From 53a0b60ba8062a76a7665aef62f1b8b57011d6e3 Mon Sep 17 00:00:00 2001 From: Paolo Date: Wed, 13 Mar 2019 11:57:36 +0100 Subject: [PATCH] - Removed method getCheckUserAuth form api/v1/CheckUserAuth - Changed LDAP_Model to a library: LDAPLib - Removed controller system/Login AuthLib: - Added new private method _createAuthObjByPerson - Moved config load from constructor to _authenticate - Moved Person_Model load from constructor to _createAuthObjByPerson - Removed method checkUserAuthByCode - Removed method checkUserAuthByCodeEmail - Adapted code to use LDAPLib --- application/config/constants.php | 4 +- .../controllers/api/v1/CheckUserAuth.php | 41 --- application/controllers/system/Login.php | 39 --- application/libraries/AuthLib.php | 249 +++++++----------- .../LDAP_Model.php => libraries/LDAPLib.php} | 4 +- 5 files changed, 100 insertions(+), 237 deletions(-) delete mode 100644 application/controllers/system/Login.php rename application/{core/LDAP_Model.php => libraries/LDAPLib.php} (99%) diff --git a/application/config/constants.php b/application/config/constants.php index 6de4d3392..26f2d655e 100644 --- a/application/config/constants.php +++ b/application/config/constants.php @@ -79,8 +79,8 @@ define('AUTH_INVALID_CREDENTIALS', 2); | LDAP constants |-------------------------------------------------------------------------- */ -define('LDAP_NO_USER_DN', 10); -define('LDAP_TOO_MANY_USER_DN', 11); +define('LDAP_NO_USER_DN', 10); +define('LDAP_TOO_MANY_USER_DN', 11); /* |-------------------------------------------------------------------------- diff --git a/application/controllers/api/v1/CheckUserAuth.php b/application/controllers/api/v1/CheckUserAuth.php index d9d6cb1a8..69dc9cda6 100644 --- a/application/controllers/api/v1/CheckUserAuth.php +++ b/application/controllers/api/v1/CheckUserAuth.php @@ -35,45 +35,4 @@ class CheckUserAuth extends REST_Controller $this->response(); } } - - /** - * Checks if username and password of a final user are valid - * Returns all the keys with which is possible to obtain all the personal data about a final user - */ - public function getCheckUserAuth() - { - $code = $this->get('code'); - $email = $this->get('email'); - $username = $this->get('username'); - $password = $this->get('password'); - - $result = null; - $httpCode = null; - - // If username and password are given then check authentication using them - if (isset($username) && isset($password)) - { - $result = $this->authlib->checkUserAuthByUsernamePassword($username, $password, true); - } - elseif (isset($code) || isset($email)) - { - // If code and email are given then check authentication using them - if (isset($code) && isset($email)) - { - $result = $this->authlib->checkUserAuthByCodeEmail($code, $email); - } - else // otherwise check authentication using only code - { - $result = $this->authlib->checkUserAuthByCode($code); - } - } - - // If is a success and contains data - if (hasData($result)) - { - $httpCode = REST_Controller::HTTP_OK; - } - - $this->response($result, $httpCode); - } } diff --git a/application/controllers/system/Login.php b/application/controllers/system/Login.php deleted file mode 100644 index 8ec52a341..000000000 --- a/application/controllers/system/Login.php +++ /dev/null @@ -1,39 +0,0 @@ -load->view('system/login/usernamePassword'); - } - - /** - * To login into the system with email and code as credentials - */ - public function emailCode() - { - } - - /** - * To login into the system using SSO - */ - public function sso() - { - } -} diff --git a/application/libraries/AuthLib.php b/application/libraries/AuthLib.php index adc286c9c..f369f45fe 100644 --- a/application/libraries/AuthLib.php +++ b/application/libraries/AuthLib.php @@ -36,12 +36,6 @@ class AuthLib // Gets CI instance $this->_ci =& get_instance(); - // Loads auth configuration - $this->_ci->config->load('auth'); - - // Load model PersonModel - $this->_ci->load->model('person/person_model', 'PersonModel'); - if ($authenticate === true) $this->_authenticate(); // if required -> authenticate the current user } @@ -57,71 +51,6 @@ class AuthLib return getSessionElement(self::SESSION_NAME, self::SESSION_AUTH_OBJ); } - /** - * Checks the authentication of an addon. Returns TRUE if valid, otherwise FALSE - */ - public function basicAuthentication($username, $password) - { - return isSuccess($this->_checkLDAPAuthentication($username, $password)); - } - - /** - * Checks if the given username and password of a final user are valid - */ - public function checkUserAuthByUsernamePassword($username, $password, $keys = false) - { - $result = error(false); - - if (isset($username) && isset($password)) - { - if (isSuccess($this->_checkLDAPAuthentication($username, $password))) - { - if ($keys === true) - { - $result = $this->_getFinalUserBasicDataByUID($username); - } - else - { - $result = success(true); - } - } - } - - return $result; - } - - /** - * Checks if the given code of a final user is valid - */ - public function checkUserAuthByCode($code) - { - $result = error(false); - - $person = $this->_ci->PersonModel->loadWhere(array('zugangscode' => $code)); - if (hasData($person)) - { - $result = $this->_getFinalUserBasicDataByPersonID($person->retval[0]->person_id); - } - - return $result; - } - - /** - * Checks if the given code and email of a final user are valid - */ - public function checkUserAuthByCodeEmail($code, $email) - { - $result = error(false); - - $person = $this->_ci->PersonModel->getPersonKontaktByZugangscode($code, $email); - if (hasData($person)) - { - $result = $this->_getFinalUserBasicDataByPersonID($person->retval[0]->person_id); - } - - return $result; - } - /** * Logs out the current logged user * If the user is using the LoginAs functionality then it is logged out from the acquired user @@ -159,34 +88,56 @@ class AuthLib */ public function loginLDAP($username, $password) { + // If already logged do NOT check another time, returns the authentication object + if ($this->_isLogged()) return $this->getAuthObj(); + + // Otherwise checks the given credentials $loginUP = $this->_checkLDAPAuthentication($username, $password); if (isSuccess($loginUP)) { - $this->_ci->PersonModel->resetQuery(); // Reset an eventually already built query + $loginUP = $this->_createAuthObjByPerson(array('uid' => $username)); - // Retrieves user data from DB using the UID - $personResult = $this->_ci->PersonModel->getByUid($username); - if (hasData($personResult)) - { - $person = getData($personResult)[0]; - - // Stores used data into the authentication object and then into a success object - $loginUP = success( - $this->_createAuthObj($person->person_id, $person->vorname, $person->nachname, $username), - AUTH_SUCCESS - ); - - $this->_storeAuthObj(getData($loginUP)); - } - elseif (isError($personResult)) // blocking error - { - $loginUP = $personResult; // to be displayed - } + // If were possible to retrieve user's data without failing, + // then stores the authentication object into authentication session + if (isSuccess($loginUP)) $this->_storeAuthObj(getData($loginUP)); } return $loginUP; } + /** + * Checks the authentication of an addon. Returns TRUE if valid, otherwise FALSE + */ + public function basicAuthentication($username, $password) + { + return isSuccess($this->_checkLDAPAuthentication($username, $password)); + } + + /** + * Checks if the given username and password of a final user are valid + */ + public function checkUserAuthByUsernamePassword($username, $password, $keys = false) + { + $result = error(false); + + if (isset($username) && isset($password)) + { + if (isSuccess($this->_checkLDAPAuthentication($username, $password))) + { + if ($keys === true) + { + $result = $this->_getFinalUserBasicDataByUID($username); + } + else + { + $result = success(true); + } + } + } + + return $result; + } + //------------------------------------------------------------------------------------------------------------------ // Private methods @@ -204,9 +155,9 @@ class AuthLib $authObj = new stdClass(); $authObj->{self::AO_PERSON_ID} = $person_id; - $authObj->{self::AO_NAME} = $name; - $authObj->{self::AO_SURNAME} = $surname; $authObj->{self::AO_USERNAME} = $username; + $authObj->{self::AO_SURNAME} = $surname; + $authObj->{self::AO_NAME} = $name; } return $authObj; @@ -276,27 +227,7 @@ class AuthLib // Checks if an authentication were performed via BT if (isset($_SESSION['bewerbung/personId']) && is_numeric($_SESSION['bewerbung/personId']) && isset($_SESSION['bewerbung/user'])) { - $this->_ci->PersonModel->resetQuery(); // Reset an eventually already built query - - // Then retrieves the person data from DB using the person_id - $this->_ci->PersonModel->addSelect('vorname, nachname'); - - // Retrieves user data using its own person_id - $personResult = $this->_ci->PersonModel->load($_SESSION['bewerbung/personId']); - if (hasData($personResult)) // found! - { - $person = getData($personResult)[0]; - - // Stores used data into the authentication object and then into a success object - $bt = success( - $this->_createAuthObj($_SESSION['bewerbung/personId'], $person->vorname, $person->nachname), - AUTH_SUCCESS - ); - } - elseif (isError($person)) // blocking error - { - $bt = $person; // return it! - } + $bt = $this->_createAuthObjByPerson(array('person_id' => $_SESSION['bewerbung/personId'])); } return $bt; @@ -318,24 +249,7 @@ class AuthLib } else // otherwise { - $this->_ci->PersonModel->resetQuery(); // Reset an eventually already built query - - // Retrieves user data from DB using the UID - $personResult = $this->_ci->PersonModel->getByUid($_SERVER['PHP_AUTH_USER']); - if (hasData($personResult)) - { - $person = getData($personResult)[0]; - - // Stores used data into the authentication object and then into a success object - $hta = success( - $this->_createAuthObj($person->person_id, $person->vorname, $person->nachname, $_SERVER['PHP_AUTH_USER']), - AUTH_SUCCESS - ); - } - elseif (isError($personResult)) // blocking error - { - $hta = $personResult; // to be displayed - } + $hta = $this->_createAuthObjByPerson(array('uid' => $_SERVER['PHP_AUTH_USER'])); } // Invalid credentials @@ -359,22 +273,23 @@ class AuthLib private function _checkLDAPAuthentication($username, $password) { $ldap = error('Not authenticated', AUTH_NOT_AUTHENTICATED); // by default is NOT authenticated - $ldapModel = new LDAP_Model(); // LDAP model handles the LDAP connection - $ldapConnection = $ldapModel->connect(); // connect! + $this->_ci->load->library('LDAPLib'); // Loads the LDAP library + + $ldapConnection = $this->_ci->ldaplib->connect(); // connect! if (isSuccess($ldapConnection)) // connected!! { // Get the user DN from LDAP - $userDN = $ldapModel->getUserDN($username); + $userDN = $this->_ci->ldaplib->getUserDN($username); if (isSuccess($userDN)) // got it! { - $ldapModel->close(); // close the previous LDAP connection + $this->_ci->ldaplib->close(); // close the previous LDAP connection // Connects to LDAP using the last working configuration + the retrieved user DN + the provided password - $ldapConnection = $ldapModel->connectUsernamePassword(getData($userDN), $password); + $ldapConnection = $this->_ci->ldaplib->connectUsernamePassword(getData($userDN), $password); if (isSuccess($ldapConnection)) // connected! { - $ldapModel->close(); // close the previous connection + $this->_ci->ldaplib->close(); // close the previous connection $ldap = success('Authenticated', AUTH_SUCCESS); // authenticated! } else // blocking error @@ -474,6 +389,8 @@ class AuthLib // If NOT logged if (!$this->_isLogged()) { + $this->_ci->config->load('auth'); // Loads auth configuration + // Checks if already logged with a foreign authentication method $auth = $this->_checkForeignAuthentication(); if (hasData($auth)) // Authenticated with a foreign authentication method @@ -492,6 +409,44 @@ class AuthLib // else the user is already logged, then continue with the execution } + /** + * It uses the given query where clause to select data for a user and then stores these data into a authentication object + */ + private function _createAuthObjByPerson($queryParamsArray) + { + $authObj = error('No user data found'); // pessimistic as usual + + $this->_ci->load->model('person/person_model', 'PersonModel'); // Loads model PersonModel + + $this->_ci->PersonModel->resetQuery(); // Reset an eventually already built query + + // Needed information + $this->_ci->PersonModel->addSelect('person_id, vorname, nachname, uid'); + // Retrieves the uid if it is possible + $this->_ci->PersonModel->addJoin('public.tbl_benutzer', 'person_id', 'LEFT'); + + $queryParamsArray['tbl_person.aktiv'] = true; // only active users! + + // Execute query with where clause + $personResult = $this->_ci->PersonModel->loadWhere($queryParamsArray); + if (hasData($personResult)) + { + $person = getData($personResult)[0]; + + // Stores user data into the authentication object and then into a success object + $authObj = success( + $this->_createAuthObj($person->person_id, $person->vorname, $person->nachname, $person->uid), + AUTH_SUCCESS + ); + } + elseif (isError($personResult)) // blocking error + { + $authObj = $personResult; // to be returned + } + + return $authObj; + } + /** * Returns all the keys with which is possible to obtain personal data about a final user * using the given username (uid) @@ -506,23 +461,13 @@ class AuthLib $benutzer = $this->_ci->BenutzerModel->load($uid); if (hasData($benutzer)) { - $finalUserBasicDataByUID = $this->_getFinalUserBasicDataByPersonID($benutzer->retval[0]->person_id); + $finalUserBasicDataByPersonID = new stdClass(); + // Store the person_id and eventually all the uid and prestudent_id related to this final user + $finalUserBasicDataByPersonID->person_id = $benutzer->retval[0]->person_id; + + $finalUserBasicDataByUID = success($finalUserBasicDataByPersonID); } return $finalUserBasicDataByUID; } - - /** - * Returns all the keys with which is possible to obtain personal data about a final user - * using the given person_id - */ - private function _getFinalUserBasicDataByPersonID($person_id) - { - $finalUserBasicDataByPersonID = new stdClass(); // returned object - - // Store the person_id and eventually all the uid and prestudent_id related to this final user - $finalUserBasicDataByPersonID->person_id = $person_id; - - return success($finalUserBasicDataByPersonID); - } } diff --git a/application/core/LDAP_Model.php b/application/libraries/LDAPLib.php similarity index 99% rename from application/core/LDAP_Model.php rename to application/libraries/LDAPLib.php index a43d5b768..06c238f85 100644 --- a/application/core/LDAP_Model.php +++ b/application/libraries/LDAPLib.php @@ -1,6 +1,6 @@ _connection = null; $this->_workingConfigArray = null; $this->_ldapConfigArray = null;