Commit | Line | Data |
---|---|---|
0337d704 | 1 | <?php |
2 | /*************************************************************************** | |
179afa7f | 3 | * Copyright (C) 2003-2008 Polytechnique.org * |
0337d704 | 4 | * http://opensource.polytechnique.org/ * |
5 | * * | |
6 | * This program is free software; you can redistribute it and/or modify * | |
7 | * it under the terms of the GNU General Public License as published by * | |
8 | * the Free Software Foundation; either version 2 of the License, or * | |
9 | * (at your option) any later version. * | |
10 | * * | |
11 | * This program is distributed in the hope that it will be useful, * | |
12 | * but WITHOUT ANY WARRANTY; without even the implied warranty of * | |
13 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * | |
14 | * GNU General Public License for more details. * | |
15 | * * | |
16 | * You should have received a copy of the GNU General Public License * | |
17 | * along with this program; if not, write to the Free Software * | |
18 | * Foundation, Inc., * | |
19 | * 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA * | |
20 | ***************************************************************************/ | |
21 | ||
670b0ac0 | 22 | function gpex_prepare_param($name, $val, &$to_hash, $charset) |
23 | { | |
24 | $val = iconv('UTF-8', $charset, $val); | |
25 | $to_hash .= $val; | |
15dec88f | 26 | return '&' . $name . '=' . urlencode($val); |
670b0ac0 | 27 | } |
28 | ||
29 | function gpex_make($chlg, $privkey, $datafields, $charset) | |
9881e0b2 | 30 | { |
0337d704 | 31 | $tohash = "1$chlg$privkey"; |
9881e0b2 | 32 | $params = ""; |
670b0ac0 | 33 | $fieldarr = explode(',', $datafields); |
0337d704 | 34 | |
670b0ac0 | 35 | $res = XDB::query("SELECT matricule, matricule_ax, promo, |
36 | promo_sortie, flags, deces, nom, | |
37 | prenom, nationalite, section, | |
38 | naissance | |
39 | FROM auth_user_md5 WHERE user_id = {?}", | |
40 | S::v('uid')); | |
9f3acd20 | 41 | $personnal_data = $res->fetchOneAssoc(); |
5d292fd8 | 42 | |
43 | foreach ($fieldarr as $val) { | |
a7de4ef7 | 44 | /* on verifie qu'on n'a pas demandé une variable inexistante ! */ |
cab08090 | 45 | if (S::has($val)) { |
670b0ac0 | 46 | $params .= gpex_prepare_param($val, S::v($val), $tohash, $charset); |
9f3acd20 | 47 | } else if (isset($personnal_data[$val])) { |
670b0ac0 | 48 | $params .= gpex_prepare_param($val, $personnal_data[$val], $tohash, $charset); |
0337d704 | 49 | } else if ($val == 'username') { |
670b0ac0 | 50 | $res = XDB::query("SELECT alias FROM aliases |
51 | WHERE id = {?} AND FIND_IN_SET('bestalias', flags)", | |
52 | S::v('uid')); | |
0337d704 | 53 | $min_username = $res->fetchOneCell(); |
670b0ac0 | 54 | $params .= gpex_prepare_param($val, $min_username, $tohash, $charset); |
b49f3f40 | 55 | } else if ($val == 'grpauth') { |
670b0ac0 | 56 | if (isset($_GET['group'])) { |
57 | $res = XDB::query("SELECT perms | |
58 | FROM groupex.membres | |
eaf30d86 | 59 | INNER JOIN groupex.asso ON(id = asso_id) |
670b0ac0 | 60 | WHERE uid = {?} AND diminutif = {?}", |
61 | S::v('uid'), $_GET['group']); | |
62 | $perms = $res->fetchOneCell(); | |
7cc98bf7 PC |
63 | if (Session::has_perms()) { |
64 | $perms = 'admin'; | |
65 | } | |
670b0ac0 | 66 | } else { |
67 | // if no group asked, return main rights | |
68 | $perms = Session::has_perms()?'admin':'membre'; | |
69 | } | |
70 | $params .= gpex_prepare_param($val, $perms, $tohash, $charset); | |
5d292fd8 | 71 | } |
0337d704 | 72 | } |
73 | $tohash .= "1"; | |
9881e0b2 | 74 | $auth = md5($tohash); |
670b0ac0 | 75 | return array($auth, "&auth=" . $auth . $params); |
0337d704 | 76 | } |
77 | ||
78 | /* cree les parametres de l'URL de retour avec les champs demandes */ | |
670b0ac0 | 79 | function gpex_make_params($chlg, $privkey, $datafields, $charset) |
80 | { | |
81 | list ($auth, $param) = gpex_make($chlg, $privkey, $datafields, $charset); | |
82 | return $param; | |
0337d704 | 83 | } |
84 | ||
a7de4ef7 | 85 | // vim:set et sw=4 sts=4 sws=4 foldmethod=marker enc=utf-8: |
0337d704 | 86 | ?> |