2010-07-15 12:09:22 +00:00
|
|
|
<?php
|
|
|
|
/**
|
2015-03-26 10:44:34 +00:00
|
|
|
* @author adrien <adrien.waksberg@believedigital.com>
|
|
|
|
* @author Aldo "xoen" Giambelluca <xoen@xoen.org>
|
|
|
|
* @author Arthur Schiwon <blizzz@owncloud.com>
|
|
|
|
* @author Bart Visscher <bartv@thisnet.nl>
|
|
|
|
* @author Björn Schießle <schiessle@owncloud.com>
|
|
|
|
* @author fabian <fabian@web2.0-apps.de>
|
|
|
|
* @author Georg Ehrke <georg@owncloud.com>
|
|
|
|
* @author Jakob Sack <mail@jakobsack.de>
|
2015-06-25 09:43:55 +00:00
|
|
|
* @author Joas Schilling <nickvergessen@owncloud.com>
|
2015-03-26 10:44:34 +00:00
|
|
|
* @author Jörn Friedrich Dreyer <jfd@butonic.de>
|
|
|
|
* @author Lukas Reschke <lukas@owncloud.com>
|
|
|
|
* @author Michael Gapczynski <GapczynskiM@gmail.com>
|
|
|
|
* @author Morris Jobke <hey@morrisjobke.de>
|
|
|
|
* @author nishiki <nishiki@yaegashi.fr>
|
|
|
|
* @author Robin Appelman <icewind@owncloud.com>
|
2016-01-12 14:02:16 +00:00
|
|
|
* @author Robin McCorkell <robin@mccorkell.me.uk>
|
2015-03-26 10:44:34 +00:00
|
|
|
* @author Thomas Müller <thomas.mueller@tmit.eu>
|
|
|
|
* @author Victor Dubiniuk <dubiniuk@owncloud.com>
|
2011-04-15 15:14:02 +00:00
|
|
|
*
|
2016-01-12 14:02:16 +00:00
|
|
|
* @copyright Copyright (c) 2016, ownCloud, Inc.
|
2015-03-26 10:44:34 +00:00
|
|
|
* @license AGPL-3.0
|
2011-04-15 15:14:02 +00:00
|
|
|
*
|
2015-03-26 10:44:34 +00:00
|
|
|
* This code is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU Affero General Public License, version 3,
|
|
|
|
* as published by the Free Software Foundation.
|
2011-04-15 15:14:02 +00:00
|
|
|
*
|
2015-03-26 10:44:34 +00:00
|
|
|
* This program is distributed in the hope that it will be useful,
|
2011-04-15 15:14:02 +00:00
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
2015-03-26 10:44:34 +00:00
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU Affero General Public License for more details.
|
2015-02-26 10:37:37 +00:00
|
|
|
*
|
2015-03-26 10:44:34 +00:00
|
|
|
* You should have received a copy of the GNU Affero General Public License, version 3,
|
|
|
|
* along with this program. If not, see <http://www.gnu.org/licenses/>
|
2015-02-26 10:37:37 +00:00
|
|
|
*
|
|
|
|
*/
|
|
|
|
/*
|
2011-04-15 15:14:02 +00:00
|
|
|
*
|
2015-02-26 10:37:37 +00:00
|
|
|
* The following SQL statement is just a help for developers and will not be
|
|
|
|
* executed!
|
2011-04-15 15:14:02 +00:00
|
|
|
*
|
2015-02-26 10:37:37 +00:00
|
|
|
* CREATE TABLE `users` (
|
|
|
|
* `uid` varchar(64) COLLATE utf8_unicode_ci NOT NULL,
|
|
|
|
* `password` varchar(255) COLLATE utf8_unicode_ci NOT NULL,
|
|
|
|
* PRIMARY KEY (`uid`)
|
|
|
|
* ) ENGINE=MyISAM DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci;
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
2016-05-04 06:34:39 +00:00
|
|
|
namespace OC\User;
|
|
|
|
|
2016-05-03 07:29:22 +00:00
|
|
|
use OC\Cache\CappedMemoryCache;
|
|
|
|
|
2015-02-26 10:37:37 +00:00
|
|
|
/**
|
|
|
|
* Class for user management in a SQL Database (e.g. MySQL, SQLite)
|
2010-07-15 12:09:22 +00:00
|
|
|
*/
|
2016-05-04 07:09:01 +00:00
|
|
|
class Database extends \OC\User\Backend implements \OCP\IUserBackend {
|
2016-05-03 07:29:22 +00:00
|
|
|
/** @var CappedMemoryCache */
|
|
|
|
private $cache;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* OC_User_Database constructor.
|
|
|
|
*/
|
|
|
|
public function __construct() {
|
|
|
|
$this->cache = new CappedMemoryCache();
|
|
|
|
}
|
2012-08-29 06:38:33 +00:00
|
|
|
|
2010-07-15 12:09:22 +00:00
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* Create a new user
|
2014-05-11 20:51:30 +00:00
|
|
|
* @param string $uid The username of the user to create
|
|
|
|
* @param string $password The password of the new user
|
|
|
|
* @return bool
|
2010-07-22 21:42:18 +00:00
|
|
|
*
|
2011-07-29 19:36:03 +00:00
|
|
|
* Creates a new user. Basic checking of username is done in OC_User
|
2011-04-18 09:39:29 +00:00
|
|
|
* itself, not in its subclasses.
|
2010-07-22 21:42:18 +00:00
|
|
|
*/
|
2013-12-11 15:22:26 +00:00
|
|
|
public function createUser($uid, $password) {
|
2014-03-06 21:34:43 +00:00
|
|
|
if (!$this->userExists($uid)) {
|
2016-05-04 06:34:39 +00:00
|
|
|
$query = \OC_DB::prepare('INSERT INTO `*PREFIX*users` ( `uid`, `password` ) VALUES( ?, ? )');
|
2014-11-06 14:42:06 +00:00
|
|
|
$result = $query->execute(array($uid, \OC::$server->getHasher()->hash($password)));
|
2011-04-15 15:14:02 +00:00
|
|
|
|
2010-07-22 21:42:18 +00:00
|
|
|
return $result ? true : false;
|
2010-07-15 17:56:13 +00:00
|
|
|
}
|
2014-03-06 21:34:43 +00:00
|
|
|
|
|
|
|
return false;
|
2010-07-21 15:53:51 +00:00
|
|
|
}
|
2010-07-22 21:42:18 +00:00
|
|
|
|
2011-04-16 23:04:23 +00:00
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* delete a user
|
2014-05-11 20:51:30 +00:00
|
|
|
* @param string $uid The username of the user to delete
|
|
|
|
* @return bool
|
2011-04-16 23:04:23 +00:00
|
|
|
*
|
2011-04-18 08:41:01 +00:00
|
|
|
* Deletes a user
|
2011-04-16 23:04:23 +00:00
|
|
|
*/
|
2013-12-11 15:22:26 +00:00
|
|
|
public function deleteUser($uid) {
|
2011-04-18 08:41:01 +00:00
|
|
|
// Delete user-group-relation
|
2016-05-04 06:34:39 +00:00
|
|
|
$query = \OC_DB::prepare('DELETE FROM `*PREFIX*users` WHERE `uid` = ?');
|
2014-03-09 11:22:47 +00:00
|
|
|
$result = $query->execute(array($uid));
|
|
|
|
|
2014-03-11 15:58:10 +00:00
|
|
|
if (isset($this->cache[$uid])) {
|
|
|
|
unset($this->cache[$uid]);
|
2014-03-10 16:27:51 +00:00
|
|
|
}
|
|
|
|
|
2014-03-11 15:58:10 +00:00
|
|
|
return $result ? true : false;
|
2011-04-16 23:04:23 +00:00
|
|
|
}
|
|
|
|
|
2010-07-15 12:09:22 +00:00
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* Set password
|
2014-05-11 20:51:30 +00:00
|
|
|
* @param string $uid The username
|
|
|
|
* @param string $password The new password
|
|
|
|
* @return bool
|
2010-07-22 21:42:18 +00:00
|
|
|
*
|
2011-04-18 08:41:01 +00:00
|
|
|
* Change the password of a user
|
2010-07-22 21:42:18 +00:00
|
|
|
*/
|
2013-12-11 15:22:26 +00:00
|
|
|
public function setPassword($uid, $password) {
|
|
|
|
if ($this->userExists($uid)) {
|
2016-05-04 06:34:39 +00:00
|
|
|
$query = \OC_DB::prepare('UPDATE `*PREFIX*users` SET `password` = ? WHERE `uid` = ?');
|
2014-11-06 14:42:06 +00:00
|
|
|
$result = $query->execute(array(\OC::$server->getHasher()->hash($password), $uid));
|
2011-04-18 08:41:01 +00:00
|
|
|
|
2014-03-09 11:22:47 +00:00
|
|
|
return $result ? true : false;
|
2011-04-18 13:07:14 +00:00
|
|
|
}
|
2014-03-07 07:46:34 +00:00
|
|
|
|
|
|
|
return false;
|
2010-07-15 12:09:22 +00:00
|
|
|
}
|
2013-02-22 16:21:57 +00:00
|
|
|
|
2013-02-11 21:01:52 +00:00
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* Set display name
|
2014-05-11 20:51:30 +00:00
|
|
|
* @param string $uid The username
|
|
|
|
* @param string $displayName The new display name
|
|
|
|
* @return bool
|
2013-02-11 21:01:52 +00:00
|
|
|
*
|
|
|
|
* Change the display name of a user
|
2013-01-28 13:23:15 +00:00
|
|
|
*/
|
2013-12-11 15:22:26 +00:00
|
|
|
public function setDisplayName($uid, $displayName) {
|
|
|
|
if ($this->userExists($uid)) {
|
2016-05-04 06:34:39 +00:00
|
|
|
$query = \OC_DB::prepare('UPDATE `*PREFIX*users` SET `displayname` = ? WHERE LOWER(`uid`) = LOWER(?)');
|
2013-12-11 15:22:26 +00:00
|
|
|
$query->execute(array($displayName, $uid));
|
2014-03-11 10:56:46 +00:00
|
|
|
$this->cache[$uid]['displayname'] = $displayName;
|
|
|
|
|
2013-02-11 21:01:52 +00:00
|
|
|
return true;
|
|
|
|
}
|
2014-03-06 21:34:43 +00:00
|
|
|
|
|
|
|
return false;
|
2013-01-28 13:23:15 +00:00
|
|
|
}
|
2010-07-19 16:52:49 +00:00
|
|
|
|
2013-02-11 21:01:52 +00:00
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* get display name of the user
|
2014-05-11 20:51:30 +00:00
|
|
|
* @param string $uid user ID of the user
|
2013-12-11 15:22:26 +00:00
|
|
|
* @return string display name
|
2013-02-11 21:01:52 +00:00
|
|
|
*/
|
|
|
|
public function getDisplayName($uid) {
|
2014-03-06 16:57:09 +00:00
|
|
|
$this->loadUser($uid);
|
2014-03-11 10:56:46 +00:00
|
|
|
return empty($this->cache[$uid]['displayname']) ? $uid : $this->cache[$uid]['displayname'];
|
2013-01-28 14:07:31 +00:00
|
|
|
}
|
2013-02-22 16:21:57 +00:00
|
|
|
|
2013-02-11 21:01:52 +00:00
|
|
|
/**
|
|
|
|
* Get a list of all display names and user ids.
|
2015-06-27 18:35:47 +00:00
|
|
|
*
|
|
|
|
* @param string $search
|
|
|
|
* @param string|null $limit
|
|
|
|
* @param string|null $offset
|
|
|
|
* @return array an array of all displayNames (value) and the corresponding uids (key)
|
2013-02-11 21:01:52 +00:00
|
|
|
*/
|
2013-01-28 14:07:31 +00:00
|
|
|
public function getDisplayNames($search = '', $limit = null, $offset = null) {
|
2015-05-18 14:38:56 +00:00
|
|
|
$parameters = [];
|
|
|
|
$searchLike = '';
|
|
|
|
if ($search !== '') {
|
|
|
|
$parameters[] = '%' . $search . '%';
|
|
|
|
$parameters[] = '%' . $search . '%';
|
|
|
|
$searchLike = ' WHERE LOWER(`displayname`) LIKE LOWER(?) OR '
|
|
|
|
. 'LOWER(`uid`) LIKE LOWER(?)';
|
|
|
|
}
|
|
|
|
|
2013-01-28 14:07:31 +00:00
|
|
|
$displayNames = array();
|
2016-05-04 06:34:39 +00:00
|
|
|
$query = \OC_DB::prepare('SELECT `uid`, `displayname` FROM `*PREFIX*users`'
|
2015-05-18 14:38:56 +00:00
|
|
|
. $searchLike .' ORDER BY `uid` ASC', $limit, $offset);
|
|
|
|
$result = $query->execute($parameters);
|
2013-02-11 21:01:52 +00:00
|
|
|
while ($row = $result->fetchRow()) {
|
|
|
|
$displayNames[$row['uid']] = $row['displayname'];
|
2013-01-31 11:09:42 +00:00
|
|
|
}
|
2013-02-22 16:21:57 +00:00
|
|
|
|
2013-02-11 21:01:52 +00:00
|
|
|
return $displayNames;
|
2013-01-28 14:07:31 +00:00
|
|
|
}
|
2013-02-22 16:21:57 +00:00
|
|
|
|
2010-07-15 12:09:22 +00:00
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* Check if the password is correct
|
2014-05-11 20:51:30 +00:00
|
|
|
* @param string $uid The username
|
|
|
|
* @param string $password The password
|
2014-05-11 17:05:28 +00:00
|
|
|
* @return string
|
2010-07-22 21:42:18 +00:00
|
|
|
*
|
2011-04-18 08:41:01 +00:00
|
|
|
* Check if the password is correct without logging in the user
|
2012-05-16 22:57:43 +00:00
|
|
|
* returns the user id or false
|
2010-07-22 21:42:18 +00:00
|
|
|
*/
|
2013-12-11 15:22:26 +00:00
|
|
|
public function checkPassword($uid, $password) {
|
2016-05-04 06:34:39 +00:00
|
|
|
$query = \OC_DB::prepare('SELECT `uid`, `password` FROM `*PREFIX*users` WHERE LOWER(`uid`) = LOWER(?)');
|
2013-12-11 15:22:26 +00:00
|
|
|
$result = $query->execute(array($uid));
|
2010-07-15 12:09:22 +00:00
|
|
|
|
2013-12-11 15:22:26 +00:00
|
|
|
$row = $result->fetchRow();
|
|
|
|
if ($row) {
|
|
|
|
$storedHash = $row['password'];
|
2014-11-06 14:42:06 +00:00
|
|
|
$newHash = '';
|
|
|
|
if(\OC::$server->getHasher()->verify($password, $storedHash, $newHash)) {
|
|
|
|
if(!empty($newHash)) {
|
|
|
|
$this->setPassword($uid, $password);
|
2012-02-26 12:49:51 +00:00
|
|
|
}
|
2014-03-06 16:57:09 +00:00
|
|
|
return $row['uid'];
|
2012-02-26 12:49:51 +00:00
|
|
|
}
|
2014-11-06 14:42:06 +00:00
|
|
|
|
2010-07-15 12:09:22 +00:00
|
|
|
}
|
2014-03-06 16:57:09 +00:00
|
|
|
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* Load an user in the cache
|
2014-03-06 21:23:17 +00:00
|
|
|
* @param string $uid the username
|
2014-05-11 17:05:28 +00:00
|
|
|
* @return boolean
|
2014-03-06 16:57:09 +00:00
|
|
|
*/
|
2014-03-11 10:56:46 +00:00
|
|
|
private function loadUser($uid) {
|
|
|
|
if (empty($this->cache[$uid])) {
|
2016-05-04 06:34:39 +00:00
|
|
|
$query = \OC_DB::prepare('SELECT `uid`, `displayname` FROM `*PREFIX*users` WHERE LOWER(`uid`) = LOWER(?)');
|
2014-03-06 16:57:09 +00:00
|
|
|
$result = $query->execute(array($uid));
|
|
|
|
|
2016-01-07 09:14:05 +00:00
|
|
|
if ($result === false) {
|
2016-05-04 06:34:39 +00:00
|
|
|
\OCP\Util::writeLog('core', \OC_DB::getErrorMessage(), \OCP\Util::ERROR);
|
2014-03-06 16:57:09 +00:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
while ($row = $result->fetchRow()) {
|
2014-03-11 10:56:46 +00:00
|
|
|
$this->cache[$uid]['uid'] = $row['uid'];
|
|
|
|
$this->cache[$uid]['displayname'] = $row['displayname'];
|
2012-02-26 12:49:51 +00:00
|
|
|
}
|
2010-07-15 12:09:22 +00:00
|
|
|
}
|
2014-03-06 16:57:09 +00:00
|
|
|
|
|
|
|
return true;
|
2010-07-15 12:09:22 +00:00
|
|
|
}
|
|
|
|
|
2010-09-12 15:04:52 +00:00
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* Get a list of all users
|
2010-09-12 15:04:52 +00:00
|
|
|
*
|
2015-06-27 18:35:47 +00:00
|
|
|
* @param string $search
|
|
|
|
* @param null|int $limit
|
|
|
|
* @param null|int $offset
|
|
|
|
* @return string[] an array of all uids
|
2010-09-12 15:04:52 +00:00
|
|
|
*/
|
2012-08-24 22:05:07 +00:00
|
|
|
public function getUsers($search = '', $limit = null, $offset = null) {
|
2015-05-18 14:38:56 +00:00
|
|
|
$parameters = [];
|
|
|
|
$searchLike = '';
|
|
|
|
if ($search !== '') {
|
|
|
|
$parameters[] = '%' . $search . '%';
|
|
|
|
$searchLike = ' WHERE LOWER(`uid`) LIKE LOWER(?)';
|
|
|
|
}
|
|
|
|
|
2016-05-04 06:34:39 +00:00
|
|
|
$query = \OC_DB::prepare('SELECT `uid` FROM `*PREFIX*users`' . $searchLike . ' ORDER BY `uid` ASC', $limit, $offset);
|
2015-05-18 14:38:56 +00:00
|
|
|
$result = $query->execute($parameters);
|
2012-07-31 00:20:46 +00:00
|
|
|
$users = array();
|
|
|
|
while ($row = $result->fetchRow()) {
|
|
|
|
$users[] = $row['uid'];
|
2010-09-12 15:04:52 +00:00
|
|
|
}
|
|
|
|
return $users;
|
|
|
|
}
|
2011-06-21 17:28:46 +00:00
|
|
|
|
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* check if a user exists
|
2011-06-21 17:28:46 +00:00
|
|
|
* @param string $uid the username
|
|
|
|
* @return boolean
|
|
|
|
*/
|
2012-09-07 13:22:01 +00:00
|
|
|
public function userExists($uid) {
|
2014-03-06 16:57:09 +00:00
|
|
|
$this->loadUser($uid);
|
2014-03-11 10:56:46 +00:00
|
|
|
return !empty($this->cache[$uid]);
|
2011-06-21 17:28:46 +00:00
|
|
|
}
|
2012-08-26 14:24:25 +00:00
|
|
|
|
|
|
|
/**
|
2014-05-19 15:50:53 +00:00
|
|
|
* get the user's home directory
|
2013-12-11 15:22:26 +00:00
|
|
|
* @param string $uid the username
|
2014-02-06 15:30:58 +00:00
|
|
|
* @return string|false
|
2013-12-11 15:22:26 +00:00
|
|
|
*/
|
2012-09-07 13:22:01 +00:00
|
|
|
public function getHome($uid) {
|
2013-12-11 15:22:26 +00:00
|
|
|
if ($this->userExists($uid)) {
|
2016-05-04 06:34:39 +00:00
|
|
|
return \OC::$server->getConfig()->getSystemValue("datadirectory", \OC::$SERVERROOT . "/data") . '/' . $uid;
|
2012-08-26 14:24:25 +00:00
|
|
|
}
|
2014-03-06 16:57:09 +00:00
|
|
|
|
|
|
|
return false;
|
2012-08-26 14:24:25 +00:00
|
|
|
}
|
2013-02-11 21:01:52 +00:00
|
|
|
|
|
|
|
/**
|
|
|
|
* @return bool
|
|
|
|
*/
|
|
|
|
public function hasUserListings() {
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2014-01-07 22:05:37 +00:00
|
|
|
/**
|
|
|
|
* counts the users in the database
|
|
|
|
*
|
2014-05-11 17:28:45 +00:00
|
|
|
* @return int|bool
|
2014-01-07 22:05:37 +00:00
|
|
|
*/
|
|
|
|
public function countUsers() {
|
2016-05-04 06:34:39 +00:00
|
|
|
$query = \OC_DB::prepare('SELECT COUNT(*) FROM `*PREFIX*users`');
|
2014-01-07 22:05:37 +00:00
|
|
|
$result = $query->execute();
|
2016-01-07 09:14:05 +00:00
|
|
|
if ($result === false) {
|
2016-05-04 06:34:39 +00:00
|
|
|
\OCP\Util::writeLog('core', \OC_DB::getErrorMessage(), \OCP\Util::ERROR);
|
2014-01-07 22:05:37 +00:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
return $result->fetchOne();
|
|
|
|
}
|
|
|
|
|
2015-10-05 09:50:36 +00:00
|
|
|
/**
|
|
|
|
* returns the username for the given login name in the correct casing
|
|
|
|
*
|
|
|
|
* @param string $loginName
|
|
|
|
* @return string|false
|
|
|
|
*/
|
|
|
|
public function loginName2UserName($loginName) {
|
|
|
|
if ($this->userExists($loginName)) {
|
|
|
|
return $this->cache[$loginName]['uid'];
|
|
|
|
}
|
|
|
|
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2014-12-12 16:25:03 +00:00
|
|
|
/**
|
|
|
|
* Backend name to be shown in user management
|
|
|
|
* @return string the name of the backend to be shown
|
|
|
|
*/
|
|
|
|
public function getBackendName(){
|
|
|
|
return 'Database';
|
|
|
|
}
|
|
|
|
|
2015-10-05 09:50:36 +00:00
|
|
|
public static function preLoginNameUsedAsUserName($param) {
|
|
|
|
if(!isset($param['uid'])) {
|
|
|
|
throw new \Exception('key uid is expected to be set in $param');
|
|
|
|
}
|
|
|
|
|
|
|
|
$backends = \OC::$server->getUserManager()->getBackends();
|
|
|
|
foreach ($backends as $backend) {
|
2016-05-04 06:34:39 +00:00
|
|
|
if ($backend instanceof \OC\User\Database) {
|
|
|
|
/** @var \OC\User\Database $backend */
|
2015-10-05 09:50:36 +00:00
|
|
|
$uid = $backend->loginName2UserName($param['uid']);
|
|
|
|
if ($uid !== false) {
|
|
|
|
$param['uid'] = $uid;
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
2010-07-15 17:56:13 +00:00
|
|
|
}
|