| 1 | <?php |
| 2 | /*************************************************************************** |
| 3 | * Copyright (C) 2003-2011 Polytechnique.org * |
| 4 | * http://opensource.polytechnique.org/ * |
| 5 | * * |
| 6 | * This program is free software; you can redistribute it and/or modify * |
| 7 | * it under the terms of the GNU General Public License as published by * |
| 8 | * the Free Software Foundation; either version 2 of the License, or * |
| 9 | * (at your option) any later version. * |
| 10 | * * |
| 11 | * This program is distributed in the hope that it will be useful, * |
| 12 | * but WITHOUT ANY WARRANTY; without even the implied warranty of * |
| 13 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * |
| 14 | * GNU General Public License for more details. * |
| 15 | * * |
| 16 | * You should have received a copy of the GNU General Public License * |
| 17 | * along with this program; if not, write to the Free Software * |
| 18 | * Foundation, Inc., * |
| 19 | * 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA * |
| 20 | ***************************************************************************/ |
| 21 | |
| 22 | function bugize($list) |
| 23 | { |
| 24 | $list = preg_split('/,/', $list, -1, PREG_SPLIT_NO_EMPTY); |
| 25 | $ans = array(); |
| 26 | |
| 27 | foreach ($list as $bug) { |
| 28 | $clean = str_replace('#', '', $bug); |
| 29 | $ans[] = "<a href='http://trackers.polytechnique.org/task/$clean'>$bug</a>"; |
| 30 | } |
| 31 | |
| 32 | return join(',', $ans); |
| 33 | } |
| 34 | |
| 35 | |
| 36 | class PlatalModule extends PLModule |
| 37 | { |
| 38 | function handlers() |
| 39 | { |
| 40 | return array( |
| 41 | 'index' => $this->make_hook('index', AUTH_PUBLIC), |
| 42 | 'cacert.pem' => $this->make_hook('cacert', AUTH_PUBLIC), |
| 43 | 'changelog' => $this->make_hook('changelog', AUTH_PUBLIC), |
| 44 | |
| 45 | // Preferences thingies |
| 46 | 'prefs' => $this->make_hook('prefs', AUTH_COOKIE), |
| 47 | 'prefs/rss' => $this->make_hook('prefs_rss', AUTH_COOKIE), |
| 48 | 'prefs/webredirect' => $this->make_hook('webredir', AUTH_MDP, 'mail'), |
| 49 | 'prefs/skin' => $this->make_hook('skin', AUTH_COOKIE), |
| 50 | |
| 51 | // password related thingies |
| 52 | 'password' => $this->make_hook('password', AUTH_MDP), |
| 53 | 'tmpPWD' => $this->make_hook('tmpPWD', AUTH_PUBLIC), |
| 54 | 'password/smtp' => $this->make_hook('smtppass', AUTH_MDP, 'mail'), |
| 55 | 'recovery' => $this->make_hook('recovery', AUTH_PUBLIC), |
| 56 | 'exit' => $this->make_hook('exit', AUTH_PUBLIC), |
| 57 | 'review' => $this->make_hook('review', AUTH_PUBLIC), |
| 58 | 'deconnexion.php' => $this->make_hook('exit', AUTH_PUBLIC), |
| 59 | ); |
| 60 | } |
| 61 | |
| 62 | function handler_index($page) |
| 63 | { |
| 64 | // Include X-XRDS-Location response-header for Yadis discovery |
| 65 | global $globals; |
| 66 | header('X-XRDS-Location: ' . $globals->baseurl . '/openid/xrds'); |
| 67 | |
| 68 | // Redirect to the suitable page |
| 69 | if (S::logged()) { |
| 70 | pl_redirect('events'); |
| 71 | } else if (!@$GLOBALS['IS_XNET_SITE']) { |
| 72 | $this->handler_review($page); |
| 73 | } |
| 74 | } |
| 75 | |
| 76 | function handler_cacert($page) |
| 77 | { |
| 78 | pl_cached_content_headers("application/x-x509-ca-cert"); |
| 79 | readfile("/etc/ssl/xorgCA/cacert.pem"); |
| 80 | exit; |
| 81 | } |
| 82 | |
| 83 | function handler_changelog($page, $core = null) |
| 84 | { |
| 85 | $page->changeTpl('platal/changeLog.tpl'); |
| 86 | |
| 87 | function formatChangeLog($file) { |
| 88 | $clog = pl_entities(file_get_contents($file)); |
| 89 | $clog = preg_replace('/===+\s*/', '</pre><hr /><pre>', $clog); |
| 90 | // url catch only (not all wiki syntax) |
| 91 | $clog = preg_replace(array( |
| 92 | '/((?:https?|ftp):\/\/(?:\.*,*[\w@~%$£µ&i#\-+=_\/\?;])*)/ui', |
| 93 | '/(\s|^)www\.((?:\.*,*[\w@~%$£µ&i#\-+=_\/\?;])*)/iu', |
| 94 | '/(?:mailto:)?([a-z0-9.\-+_]+@([\-.+_]?[a-z0-9])+)/i'), |
| 95 | array( |
| 96 | '<a href="\\0">\\0</a>', |
| 97 | '\\1<a href="http://www.\\2">www.\\2</a>', |
| 98 | '<a href="mailto:\\0">\\0</a>'), |
| 99 | $clog); |
| 100 | $clog = preg_replace('!(#[0-9]+(,[0-9]+)*)!e', 'bugize("\1")', $clog); |
| 101 | $clog = preg_replace('!vim:.*$!', '', $clog); |
| 102 | return preg_replace("!(<hr />(\\s|\n)*)?<pre>(\s|\n)*</pre>((\\s|\n)*<hr />)?!m", "", "<pre>$clog</pre>"); |
| 103 | } |
| 104 | if ($core != 'core') { |
| 105 | $page->assign('core', false); |
| 106 | $page->assign('ChangeLog', formatChangeLog(dirname(__FILE__).'/../ChangeLog')); |
| 107 | } else { |
| 108 | $page->assign('core', true); |
| 109 | $page->assign('ChangeLog', formatChangeLog(dirname(__FILE__).'/../core/ChangeLog')); |
| 110 | } |
| 111 | } |
| 112 | |
| 113 | function __set_rss_state($state) |
| 114 | { |
| 115 | if ($state) { |
| 116 | if (!S::user()->token) { |
| 117 | S::user()->token = rand_url_id(16); |
| 118 | S::set('token', S::user()->token); |
| 119 | XDB::execute('UPDATE accounts |
| 120 | SET token = {?} |
| 121 | WHERE uid = {?}', S::user()->token, S::i('uid')); |
| 122 | } |
| 123 | } else { |
| 124 | S::kill('token'); |
| 125 | S::user()->token = null; |
| 126 | XDB::execute('UPDATE accounts |
| 127 | SET token = NULL |
| 128 | WHERE uid = {?}', S::i('uid')); |
| 129 | } |
| 130 | } |
| 131 | |
| 132 | function handler_prefs($page) |
| 133 | { |
| 134 | $page->changeTpl('platal/preferences.tpl'); |
| 135 | $page->setTitle('Mes préférences'); |
| 136 | |
| 137 | if (Post::has('email_format')) { |
| 138 | S::assert_xsrf_token(); |
| 139 | $fmt = Post::s('email_format'); |
| 140 | S::user()->setEmailFormat($fmt); |
| 141 | } |
| 142 | |
| 143 | if (Post::has('rss')) { |
| 144 | S::assert_xsrf_token(); |
| 145 | $this->__set_rss_state(Post::s('rss') == 'on'); |
| 146 | } |
| 147 | } |
| 148 | |
| 149 | function handler_webredir($page) |
| 150 | { |
| 151 | $page->changeTpl('platal/webredirect.tpl'); |
| 152 | $page->setTitle('Redirection de page WEB'); |
| 153 | |
| 154 | if (Env::v('submit') == 'Valider' && !Env::blank('url')) { |
| 155 | if (Env::blank('url')) { |
| 156 | $page->trigError('URL invalide'); |
| 157 | } else { |
| 158 | $url = Env::t('url'); |
| 159 | XDB::execute('INSERT INTO carvas (uid, url) |
| 160 | VALUES ({?}, {?}) |
| 161 | ON DUPLICATE KEY UPDATE url = VALUES(url)', |
| 162 | S::i('uid'), $url); |
| 163 | S::logger()->log('carva_add', 'http://' . $url); |
| 164 | $page->trigSuccess("Redirection activée vers <a href='http://$url'>$url</a>"); |
| 165 | } |
| 166 | } elseif (Env::v('submit') == 'Supprimer') { |
| 167 | XDB::execute('DELETE FROM carvas |
| 168 | WHERE uid = {?}', S::i('uid')); |
| 169 | Post::kill('url'); |
| 170 | S::logger()->log('carva_del'); |
| 171 | $page->trigSuccess('Redirection supprimée'); |
| 172 | } |
| 173 | |
| 174 | $url = XDB::fetchOneCell('SELECT url |
| 175 | FROM carvas |
| 176 | WHERE uid = {?}', S::i('uid')); |
| 177 | $page->assign('carva', $url); |
| 178 | |
| 179 | # FIXME: this code is not multi-domain compatible. We should decide how |
| 180 | # carva will extend to users not in the main domain. |
| 181 | $best = XDB::fetchOneCell('SELECT email |
| 182 | FROM email_source_account |
| 183 | WHERE uid = {?} AND FIND_IN_SET(\'bestalias\', flags)', |
| 184 | S::user()->id()); |
| 185 | $page->assign('bestalias', $best); |
| 186 | } |
| 187 | |
| 188 | function handler_prefs_rss($page) |
| 189 | { |
| 190 | $page->changeTpl('platal/filrss.tpl'); |
| 191 | |
| 192 | $page->assign('goback', Env::v('referer', 'login')); |
| 193 | |
| 194 | if (Env::v('act_rss') == 'Activer') { |
| 195 | $this->__set_rss_state(true); |
| 196 | $page->trigSuccess("Ton Fil RSS est activé."); |
| 197 | } |
| 198 | } |
| 199 | |
| 200 | function handler_password($page) |
| 201 | { |
| 202 | global $globals; |
| 203 | |
| 204 | if (Post::has('pwhash') && Post::t('pwhash')) { |
| 205 | S::assert_xsrf_token(); |
| 206 | |
| 207 | S::set('password', $password = Post::t('pwhash')); |
| 208 | XDB::execute('UPDATE accounts |
| 209 | SET password = {?} |
| 210 | WHERE uid={?}', $password, |
| 211 | S::i('uid')); |
| 212 | |
| 213 | // If GoogleApps is enabled, and the user did choose to use synchronized passwords, |
| 214 | // updates the Google Apps password as well. |
| 215 | if ($globals->mailstorage->googleapps_domain) { |
| 216 | require_once 'googleapps.inc.php'; |
| 217 | $account = new GoogleAppsAccount(S::user()); |
| 218 | if ($account->active() && $account->sync_password) { |
| 219 | $account->set_password($password); |
| 220 | } |
| 221 | } |
| 222 | |
| 223 | S::logger()->log('passwd'); |
| 224 | Platal::session()->setAccessCookie(true); |
| 225 | |
| 226 | $page->changeTpl('platal/password.success.tpl'); |
| 227 | $page->run(); |
| 228 | } |
| 229 | |
| 230 | $page->changeTpl('platal/password.tpl'); |
| 231 | $page->setTitle('Mon mot de passe'); |
| 232 | $page->assign('do_auth', 0); |
| 233 | } |
| 234 | |
| 235 | function handler_smtppass($page) |
| 236 | { |
| 237 | $page->changeTpl('platal/acces_smtp.tpl'); |
| 238 | $page->setTitle('Acces SMTP/NNTP'); |
| 239 | |
| 240 | $wp = new PlWikiPage('Xorg.SMTPSécurisé'); |
| 241 | $wp->buildCache(); |
| 242 | $wp = new PlWikiPage('Xorg.NNTPSécurisé'); |
| 243 | $wp->buildCache(); |
| 244 | |
| 245 | $uid = S::i('uid'); |
| 246 | $pass = Env::v('smtppass1'); |
| 247 | |
| 248 | if (Env::v('op') == "Valider" && strlen($pass) >= 6 |
| 249 | && Env::v('smtppass1') == Env::v('smtppass2')) { |
| 250 | XDB::execute('UPDATE accounts |
| 251 | SET weak_password = {?} |
| 252 | WHERE uid = {?}', $pass, $uid); |
| 253 | $page->trigSuccess('Mot de passe enregistré'); |
| 254 | S::logger()->log("passwd_ssl"); |
| 255 | } elseif (Env::v('op') == "Supprimer") { |
| 256 | XDB::execute('UPDATE accounts |
| 257 | SET weak_password = NULL |
| 258 | WHERE uid = {?}', $uid); |
| 259 | $page->trigSuccess('Compte SMTP et NNTP supprimé'); |
| 260 | S::logger()->log("passwd_del"); |
| 261 | } |
| 262 | |
| 263 | $res = XDB::query("SELECT weak_password IS NOT NULL |
| 264 | FROM accounts |
| 265 | WHERE uid = {?}", $uid); |
| 266 | $page->assign('actif', $res->fetchOneCell()); |
| 267 | } |
| 268 | |
| 269 | function handler_recovery($page) |
| 270 | { |
| 271 | global $globals; |
| 272 | |
| 273 | $page->changeTpl('platal/recovery.tpl'); |
| 274 | |
| 275 | if (!Env::has('login') || !Env::has('birth')) { |
| 276 | return; |
| 277 | } |
| 278 | |
| 279 | if (!preg_match('/^[0-3][0-9][0-1][0-9][1][9]([0-9]{2})$/', Env::v('birth'))) { |
| 280 | $page->trigError('Date de naissance incorrecte ou incohérente'); |
| 281 | return; |
| 282 | } |
| 283 | |
| 284 | $birth = sprintf('%s-%s-%s', |
| 285 | substr(Env::v('birth'), 4, 4), |
| 286 | substr(Env::v('birth'), 2, 2), |
| 287 | substr(Env::v('birth'), 0, 2)); |
| 288 | |
| 289 | $mailorg = strtok(Env::v('login'), '@'); |
| 290 | |
| 291 | $profile = Profile::get(Env::t('login')); |
| 292 | if (is_null($profile) || $profile->birthdate != $birth) { |
| 293 | $page->trigError('Les informations que tu as rentrées ne permettent pas de récupérer ton mot de passe.<br />'. |
| 294 | 'Si tu as un homonyme, utilise prenom.nom.promo comme login'); |
| 295 | return; |
| 296 | } |
| 297 | |
| 298 | $user = $profile->owner(); |
| 299 | if ($user->state != 'active') { |
| 300 | $page->trigError('Ton compte n\'est pas activé.'); |
| 301 | return; |
| 302 | } |
| 303 | |
| 304 | if ($user->lost) { |
| 305 | $page->assign('no_addr', true); |
| 306 | return; |
| 307 | } |
| 308 | |
| 309 | $page->assign('ok', true); |
| 310 | |
| 311 | $url = rand_url_id(); |
| 312 | XDB::execute('INSERT INTO account_lost_passwords (certificat,uid,created) |
| 313 | VALUES ({?},{?},NOW())', $url, $user->id()); |
| 314 | $to = XDB::fetchOneCell('SELECT redirect |
| 315 | FROM email_redirect_account |
| 316 | WHERE uid = {?} AND redirect = {?}', |
| 317 | $user->id(), Post::t('email')); |
| 318 | if (is_null($to)) { |
| 319 | $emails = XDB::fetchColumn('SELECT redirect |
| 320 | FROM email_redirect_account |
| 321 | WHERE uid = {?} AND flags = \'inactive\' AND type = \'smtp\'', |
| 322 | $user->id()); |
| 323 | $inactives_to = implode(', ', $emails); |
| 324 | } |
| 325 | $mymail = new PlMailer(); |
| 326 | $mymail->setFrom('"Gestion des mots de passe" <support+password@' . $globals->mail->domain . '>'); |
| 327 | if (is_null($to)) { |
| 328 | $mymail->addTo($user); |
| 329 | $mymail->addTo($inactives_to); |
| 330 | } else { |
| 331 | $mymail->addTo($to); |
| 332 | } |
| 333 | $mymail->setSubject("Ton certificat d'authentification"); |
| 334 | $mymail->setTxtBody("Visite la page suivante qui expire dans six heures : |
| 335 | {$globals->baseurl}/tmpPWD/$url |
| 336 | |
| 337 | Si en cliquant dessus tu n'y arrives pas, copie intégralement l'adresse dans la barre de ton navigateur. Si tu n'as pas utilisé ce lien dans six heures, tu peux tout simplement recommencer cette procédure. |
| 338 | |
| 339 | -- |
| 340 | Polytechnique.org |
| 341 | \"Le portail des élèves & anciens élèves de l'École polytechnique\" |
| 342 | |
| 343 | Email envoyé à ".Env::v('login') . (is_null($to) ? '' : ' |
| 344 | Adresse de secours : ' . $to)); |
| 345 | $mymail->send(); |
| 346 | |
| 347 | S::logger($user->id())->log('recovery', is_null($to) ? $inactives_to . ', ' . $user->bestEmail() : $to); |
| 348 | } |
| 349 | |
| 350 | function handler_tmpPWD($page, $certif = null) |
| 351 | { |
| 352 | global $globals; |
| 353 | // XXX: recovery requires data from the profile |
| 354 | XDB::execute('DELETE FROM account_lost_passwords |
| 355 | WHERE DATE_SUB(NOW(), INTERVAL 380 MINUTE) > created'); |
| 356 | |
| 357 | $res = XDB::query('SELECT uid |
| 358 | FROM account_lost_passwords WHERE certificat={?}', $certif); |
| 359 | $ligne = $res->fetchOneAssoc(); |
| 360 | if (!$ligne) { |
| 361 | $page->changeTpl('platal/index.tpl'); |
| 362 | $page->kill("Cette adresse n'existe pas ou n'existe plus sur le serveur."); |
| 363 | } |
| 364 | |
| 365 | $uid = $ligne["uid"]; |
| 366 | if (Post::has('pwhash') && Post::t('pwhash')) { |
| 367 | $password = Post::t('pwhash'); |
| 368 | XDB::query('UPDATE accounts |
| 369 | SET password={?} |
| 370 | WHERE uid = {?} AND state = \'active\'', |
| 371 | $password, $uid); |
| 372 | XDB::query('DELETE FROM account_lost_passwords |
| 373 | WHERE certificat={?}', $certif); |
| 374 | |
| 375 | // If GoogleApps is enabled, and the user did choose to use synchronized passwords, |
| 376 | // updates the Google Apps password as well. |
| 377 | if ($globals->mailstorage->googleapps_domain) { |
| 378 | require_once 'googleapps.inc.php'; |
| 379 | $account = new GoogleAppsAccount(User::getSilent($uid)); |
| 380 | if ($account->active() && $account->sync_password) { |
| 381 | $account->set_password($password); |
| 382 | } |
| 383 | } |
| 384 | |
| 385 | S::logger($uid)->log("passwd", ""); |
| 386 | |
| 387 | // Try to start a session (so the user don't have to log in); we will use |
| 388 | // the password available in Post:: to authenticate the user. |
| 389 | Platal::session()->start(AUTH_MDP); |
| 390 | |
| 391 | $page->changeTpl('platal/tmpPWD.success.tpl'); |
| 392 | } else { |
| 393 | $hruid = XDB::fetchOneCell('SELECT hruid |
| 394 | FROM accounts |
| 395 | WHERE uid = {?}', |
| 396 | $uid); |
| 397 | $page->changeTpl('platal/password.tpl'); |
| 398 | $page->assign('hruid', $hruid); |
| 399 | $page->assign('do_auth', 1); |
| 400 | } |
| 401 | } |
| 402 | |
| 403 | function handler_skin($page) |
| 404 | { |
| 405 | global $globals; |
| 406 | |
| 407 | $page->changeTpl('platal/skins.tpl'); |
| 408 | $page->setTitle('Skins'); |
| 409 | |
| 410 | if (Env::has('newskin')) { // formulaire soumis, traitons les données envoyées |
| 411 | XDB::execute('UPDATE accounts |
| 412 | SET skin = {?} |
| 413 | WHERE uid = {?}', |
| 414 | Env::i('newskin'), S::i('uid')); |
| 415 | S::kill('skin'); |
| 416 | Platal::session()->setSkin(); |
| 417 | } |
| 418 | |
| 419 | $res = XDB::query('SELECT id |
| 420 | FROM skins |
| 421 | WHERE skin_tpl = {?}', S::v('skin')); |
| 422 | $page->assign('skin_id', $res->fetchOneCell()); |
| 423 | |
| 424 | $sql = 'SELECT s.*, auteur, COUNT(*) AS nb |
| 425 | FROM skins AS s |
| 426 | LEFT JOIN accounts AS a ON (a.skin = s.id) |
| 427 | WHERE skin_tpl != \'\' AND ext != \'\' |
| 428 | GROUP BY id ORDER BY s.date DESC'; |
| 429 | $page->assign('skins', XDB::iterator($sql)); |
| 430 | } |
| 431 | |
| 432 | function handler_exit($page, $level = null) |
| 433 | { |
| 434 | if (S::suid()) { |
| 435 | $old = S::user()->login(); |
| 436 | S::logger()->log('suid_stop', $old . " by " . S::suid('hruid')); |
| 437 | Platal::session()->stopSUID(); |
| 438 | $target = S::s('suid_startpage'); |
| 439 | S::kill('suid_startpage'); |
| 440 | if (!empty($target)) { |
| 441 | http_redirect($target); |
| 442 | } |
| 443 | pl_redirect('admin/user/' . $old); |
| 444 | } |
| 445 | |
| 446 | if ($level == 'forget' || $level == 'forgetall') { |
| 447 | Platal::session()->killAccessCookie(); |
| 448 | } |
| 449 | |
| 450 | if ($level == 'forgetuid' || $level == 'forgetall') { |
| 451 | Platal::session()->killLoginFormCookies(); |
| 452 | } |
| 453 | |
| 454 | if (S::logged()) { |
| 455 | S::logger()->log('deconnexion', @$_SERVER['HTTP_REFERER']); |
| 456 | Platal::session()->destroy(); |
| 457 | } |
| 458 | |
| 459 | if (Get::has('redirect')) { |
| 460 | http_redirect(rawurldecode(Get::v('redirect'))); |
| 461 | } else { |
| 462 | $page->changeTpl('platal/exit.tpl'); |
| 463 | } |
| 464 | } |
| 465 | |
| 466 | function handler_review($page, $action = null, $mode = null) |
| 467 | { |
| 468 | // Include X-XRDS-Location response-header for Yadis discovery |
| 469 | global $globals; |
| 470 | header('X-XRDS-Location: ' . $globals->baseurl . '/openid/xrds'); |
| 471 | |
| 472 | $this->load('review.inc.php'); |
| 473 | $dom = 'Review'; |
| 474 | if (@$GLOBALS['IS_XNET_SITE']) { |
| 475 | $dom .= 'Xnet'; |
| 476 | } |
| 477 | $wp = new PlWikiPage($dom . '.Admin'); |
| 478 | $conf = explode('%0a', $wp->getField('text')); |
| 479 | $wiz = new PlWizard('Tour d\'horizon', PlPage::getCoreTpl('plwizard.tpl'), true); |
| 480 | foreach ($conf as $line) { |
| 481 | $list = preg_split('/\s*[*|]\s*/', $line, -1, PREG_SPLIT_NO_EMPTY); |
| 482 | $wiz->addPage('ReviewPage', $list[0], $list[1]); |
| 483 | } |
| 484 | $wiz->apply($page, 'review', $action, $mode); |
| 485 | } |
| 486 | } |
| 487 | |
| 488 | // vim:set et sw=4 sts=4 sws=4 foldmethod=marker enc=utf-8: |
| 489 | ?> |