2008-11-15 11:54:39 +01:00
|
|
|
<?php
|
|
|
|
/**
|
2016-03-06 21:47:10 +01:00
|
|
|
* EGroupware API - Authentication from CAS
|
2008-11-15 11:54:39 +01:00
|
|
|
*
|
|
|
|
* @link http://www.egroupware.org
|
|
|
|
* @license http://opensource.org/licenses/lgpl-license.php LGPL - GNU Lesser General Public License
|
|
|
|
* @package api
|
|
|
|
* @subpackage authentication
|
|
|
|
* @version $Id$
|
|
|
|
*/
|
|
|
|
|
2016-03-06 21:47:10 +01:00
|
|
|
namespace EGroupware\Api\Auth;
|
|
|
|
|
|
|
|
use EGroupware\Api;
|
|
|
|
use phpCAS;
|
|
|
|
|
2008-11-15 11:54:39 +01:00
|
|
|
/**
|
2016-03-06 21:47:10 +01:00
|
|
|
* Authentication based on CAS (Central Authetication Service)
|
2008-11-15 11:54:39 +01:00
|
|
|
*/
|
2016-03-06 21:47:10 +01:00
|
|
|
class Cas implements Backend
|
2008-11-15 11:54:39 +01:00
|
|
|
{
|
|
|
|
var $previous_login = -1;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* authentication against CAS
|
|
|
|
*
|
|
|
|
* @param string $username username of account to authenticate
|
|
|
|
* @param string $passwd corresponding password
|
2016-03-06 21:47:10 +01:00
|
|
|
* @param string $passwd_type ='text' 'text' for cleartext passwords (default)
|
2008-11-15 11:54:39 +01:00
|
|
|
* @return boolean true if successful authenticated, false otherwise
|
|
|
|
*/
|
2010-01-28 05:22:37 +01:00
|
|
|
function authenticate($username, $passwd, $passwd_type='text')
|
2008-11-15 11:54:39 +01:00
|
|
|
{
|
|
|
|
/* if program goes here, authenticate is, normaly, already verified by CAS */
|
|
|
|
if ($GLOBALS['egw_info']['server']['account_repository'] != 'ldap' &&
|
|
|
|
$GLOBALS['egw_info']['server']['account_repository'] != 'ldsq') /* For anonymous LDAP connection */
|
|
|
|
{
|
|
|
|
if (!($id = $GLOBALS['egw']->accounts->name2id($username,'account_lid','u')) &&
|
|
|
|
$GLOBALS['egw_info']['server']['auto_create_acct'])
|
|
|
|
{
|
|
|
|
// create a global array with all availible info about that account
|
|
|
|
$GLOBALS['auto_create_acct'] = array();
|
|
|
|
foreach(array(
|
|
|
|
'givenname' => 'firstname',
|
|
|
|
'sn' => 'lastname',
|
|
|
|
'uidnumber' => 'id',
|
|
|
|
'mail' => 'email',
|
|
|
|
'gidnumber' => 'primary_group',
|
|
|
|
) as $ldap_name => $acct_name)
|
|
|
|
{
|
2016-03-06 21:47:10 +01:00
|
|
|
$GLOBALS['auto_create_acct'][$acct_name] = Api\Translation::convert($allValues[0][$ldap_name][0],'utf-8');
|
2008-11-15 11:54:39 +01:00
|
|
|
}
|
|
|
|
return True;
|
|
|
|
}
|
|
|
|
return $id && $GLOBALS['egw']->accounts->id2name($id,'account_status') == 'A' && phpCAS::checkAuthentication();
|
|
|
|
}
|
|
|
|
return phpCAS::checkAuthentication();
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* changes password in CAS
|
|
|
|
*
|
|
|
|
* @param string $old_passwd must be cleartext or empty to not to be checked
|
|
|
|
* @param string $new_passwd must be cleartext
|
2016-03-06 21:47:10 +01:00
|
|
|
* @param int $account_id =0 account id of user whose passwd should be changed
|
2008-11-15 11:54:39 +01:00
|
|
|
* @return boolean true if password successful changed, false otherwise
|
|
|
|
*/
|
|
|
|
function change_password($old_passwd, $new_passwd, $account_id=0)
|
|
|
|
{
|
|
|
|
/* Not allowed */
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|