2011-09-02 12:56:40 +00:00
|
|
|
<?php
|
|
|
|
/**
|
|
|
|
* HTTP Basic authentication backend class
|
|
|
|
*
|
|
|
|
* This class can be used by authentication objects wishing to use HTTP Basic
|
|
|
|
* Most of the digest logic is handled, implementors just need to worry about
|
|
|
|
* the validateUserPass method.
|
|
|
|
*
|
|
|
|
* @package Sabre
|
|
|
|
* @subpackage DAV
|
|
|
|
* @copyright Copyright (C) 2007-2011 Rooftop Solutions. All rights reserved.
|
|
|
|
* @author James David Low (http://jameslow.com/)
|
|
|
|
* @author Evert Pot (http://www.rooftopsolutions.nl/)
|
|
|
|
* @license http://code.google.com/p/sabredav/wiki/License Modified BSD License
|
|
|
|
*/
|
2011-12-07 14:51:47 +00:00
|
|
|
|
2011-09-02 12:56:40 +00:00
|
|
|
class OC_Connector_Sabre_Auth_ro_oauth extends Sabre_DAV_Auth_Backend_AbstractBasic {
|
|
|
|
private $validTokens;
|
2012-02-25 21:59:58 +00:00
|
|
|
private $category;
|
|
|
|
public function __construct($validTokensArg, $categoryArg) {
|
2011-09-02 12:56:40 +00:00
|
|
|
$this->validTokens = $validTokensArg;
|
2012-02-25 21:59:58 +00:00
|
|
|
$this->category = $categoryArg;
|
2011-09-02 12:56:40 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Validates a username and password
|
|
|
|
*
|
|
|
|
* This method should return true or false depending on if login
|
|
|
|
* succeeded.
|
|
|
|
*
|
|
|
|
* @return bool
|
|
|
|
*/
|
|
|
|
protected function validateUserPass($username, $password){
|
|
|
|
//always give read-only:
|
2012-02-25 21:59:58 +00:00
|
|
|
if(($_SERVER['REQUEST_METHOD'] == 'OPTIONS')
|
|
|
|
|| (isset($this->validTokens[$password]))
|
|
|
|
|| (($_SERVER['REQUEST_METHOD'] == 'GET') && ($this->category == 'public'))
|
|
|
|
) {
|
2011-09-02 12:56:40 +00:00
|
|
|
OC_Util::setUpFS();
|
|
|
|
return true;
|
|
|
|
} else {
|
2012-02-25 21:59:58 +00:00
|
|
|
//var_export($_SERVER);
|
|
|
|
//var_export($this->validTokens);
|
|
|
|
//die('not getting in with "'.$username.'"/"'.$password.'"!');
|
2011-09-02 12:56:40 +00:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
//overwriting this to make it not automatically fail if no auth header is found:
|
|
|
|
public function authenticate(Sabre_DAV_Server $server,$realm) {
|
2012-02-22 18:05:52 +00:00
|
|
|
$auth = new Sabre_HTTP_BearerAuth();
|
2011-09-02 12:56:40 +00:00
|
|
|
$auth->setHTTPRequest($server->httpRequest);
|
|
|
|
$auth->setHTTPResponse($server->httpResponse);
|
|
|
|
$auth->setRealm($realm);
|
|
|
|
$userpass = $auth->getUserPass();
|
|
|
|
if (!$userpass) {
|
2012-02-25 21:59:58 +00:00
|
|
|
if(($_SERVER['REQUEST_METHOD'] == 'OPTIONS')
|
|
|
|
||(($_SERVER['REQUEST_METHOD'] == 'GET') && ($this->category == 'public'))
|
|
|
|
) {
|
2011-09-02 12:56:40 +00:00
|
|
|
$userpass = array('', '');
|
|
|
|
} else {
|
|
|
|
$auth->requireLogin();
|
|
|
|
throw new Sabre_DAV_Exception_NotAuthenticated('No basic authentication headers were found');
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Authenticates the user
|
|
|
|
if (!$this->validateUserPass($userpass[0],$userpass[1])) {
|
|
|
|
$auth->requireLogin();
|
|
|
|
throw new Sabre_DAV_Exception_NotAuthenticated('Username or password does not match');
|
|
|
|
}
|
|
|
|
$this->currentUser = $userpass[0];
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
|
|
|
|