2 /***************************************************************************
3 * Copyright (C) 2003-2010 Polytechnique.org *
4 * http://opensource.polytechnique.org/ *
6 * This program is free software; you can redistribute it and/or modify *
7 * it under the terms of the GNU General Public License as published by *
8 * the Free Software Foundation; either version 2 of the License, or *
9 * (at your option) any later version. *
11 * This program is distributed in the hope that it will be useful, *
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
14 * GNU General Public License for more details. *
16 * You should have received a copy of the GNU General Public License *
17 * along with this program; if not, write to the Free Software *
19 * 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA *
20 ***************************************************************************/
22 // Post-processes the successful Google Apps account creation queue job.
23 function post_queue_u_create($job) {
26 // Retrieves the user parameters (GoogleApps username and uid).
27 $parameters = json_decode($job['j_parameters'], true
);
28 $username = isset($parameters['username']) ?
$parameters['username'] : null
;
29 if (!($user = User
::getSilent($username))) {
33 // Adds a redirection to the Google Apps delivery address, if requested by
34 // the user at creation time.
35 $account = new GoogleAppsAccount($user);
36 if ($account->activate_mail_redirection
) {
37 require_once('emails.inc.php');
38 $storage = new EmailStorage($user, 'googleapps');
42 // Sends the 'account created' email to the user, with basic documentation.
43 $mailer = new PlMailer('googleapps/create.mail.tpl');
44 $mailer->assign('account', $account);
45 $mailer->assign('email', $user->bestEmail());
46 $mailer->assign('googleapps_domain', $globals->mailstorage
->googleapps_domain
);
47 $mailer->assign('prenom', $user->displayName());
48 $mailer->assign('sexe', $user->isFemale());
52 // Post-processes the successful Google Apps account update queue job.
53 function post_queue_u_update($job) {
56 // If the u_update job was an unsuspend request, re-adds the redirection
57 // to the Google Apps delivery address, provided the account is active (it might
58 // have been deleted between the unsuspension and the post-queue processing).
59 $parameters = json_decode($job['j_parameters'], true
);
60 $username = isset($parameters['username']) ?
$parameters['username'] : null
;
61 if (!($user = User
::getSilent($username))) {
65 if (isset($parameters['suspended']) && $parameters['suspended'] == false
) {
66 require_once('emails.inc.php');
67 $account = new GoogleAppsAccount($user);
68 if ($account->active()) {
69 // Re-adds the email redirection (if the user did request it).
70 if ($account->activate_mail_redirection
) {
71 $storage = new EmailStorage($user, 'googleapps');
75 // Sends an email to the account owner.
76 $mailer = new PlMailer('googleapps/unsuspend.mail.tpl');
77 $mailer->assign('account', $account);
78 $mailer->assign('email', $user->bestEmail());
79 $mailer->assign('prenom', $user->displayName());
80 $mailer->assign('sexe', $user->isFemale());
86 // Reprensentation of an SQL-stored Google Apps account.
87 // This class is the interface with the gappsd SQL tables: gappsd is the python
88 // daemon which deals with Google Apps provisioning APIs.
89 // TODO(vincent.zanotti): add the url of gappsd, when available.
90 class GoogleAppsAccount
92 // User identification: user id, and hruid.
94 public $g_account_name;
96 // Local account parameters.
97 public $sync_password;
98 public $activate_mail_redirection;
100 // Account status, obtained from Google Apps provisioning & reporting APIs.
101 public $g_account_id;
103 public $g_suspension;
104 public $r_disk_usage;
106 public $r_last_login;
107 public $r_last_webmail;
108 public $reporting_date;
110 // Nicknames (aliases) registered for that user, lazily loaded.
113 // Pending requests in the gappsd job queue (cf. top note).
114 public $pending_create;
115 public $pending_delete;
116 public $pending_update;
117 public $pending_update_admin;
118 public $pending_update_other;
119 public $pending_update_password;
120 public $pending_update_suspension;
122 // Pending requests in plat/al validation queue.
123 public $pending_validation_unsuspend;
125 // Constructs the account object, by retrieving all informations from the
126 // GApps account table, from GApps job queue, and from plat/al validation queue.
127 public function __construct(User
&$user)
129 $this->user
= &$user;
130 if (!$this->user ||
!$this->user
->login()) {
134 // TODO: switch to multi-domain Google Apps, and use $this->user->forlifeEmail()
135 // as Google Apps idenfiant (requires changes in gappsd).
136 $this->g_account_name
= $this->user
->login();
137 $this->g_status
= NULL
;
140 "SELECT l_sync_password, l_activate_mail_redirection,
141 g_account_name, g_account_id, g_status, g_suspension, r_disk_usage,
142 UNIX_TIMESTAMP(r_creation) as r_creation,
143 UNIX_TIMESTAMP(r_last_login) as r_last_login,
144 UNIX_TIMESTAMP(r_last_webmail) as r_last_webmail
146 WHERE g_account_name = {?}", $this->g_account_name
);
147 if ($account = $res->fetchOneAssoc()) {
148 $this->sync_password
= $account['l_sync_password'];
149 $this->activate_mail_redirection
= $account['l_activate_mail_redirection'];
150 $this->g_account_id
= $account['g_account_id'];
151 $this->g_status
= $account['g_status'];
152 $this->g_suspension
= $account['g_suspension'];
153 $this->r_disk_usage
= $account['r_disk_usage'];
154 $this->r_creation
= $account['r_creation'];
155 $this->r_last_login
= $account['r_last_webmail'];
156 $this->r_last_webmail
= $account['r_last_webmail'];
158 $this->load_pending_counts();
159 $this->load_pending_validations();
160 if ($this->pending_update
) {
161 $this->load_pending_updates();
164 $res = XDB
::query("SELECT MAX(date) FROM gapps_reporting");
165 $this->reporting_date
= $res->fetchOneCell();
169 // Determines if changes to the Google Account are currently waiting in the
170 // GApps job queue, and initializes the local values accordingly.
171 private function load_pending_counts()
174 "SELECT SUM(j_type = 'u_create') AS pending_create,
175 SUM(j_type = 'u_update') AS pending_update,
176 SUM(j_type = 'u_delete') AS pending_delete
178 WHERE q_recipient_id = {?} AND
179 p_status IN ('idle', 'active', 'softfail')
180 GROUP BY j_type", $this->user
->id());
181 $pending = $res->fetchOneAssoc();
182 $this->pending_create
= $pending['pending_create'];
183 $this->pending_update
= $pending['pending_update'];
184 $this->pending_delete
= $pending['pending_delete'];
186 $this->pending_update_admin
= false
;
187 $this->pending_update_other
= false
;
188 $this->pending_update_password
= false
;
189 $this->pending_update_suspension
= false
;
192 // Checks for unsuspend requests waiting for validation in plat/al
194 private function load_pending_validations()
196 $this->pending_validation_unsuspend
=
197 Validate
::get_typed_requests_count($this->user
->id(), 'gapps-unsuspend');
200 // Retrieves all the pending update job in the gappsd queue for the current
201 // user, and analyzes the scope of the update (ie. the fields in the user
202 // account which are going to be updated).
203 private function load_pending_updates()
205 $res = XDB
::iterator(
208 WHERE q_recipient_id = {?} AND
209 p_status IN ('idle', 'active', 'softfail') AND
210 j_type = 'u_update'", $this->user
->id());
211 while ($update = $res->next()) {
212 $update_data = json_decode($update["j_parameters"], true
);
214 if (isset($update_data["suspended"])) {
215 $this->pending_update_suspension
= true
;
216 } elseif (isset($update_data["password"])) {
217 $this->pending_update_password
= true
;
218 } elseif (isset($update_data["admin"])) {
219 $this->pending_update_admin
= true
;
221 $this->pending_update_other
= true
;
226 // Creates a queue job of the @p type, for the user represented by this
227 // GoogleAppsAccount object, using @p parameters. @p parameters is supposed
228 // to be a one-dimension array of key-value mappings.
229 // The created job as a 'immediate' priority, and is scheduled for immediate
231 private function create_queue_job($type, $parameters) {
232 $parameters["username"] = $this->g_account_name
;
234 "INSERT INTO gapps_queue
235 SET q_owner_id = {?}, q_recipient_id = {?},
236 p_entry_date = NOW(), p_notbefore_date = NOW(),
237 p_priority = 'immediate',
238 j_type = {?}, j_parameters = {?}",
242 json_encode($parameters));
246 // Returns true if the account is currently active.
247 public function active()
249 return $this->g_status
== 'active';
252 // Returns true if the account exists in Google Apps.
253 public function provisioned()
255 return $this->g_status
== 'active' or $this->g_status
== 'disabled';
258 // Returns true if the account exists, but cannot be used (user-requested
259 // suspension, or Google-requested suspension).
260 public function suspended()
262 return $this->g_status
== 'disabled';
265 // Loads and returns the list of nicknames for the user.
266 public function nicknames()
268 if ($this->nicknames
== null
) {
272 WHERE g_account_name = {?}
273 ORDER BY g_nickname",
274 $this->g_account_name
);
275 $this->nicknames
= $res->fetchColumn();
277 return $this->nicknames
;
281 // Changes the GoogleApps password.
282 public function set_password($password) {
283 if (!$this->provisioned()) {
287 if (!$this->pending_update_password
) {
288 $this->create_queue_job('u_update', array('password' => $password));
289 $this->pending_update_password
= true
;
294 // Changes the password synchronization status ("sync = true" means that the
295 // Polytechnique.org password will be replicated to the Google Apps account).
296 public function set_password_sync($sync) {
297 if (!$this->provisioned()) {
301 $this->sync_password
= $sync;
303 "UPDATE gapps_accounts
304 SET l_sync_password = {?}
305 WHERE g_account_name = {?}",
307 $this->g_account_name
);
310 // Suspends the Google Apps account.
311 public function suspend() {
312 if (!$this->provisioned()) {
316 if (!$this->pending_update_suspension
) {
317 $this->create_queue_job('u_update', array('suspended' => true
));
318 $this->pending_update_suspension
= true
;
320 "UPDATE gapps_accounts
321 SET g_status = 'disabled'
322 WHERE g_account_name = {?} AND g_status = 'active'",
323 $this->g_account_name
);
327 // Adds an unsuspension request to the validation queue (used on user-request).
328 public function unsuspend($activate_mail_redirection = NULL
) {
329 if (!$this->provisioned()) {
332 if ($activate_mail_redirection !== NULL
) {
333 $this->activate_mail_redirection
= $activate_mail_redirection;
335 "UPDATE gapps_accounts
336 SET l_activate_mail_redirection = {?}
337 WHERE g_account_name = {?}",
338 $activate_mail_redirection,
339 $this->g_account_name
);
342 if (!$this->pending_update_suspension
&& !$this->pending_validation_unsuspend
) {
343 $unsuspend = new GoogleAppsUnsuspendReq($this->user
);
344 $unsuspend->submit();
345 $this->pending_validation_unsuspend
= true
;
349 // Unsuspends the Google Apps account (used on admin-request, or on validation of
351 public function do_unsuspend() {
352 if (!$this->provisioned()) {
356 if (!$this->pending_update_suspension
) {
357 if ($this->sync_password
) {
358 $this->create_queue_job('u_update', array('suspended' => false
, 'password' => $this->user
->password()));
360 $this->create_queue_job('u_update', array('suspended' => false
));
362 $this->pending_update_suspension
= true
;
368 // Creates a new Google Apps account with the @p local parameters.
369 public function create($password_sync, $password, $redirect_mails)
371 if ($this->g_status
!= NULL
) {
375 if (!$this->pending_create
) {
376 // Retrieves information on the new account.
377 if (!$this->user
->hasProfile()) {
378 $prenom = $this->user
->displayName();
379 $nom = $this->user
->fullName();
381 $prenom = $this->user
->profile()->firstName();
382 $nom = $this->user
->profile()->lastName();
385 // Adds an 'unprovisioned' entry in the gapps_accounts table.
387 "INSERT INTO gapps_accounts
389 l_sync_password = {?},
390 l_activate_mail_redirection = {?},
391 g_account_name = {?},
394 g_status = 'unprovisioned'",
398 $this->g_account_name
,
401 // Adds the creation job in the GApps queue.
402 $this->create_queue_job(
405 'username' => $this->g_account_name
,
406 'first_name' => $prenom,
408 'password' => $password,
411 // Updates the GoogleAppsAccount status.
412 $this->__construct($this->user
);
417 // Returns the status of the Google Apps account for @p user, or false
418 // when no account exists.
419 static public function account_status($uid) {
423 WHERE l_userid = {?}", $uid);
424 return ($res->numRows() > 0 ?
$res->fetchOneCell() : false
);
427 // Returns true if the @p user is an administrator of the Google Apps domain.
428 static public function is_administrator($uid) {
432 WHERE l_userid = {?} AND g_status = 'active'", $uid);
433 return ($res->numRows() > 0 ?
(bool
)$res->fetchOneCell() : false
);
437 // vim:set et sw=4 sts=4 sws=4 foldmethod=marker enc=utf-8: