1076
by chadnickbok
Created a new app, logout, which when given a GET |
1 |
# IVLE
|
2 |
# Copyright (C) 2007-2009 The University of Melbourne
|
|
3 |
#
|
|
4 |
# This program is free software; you can redistribute it and/or modify
|
|
5 |
# it under the terms of the GNU General Public License as published by
|
|
6 |
# the Free Software Foundation; either version 2 of the License, or
|
|
7 |
# (at your option) any later version.
|
|
8 |
#
|
|
9 |
# This program is distributed in the hope that it will be useful,
|
|
10 |
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
11 |
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
12 |
# GNU General Public License for more details.
|
|
13 |
#
|
|
14 |
# You should have received a copy of the GNU General Public License
|
|
15 |
# along with this program; if not, write to the Free Software
|
|
16 |
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
|
|
17 |
||
1099.1.41
by William Grant
Port www/apps/logout to new framework (in ivle.webapp.security). |
18 |
# Author: Will Grant, Nick Chadwick
|
19 |
||
1099.1.120
by William Grant
Move the login machinery to the new framework. |
20 |
import urllib |
21 |
import datetime |
|
22 |
try: |
|
23 |
import mod_python.Cookie |
|
24 |
except ImportError: |
|
25 |
# This needs to be importable from outside Apache.
|
|
26 |
pass
|
|
27 |
||
28 |
import ivle.util |
|
1137
by William Grant
Attempt to use subject pulldown modules to enrol users whenever they log in. |
29 |
import ivle.pulldown_subj |
1099.1.161
by William Grant
Move ivle.dispatch.login.get_user_details() to ivle.webapp.security. |
30 |
import ivle.webapp.security |
1099.1.120
by William Grant
Move the login machinery to the new framework. |
31 |
from ivle.auth import authenticate, AuthError |
1099.1.41
by William Grant
Port www/apps/logout to new framework (in ivle.webapp.security). |
32 |
from ivle.webapp.base.xhtml import XHTMLView |
1099.1.120
by William Grant
Move the login machinery to the new framework. |
33 |
from ivle.webapp.base.plugins import CookiePlugin |
34 |
||
35 |
class LoginView(XHTMLView): |
|
36 |
'''A view to allow a user to log in.'''
|
|
37 |
template = 'login.html' |
|
1099.1.129
by William Grant
Allow XHTML views to specify that they cannot have overlays. |
38 |
allow_overlays = False |
1099.1.120
by William Grant
Move the login machinery to the new framework. |
39 |
|
40 |
def authorize(self, req): |
|
41 |
return True |
|
42 |
||
43 |
def populate(self, req, ctx): |
|
44 |
fields = req.get_fieldstorage() |
|
45 |
nexturl = fields.getfirst('url') |
|
46 |
||
47 |
if nexturl is None: |
|
48 |
nexturl = '/' |
|
49 |
||
1154
by William Grant
Only redirect +login for logged in users if the method is not POST. We do this |
50 |
# We are already logged in. If it is a POST, they might be trying to
|
51 |
# clobber their session with some new credentials. That's their own
|
|
52 |
# business, so we let them do it. Otherwise, we don't bother prompting
|
|
53 |
# and just redirect to the destination.
|
|
1099.1.125
by William Grant
Move the pending/no_agreement handling into the new login machinery. |
54 |
# Note that req.user is None even if we are 'logged in', if the user is
|
1154
by William Grant
Only redirect +login for logged in users if the method is not POST. We do this |
55 |
# invalid (state != enabled, or expired).
|
56 |
if req.method != "POST" and req.user is not None: |
|
1099.1.120
by William Grant
Move the login machinery to the new framework. |
57 |
req.throw_redirect(nexturl) |
58 |
||
1099.1.209
by William Grant
Don't escape / in paths when they are in +login/+tos URLs. |
59 |
# Don't give any URL if we want /.
|
60 |
if nexturl == '/': |
|
61 |
query_string = '' |
|
62 |
else: |
|
63 |
query_string = '?url=' + urllib.quote(nexturl, safe="/~") |
|
64 |
||
65 |
ctx['path'] = ivle.util.make_path('+login') + query_string |
|
1099.1.120
by William Grant
Move the login machinery to the new framework. |
66 |
|
1099.1.125
by William Grant
Move the pending/no_agreement handling into the new login machinery. |
67 |
# If this succeeds, the user is invalid.
|
1099.1.161
by William Grant
Move ivle.dispatch.login.get_user_details() to ivle.webapp.security. |
68 |
user = ivle.webapp.security.get_user_details(req) |
1099.1.125
by William Grant
Move the pending/no_agreement handling into the new login machinery. |
69 |
if user is not None: |
70 |
if user.state == "no_agreement": |
|
71 |
# Authenticated, but need to accept the ToS. Send them there.
|
|
72 |
# IMPORTANT NOTE FOR HACKERS: You can't simply disable this
|
|
73 |
# if you are not planning to display a ToS page - the ToS
|
|
74 |
# acceptance process actually calls usrmgt to create the user
|
|
75 |
# jails and related stuff.
|
|
1099.1.209
by William Grant
Don't escape / in paths when they are in +login/+tos URLs. |
76 |
req.throw_redirect(ivle.util.make_path('+tos') + query_string) |
1099.1.125
by William Grant
Move the pending/no_agreement handling into the new login machinery. |
77 |
elif user.state == "pending": |
78 |
# FIXME: this isn't quite the right answer, but it
|
|
79 |
# should be more robust in the short term.
|
|
80 |
session = req.get_session() |
|
81 |
session.invalidate() |
|
82 |
session.delete() |
|
83 |
user.state = u'no_agreement' |
|
84 |
req.store.commit() |
|
85 |
req.throw_redirect(nexturl) |
|
86 |
||
1099.1.120
by William Grant
Move the login machinery to the new framework. |
87 |
if req.method == "POST": |
88 |
# While req.user is normally set to get_user_details, it won't set
|
|
89 |
# it if the account isn't valid. So we get it ourselves.
|
|
1099.1.161
by William Grant
Move ivle.dispatch.login.get_user_details() to ivle.webapp.security. |
90 |
user = ivle.webapp.security.get_user_details(req) |
1099.1.120
by William Grant
Move the login machinery to the new framework. |
91 |
|
92 |
badlogin = None |
|
93 |
||
94 |
username = fields.getfirst('user') |
|
95 |
password = fields.getfirst('pass') |
|
96 |
if username is not None: |
|
97 |
# From this point onwards, we will be showing an error message
|
|
98 |
# if unsuccessful.
|
|
99 |
# Authenticate
|
|
100 |
if password is None: |
|
101 |
badlogin = "No password supplied." |
|
102 |
else: |
|
103 |
user = None |
|
104 |
try: |
|
105 |
user = authenticate.authenticate(req.store, |
|
106 |
username.value, password.value) |
|
107 |
except AuthError, msg: |
|
108 |
badlogin = msg |
|
109 |
if user is None: |
|
110 |
# Must have got an error. Do not authenticate.
|
|
1099.1.123
by William Grant
Don't crash when not authenticated, and display an error on password absence. |
111 |
# The except: above will have set a message.
|
1099.1.120
by William Grant
Move the login machinery to the new framework. |
112 |
pass
|
113 |
else: |
|
114 |
# Success - Set the session and redirect to the URL.
|
|
115 |
session = req.get_session() |
|
116 |
session['login'] = user.login |
|
117 |
session.save() |
|
1130
by William Grant
Unlock the session everywhere as soon as we are done with it, and add a warning |
118 |
session.unlock() |
1099.1.120
by William Grant
Move the login machinery to the new framework. |
119 |
user.last_login = datetime.datetime.now() |
120 |
||
121 |
# Create cookies for plugins that might request them.
|
|
1092.1.59
by William Grant
Move the plugin loading/indexing logic into ivle.config.Config. |
122 |
for plugin in req.config.plugin_index[CookiePlugin]: |
1099.1.120
by William Grant
Move the login machinery to the new framework. |
123 |
for cookie in plugin.cookies: |
124 |
# The function can be None if they just need to be
|
|
125 |
# deleted at logout.
|
|
126 |
if plugin.cookies[cookie] is not None: |
|
127 |
req.add_cookie(mod_python.Cookie.Cookie(cookie, |
|
128 |
plugin.cookies[cookie](user), path='/')) |
|
129 |
||
1137
by William Grant
Attempt to use subject pulldown modules to enrol users whenever they log in. |
130 |
# Add any new enrolments.
|
131 |
ivle.pulldown_subj.enrol_user(req.store, user) |
|
132 |
req.store.commit() |
|
133 |
||
1099.1.120
by William Grant
Move the login machinery to the new framework. |
134 |
req.throw_redirect(nexturl) |
135 |
||
1099.1.123
by William Grant
Don't crash when not authenticated, and display an error on password absence. |
136 |
# We didn't succeed.
|
137 |
# Render the login form with the error message.
|
|
138 |
ctx['error'] = badlogin |
|
1099.1.120
by William Grant
Move the login machinery to the new framework. |
139 |
|
1099.1.41
by William Grant
Port www/apps/logout to new framework (in ivle.webapp.security). |
140 |
|
141 |
class LogoutView(XHTMLView): |
|
142 |
'''A view to log the current session out.'''
|
|
143 |
template = 'logout.html' |
|
1099.1.129
by William Grant
Allow XHTML views to specify that they cannot have overlays. |
144 |
allow_overlays = False |
1099.1.41
by William Grant
Port www/apps/logout to new framework (in ivle.webapp.security). |
145 |
|
1099.1.110
by William Grant
Implement an authorization system in the new framework. This breaks the REST |
146 |
def authorize(self, req): |
1099.1.126
by William Grant
Allow any authenticated (even invalid) user to use the logout view. |
147 |
# This can be used by any authenticated user, even if they haven't
|
148 |
# accepted the ToS yet.
|
|
1099.1.161
by William Grant
Move ivle.dispatch.login.get_user_details() to ivle.webapp.security. |
149 |
return ivle.webapp.security.get_user_details(req) is not None |
1099.1.110
by William Grant
Implement an authorization system in the new framework. This breaks the REST |
150 |
|
1099.1.41
by William Grant
Port www/apps/logout to new framework (in ivle.webapp.security). |
151 |
def populate(self, req, ctx): |
152 |
if req.method == "POST": |
|
153 |
req.logout() |
|
154 |
else: |
|
1099.1.120
by William Grant
Move the login machinery to the new framework. |
155 |
ctx['path'] = ivle.util.make_path('+logout') |