functions_openid.php 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103
  1. <?php
  2. /* Copyright (C) 2007-2013 Laurent Destailleur <eldy@users.sourceforge.net>
  3. * Copyright (C) 2007-2009 Regis Houssin <regis.houssin@inodbox.com>
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation; either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <https://www.gnu.org/licenses/>.
  17. */
  18. /**
  19. * \file htdocs/core/login/functions_openid.php
  20. * \ingroup core
  21. * \brief Authentication functions for OpenId mode
  22. *
  23. * This authentication method is based on "OpenID v2" and is deprecated.
  24. * Use instead the method "OpenID Connect".
  25. */
  26. include_once DOL_DOCUMENT_ROOT.'/core/class/openid.class.php';
  27. /**
  28. * Check validity of user/password/entity
  29. * If test is ko, reason must be filled into $_SESSION["dol_loginmesg"]
  30. *
  31. * @param string $usertotest Login
  32. * @param string $passwordtotest Password
  33. * @param int $entitytotest Number of instance (always 1 if module multicompany not enabled)
  34. * @return string Login if OK, '' if KO
  35. */
  36. function check_user_password_openid($usertotest, $passwordtotest, $entitytotest)
  37. {
  38. global $db, $conf, $langs;
  39. dol_syslog("functions_openid::check_user_password_openid usertotest=".$usertotest);
  40. $login = '';
  41. // Get identity from user and redirect browser to OpenID Server
  42. if (GETPOSTISSET('username')) {
  43. $openid = new SimpleOpenID();
  44. $openid->SetIdentity(GETPOST('username'));
  45. $protocol = ($conf->file->main_force_https ? 'https://' : 'http://');
  46. $openid->SetTrustRoot($protocol.$_SERVER["HTTP_HOST"]);
  47. $openid->SetRequiredFields(array('email', 'fullname'));
  48. $_SESSION['dol_entity'] = GETPOST("entity", 'int');
  49. //$openid->SetOptionalFields(array('dob','gender','postcode','country','language','timezone'));
  50. if ($openid->sendDiscoveryRequestToGetXRDS()) {
  51. $openid->SetApprovedURL($protocol.$_SERVER["HTTP_HOST"].$_SERVER["SCRIPT_NAME"]); // Send Response from OpenID server to this script
  52. $openid->Redirect(); // This will redirect user to OpenID Server
  53. } else {
  54. $_SESSION["dol_loginmesg"] = $openid->GetError();
  55. return false;
  56. }
  57. return false;
  58. } elseif ($_GET['openid_mode'] == 'id_res') {
  59. // Perform HTTP Request to OpenID server to validate key
  60. $openid = new SimpleOpenID();
  61. $openid->SetIdentity(GETPOST('openid_identity'));
  62. $openid_validation_result = $openid->ValidateWithServer();
  63. if ($openid_validation_result === true) {
  64. // OK HERE KEY IS VALID
  65. $sql = "SELECT login, entity, datestartvalidity, dateendvalidity";
  66. $sql .= " FROM ".MAIN_DB_PREFIX."user";
  67. $sql .= " WHERE openid = '".$db->escape(GETPOST('openid_identity'))."'";
  68. $sql .= " AND entity IN (0,".(!empty($_SESSION["dol_entity"]) ? ((int) $_SESSION["dol_entity"]) : 1).")";
  69. dol_syslog("functions_openid::check_user_password_openid", LOG_DEBUG);
  70. $resql = $db->query($sql);
  71. if ($resql) {
  72. $obj = $db->fetch_object($resql);
  73. if ($obj) {
  74. // Note: Test on date validity is done later natively with isNotIntoValidityDateRange() by core after calling checkLoginPassEntity() that call this method
  75. $login = $obj->login;
  76. }
  77. }
  78. } elseif ($openid->IsError() === true) {
  79. // ON THE WAY, WE GOT SOME ERROR
  80. $_SESSION["dol_loginmesg"] = $openid->GetError();
  81. return false;
  82. } else {
  83. // Signature Verification Failed
  84. //echo "INVALID AUTHORIZATION";
  85. return false;
  86. }
  87. } elseif ($_GET['openid_mode'] == 'cancel') {
  88. // User Canceled your Request
  89. //echo "USER CANCELED REQUEST";
  90. return false;
  91. }
  92. return $login;
  93. }