une chaine aleatoire convenable pour un mot de passe
95 * @return la chaine aleatoire
96 */
97function rand_pass()
98{
99 return rand_token(8);
100}
101
a14159bf 102/** Remove accent from a string and replace them by the nearest letter
103 */
104global $lc_convert, $uc_convert;
105$lc_convert = array('é' => 'e', 'è' => 'e', 'ë' => 'e', 'ê' => 'e',
d36e55a1 106 'á' => 'a', 'à' => 'a', 'ä' => 'a', 'â' => 'a', 'å' => 'a', 'ã' => 'a',
107 'ï' => 'i', 'î' => 'i', 'ì' => 'i', 'í' => 'i',
108 'ô' => 'o', 'ö' => 'o', 'ò' => 'o', 'ó' => 'o', 'õ' => 'o', 'ø' => 'o',
109 'ú' => 'u', 'ù' => 'u', 'û' => 'u', 'ü' => 'u',
110 'ç' => 'c', 'ñ' => 'n');
eaf30d86
PH
111$uc_convert = array('É' => 'E', 'È' => 'E', 'Ë' => 'E', 'Ê' => 'E',
112 'Á' => 'A', 'À' => 'A', 'Ä' => 'A', 'Â' => 'A', 'Å' => 'A', 'Ã' => 'A',
113 'Ï' => 'I', 'Î' => 'I', 'Ì' => 'I', 'Í' => 'I',
114 'Ô' => 'O', 'Ö' => 'O', 'Ò' => 'O', 'Ó' => 'O', 'Õ' => 'O', 'Ø' => 'O',
115 'Ú' => 'U', 'Ù' => 'U', 'Û' => 'U', 'Ü' => 'U',
d36e55a1 116 'Ç' => 'C', 'Ñ' => 'N');
a14159bf 117
118function replace_accent($string)
119{
120 global $lc_convert, $uc_convert;
121 $string = strtr($string, $lc_convert);
122 return strtr($string, $uc_convert);
123}
124
a11b5424 125/** creates a username from a first and last name
d36e55a1 126 *
127 * @param $prenom the firstname
128 * @param $nom the last name
129 *
130 * return STRING the corresponding username
131 */
132function make_username($prenom,$nom)
133{
a11b5424 134 /* on traite le prenom */
135 $prenomUS=replace_accent(trim($prenom));
136 $prenomUS=stripslashes($prenomUS);
137
138 /* on traite le nom */
139 $nomUS=replace_accent(trim($nom));
140 $nomUS=stripslashes($nomUS);
141
142 // calcul du login
143 $username = strtolower($prenomUS.".".$nomUS);
144 $username = str_replace(" ","-",$username);
145 $username = str_replace("'","",$username);
146 return $username;
147}
148
a7de4ef7 149/* Un soundex en français posté par Frédéric Bouchery
150 Voici une adaptation en PHP de la fonction soundex2 francisée de Frédéric BROUARD (http://sqlpro.developpez.com/Soundex/).
151 C'est une bonne démonstration de la force des expressions régulières compatible Perl.
d36e55a1 152trouvé sur http://expreg.com/voirsource.php?id=40&type=Chaines%20de%20caract%E8res */
0337d704 153function soundex_fr($sIn)
94f6c381 154{
155 static $convVIn, $convVOut, $convGuIn, $convGuOut, $accents;
156 if (!isset($convGuIn)) {
d36e55a1 157 global $uc_convert, $lc_convert;
94f6c381 158 $convGuIn = array( 'GUI', 'GUE', 'GA', 'GO', 'GU', 'SC', 'CA', 'CO', 'CU', 'QU', 'Q', 'CC', 'CK', 'G', 'ST', 'PH');
159 $convGuOut = array( 'KI', 'KE', 'KA', 'KO', 'KU', 'SK', 'KA', 'KO', 'KU', 'K', 'K', 'K', 'K', 'J', 'T', 'F');
393137f9 160 $convVIn = array( '/E?(AU)/', '/([EA])?[UI]([NM])([^EAIOUY]|$)/', '/[AE]O?[NM]([^AEIOUY]|$)/',
d36e55a1 161 '/[EA][IY]([NM]?[^NM]|$)/', '/(^|[^OEUIA])(OEU|OE|EU)([^OEUIA]|$)/', '/OI/',
162 '/(ILLE?|I)/', '/O(U|W)/', '/O[NM]($|[^EAOUIY])/', '/(SC|S|C)H/',
163 '/([^AEIOUY1])[^AEIOUYLKTP]([UAO])([^AEIOUY])/', '/([^AEIOUY]|^)([AUO])[^AEIOUYLKTP]([^AEIOUY1])/', '/^KN/',
164 '/^PF/', '/C([^AEIOUY]|$)/',
1c428347 165 '/C/', '/Z$/', '/(?<!^)Z+/', '/ER$/', '/H/', '/W/');
94f6c381 166 $convVOut = array( 'O', '1\3', 'A\1',
d36e55a1 167 'E\1', '\1E\3', 'O',
168 'Y', 'U', 'O\1', '9',
169 '\1\2\3', '\1\2\3', 'N',
170 'F', 'K\1',
1c428347 171 'S', 'SE', 'S', 'E', '', 'V');
d36e55a1 172 $accents = $uc_convert + $lc_convert;
94f6c381 173 $accents['Ç'] = 'S';
174 $accents['¿'] = 'E';
175 }
eaf30d86
PH
176 // Si il n'y a pas de mot, on sort immédiatement
177 if ( $sIn === '' ) return ' ';
178 // On supprime les accents
d36e55a1 179 $sIn = strtr( $sIn, $accents);
eaf30d86
PH
180 // On met tout en minuscule
181 $sIn = strtoupper( $sIn );
182 // On supprime tout ce qui n'est pas une lettre
183 $sIn = preg_replace( '`[^A-Z]`', '', $sIn );
184 // Si la chaîne ne fait qu'un seul caractère, on sort avec.
185 if ( strlen( $sIn ) === 1 ) return $sIn . ' ';
186 // on remplace les consonnances primaires
94f6c381 187 $sIn = str_replace( $convGuIn, $convGuOut, $sIn );
188 // on supprime les lettres répétitives
189 $sIn = preg_replace( '`(.)\1`', '$1', $sIn );
190 // on réinterprète les voyelles
191 $sIn = preg_replace( $convVIn, $convVOut, $sIn);
eaf30d86 192 // on supprime les terminaisons T, D, S, X (et le L qui précède si existe)
94f6c381 193 $sIn = preg_replace( '`L?[TDSX]$`', '', $sIn );
194 // on supprime les E, A et Y qui ne sont pas en première position
195 $sIn = preg_replace( '`(?!^)Y([^AEOU]|$)`', '\1', $sIn);
393137f9 196 $sIn = preg_replace( '`(?!^)[EA]`', '', $sIn);
eaf30d86 197 return substr( $sIn . ' ', 0, 4);
0337d704 198}
199
e2fcbef1 200/** met les majuscules au debut de chaque atome du prénom
201 * @param $prenom le prénom à formater
202 * return STRING le prénom avec les majuscules
203 */
94f6c381 204function make_firstname_case($prenom)
205{
d36e55a1 206 $prenom = strtolower($prenom);
207 $pieces = explode('-',$prenom);
e2fcbef1 208
d36e55a1 209 foreach ($pieces as $piece) {
210 $subpieces = explode("'",$piece);
211 $usubpieces="";
212 foreach ($subpieces as $subpiece)
213 $usubpieces[] = ucwords($subpiece);
214 $upieces[] = implode("'",$usubpieces);
215 }
216 return implode('-',$upieces);
e2fcbef1 217}
218
219
d36e55a1 220function make_forlife($prenom, $nom, $promo)
221{
0337d704 222 $prenomUS = replace_accent(trim($prenom));
223 $nomUS = replace_accent(trim($nom));
224
225 $forlife = strtolower($prenomUS.".".$nomUS.".".$promo);
226 $forlife = str_replace(" ","-",$forlife);
227 $forlife = str_replace("'","",$forlife);
228 return $forlife;
229}
5480a216 230
9797734d
FB
231/** Convert ip to uint (to store it in a database)
232 */
233function ip_to_uint($ip)
234{
235 $part = explode('.', $ip);
236 $v = 0;
237 $fact = 0x1000000;
238 for ($i = 0 ; $i < 4 ; ++$i) {
239 $v += $fact * $part[$i];
240 $fact >>= 8;
241 }
242 return $v;
243}
244
245/** Convert uint to ip (to build a human understandable ip)
246 */
247function uint_to_ip($uint)
248{
249 return sprintf('%d.%d.%d.%d', ($uint / 16777216) % 0xff,
250 ($uint / 65536) & 0xff,
251 ($uint / 256) & 0xff,
252 ($uint / 1.0) & 0xff);
253}
254
255
256/******************************************************************************
257 * Security functions
258 *****************************************************************************/
259
5480a216 260function check_ip($level)
a2446af5 261{
262 if (empty($_SERVER['REMOTE_ADDR'])) {
e76421d8 263 return false;
8f61b4d5 264 }
265 if (empty($_SESSION['check_ip'])) {
e76421d8 266 $ips = array();
267 if (!empty($_SERVER['HTTP_X_FORWARDED_FOR'])) {
268 $ips = explode(',', $_SERVER['HTTP_X_FORWARDED_FOR']);
269 }
270 $ips[] = $_SERVER['REMOTE_ADDR'];
271 foreach ($ips as &$ip) {
9797734d 272 $ip = "ip = " . ip_to_uint($ip);
e76421d8 273 }
d36e55a1 274 $res = XDB::query('SELECT state
275 FROM ip_watch
276 WHERE ' . implode(' OR ', $ips) . '
277 ORDER BY state DESC');
8f61b4d5 278 if ($res->numRows()) {
279 $_SESSION['check_ip'] = $res->fetchOneCell();
280 } else {
281 $_SESSION['check_ip'] = 'safe';
282 }
283 }
5480a216 284 $test = array();
285 switch ($level) {
8f61b4d5 286 case 'unsafe': $test[] = 'unsafe';
287 case 'dangerous': $test[] = 'dangerous';
288 case 'ban': $test[] = 'ban'; break;
5480a216 289 default: return false;
290 }
8f61b4d5 291 return in_array($_SESSION['check_ip'], $test);
5480a216 292}
293
0d693e2f 294function check_email($email, $message)
295{
296 $res = XDB::query("SELECT state, description
d36e55a1 297 FROM emails_watch
298 WHERE state != 'safe' AND email = {?}", $email);
0d693e2f 299 if ($res->numRows()) {
300 send_warning_mail($message);
301 return true;
302 }
303 return false;
304}
305
0be07aa6 306function check_account()
307{
bfa821a0 308 return S::v('watch_account');
0be07aa6 309}
310
ccdbc270 311function check_redirect($red = null)
312{
313 require_once 'emails.inc.php';
314 if (is_null($red)) {
315 $red = new Redirect(S::v('uid'));
eaf30d86 316 }
ccdbc270 317 $_SESSION['no_redirect'] = !$red->other_active('');
eaf30d86 318 $_SESSION['mx_failures'] = $red->get_broken_mx();
ccdbc270 319}
320
5480a216 321function send_warning_mail($title)
322{
8932382b 323 global $globals;
5480a216 324 $mailer = new PlMailer();
1d55fe45 325 $mailer->setFrom("webmaster@" . $globals->mail->domain);
d7dd70be 326 $mailer->addTo($globals->core->admin_email);
2efe5355 327 $mailer->setSubject("[Plat/al Security Alert] $title");
5480a216 328 $mailer->setTxtBody("Identifiants de session :\n" . var_export($_SESSION, true) . "\n\n"
d36e55a1 329 ."Identifiants de connexion :\n" . var_export($_SERVER, true));
ef42a9d6 330 $mailer->send();
5480a216 331}
332
9797734d
FB
333
334/******************************************************************************
335 * Dynamic configuration update/edition stuff
336 *****************************************************************************/
337
328d2791
PC
338function update_NbIns()
339{
340 global $globals;
84868ee9
FB
341 $res = XDB::query("SELECT COUNT(*)
342 FROM auth_user_md5
343 WHERE perms IN ('admin','user') AND deces=0");
328d2791
PC
344 $cnt = $res->fetchOneCell();
345 $globals->change_dynamic_config(array('NbIns' => $cnt));
346}
347
84868ee9
FB
348function update_NbValid()
349{
350 global $globals;
351 $res = XDB::query("SELECT COUNT(*)
352 FROM requests");
353 $globals->change_dynamic_config(array('NbValid' => $res->fetchOneCell()));
354}
355
c557ed51
FB
356function update_NbNotifs()
357{
358 require_once 'notifs.inc.php';
359 $n = select_notifs(false, S::i('uid'), S::v('watch_last'), false);
360 $_SESSION['notifs'] = $n->numRows();
361}
362
a7de4ef7 363// vim:set et sw=4 sts=4 sws=4 foldmethod=marker enc=utf-8:
0337d704 364?>