2008-12-26 20:18:23 +01:00
|
|
|
##@file
|
|
|
|
# CAS authentication backend file
|
|
|
|
|
|
|
|
##@class
|
|
|
|
# CAS authentication backend class
|
2007-03-01 21:03:19 +01:00
|
|
|
package Lemonldap::NG::Portal::AuthCAS;
|
|
|
|
|
|
|
|
use strict;
|
|
|
|
use Lemonldap::NG::Portal::Simple;
|
|
|
|
|
2009-11-17 16:43:05 +01:00
|
|
|
our $VERSION = '0.13';
|
2008-06-01 08:25:09 +02:00
|
|
|
|
2009-02-17 15:56:38 +01:00
|
|
|
## @apmethod int authInit()
|
2009-11-17 16:43:05 +01:00
|
|
|
# Try to load AuthCAS perl module
|
2008-12-28 09:36:52 +01:00
|
|
|
# @return Lemonldap::NG::Portal constant
|
2008-06-06 05:51:39 +02:00
|
|
|
sub authInit {
|
2009-11-17 16:43:05 +01:00
|
|
|
my $self = shift;
|
|
|
|
|
|
|
|
# require Perl module
|
|
|
|
eval { require AuthCAS };
|
|
|
|
if ($@) {
|
|
|
|
$self->lmLog(
|
|
|
|
"Module AuthCAS not found in @INC",
|
|
|
|
'error' );
|
|
|
|
return PE_ERROR;
|
|
|
|
}
|
|
|
|
|
2008-10-07 22:15:48 +02:00
|
|
|
PE_OK;
|
2008-06-06 05:51:39 +02:00
|
|
|
}
|
2008-06-01 08:25:09 +02:00
|
|
|
|
2009-02-17 15:56:38 +01:00
|
|
|
## @apmethod int extractFormInfo()
|
2008-12-26 18:58:48 +01:00
|
|
|
# Read username return by CAS authentication system.
|
|
|
|
# If user isn't authenticated, redirect it to CAS portal.
|
2008-12-28 09:36:52 +01:00
|
|
|
# @return Lemonldap::NG::Portal constant
|
2008-06-06 05:51:39 +02:00
|
|
|
sub extractFormInfo {
|
|
|
|
my $self = shift;
|
|
|
|
my $cas = new AuthCAS(
|
|
|
|
casUrl => $self->{CAS_url},
|
|
|
|
CAFile => $self->{CAS_CAFile},
|
|
|
|
);
|
2009-11-05 15:25:55 +01:00
|
|
|
|
2009-11-07 14:05:50 +01:00
|
|
|
my $casLoginUrl = $self->{CAS_loginUrl};
|
2009-11-05 15:25:55 +01:00
|
|
|
my $casValidationUrl = $self->{CAS_validationUrl};
|
2009-11-07 14:05:50 +01:00
|
|
|
if ( $self->{_url} ) {
|
|
|
|
my $url_param = 'url=' . $self->{_url};
|
|
|
|
$casLoginUrl .= ( $casLoginUrl =~ /\?/ ? '&' : '?' ) . $url_param;
|
|
|
|
$casValidationUrl .=
|
|
|
|
( $casValidationUrl =~ /\?/ ? '&' : '?' ) . $url_param;
|
2009-11-05 15:25:55 +01:00
|
|
|
}
|
|
|
|
|
2009-11-07 14:05:50 +01:00
|
|
|
my $login_url = $cas->getServerLoginURL($casLoginUrl);
|
2008-06-06 05:51:39 +02:00
|
|
|
|
|
|
|
my $ticket = $self->param('ticket');
|
|
|
|
|
|
|
|
# Unless a ticket has been found, we redirect the user
|
2009-11-07 14:05:50 +01:00
|
|
|
unless ( $self->{user} = $cas->validateST( $casValidationUrl, $ticket ) ) {
|
2009-07-21 15:52:10 +02:00
|
|
|
print $self->redirect(
|
2008-06-06 05:51:39 +02:00
|
|
|
-uri => $login_url,
|
2009-08-18 15:33:36 +02:00
|
|
|
-status => '303 See Other'
|
2008-06-06 05:51:39 +02:00
|
|
|
);
|
|
|
|
exit;
|
|
|
|
}
|
|
|
|
PE_OK;
|
|
|
|
}
|
2008-06-01 08:25:09 +02:00
|
|
|
|
2009-02-17 15:56:38 +01:00
|
|
|
## @apmethod int setAuthSessionInfo()
|
|
|
|
# Does nothing here.
|
|
|
|
# @return Lemonldap::NG::Portal constant
|
|
|
|
sub setAuthSessionInfo {
|
2009-05-26 14:24:03 +02:00
|
|
|
my $self = shift;
|
2009-05-25 14:59:57 +02:00
|
|
|
|
|
|
|
# Store user submitted login for basic rules
|
|
|
|
$self->{sessionInfo}->{'_user'} = $self->{'user'};
|
|
|
|
|
2009-02-17 15:56:38 +01:00
|
|
|
PE_OK;
|
|
|
|
}
|
|
|
|
|
|
|
|
## @apmethod int authenticate()
|
2008-12-26 18:58:48 +01:00
|
|
|
# Does nothing.
|
2008-12-28 09:36:52 +01:00
|
|
|
# @return Lemonldap::NG::Portal constant
|
2008-06-06 05:51:39 +02:00
|
|
|
sub authenticate {
|
|
|
|
PE_OK;
|
|
|
|
}
|
2007-03-01 21:03:19 +01:00
|
|
|
|
|
|
|
1;
|
|
|
|
__END__
|
|
|
|
|
|
|
|
=head1 NAME
|
|
|
|
|
|
|
|
Lemonldap::NG::Portal::AuthCAS - Perl extension for building Lemonldap::NG
|
|
|
|
compatible portals with CAS authentication. EXPERIMENTAL AND NOT FINISHED!
|
|
|
|
|
|
|
|
=head1 SYNOPSIS
|
|
|
|
|
|
|
|
use Lemonldap::NG::Portal::SharedConf;
|
|
|
|
my $portal = new Lemonldap::NG::Portal::Simple(
|
|
|
|
configStorage => {...}, # See Lemonldap::NG::Portal
|
|
|
|
authentication => 'CAS',
|
|
|
|
CAS_url => 'https://cas.myserver',
|
|
|
|
CAS_CAFile => '/etc/httpd/conf/ssl.crt/ca-bundle.crt',
|
|
|
|
CAS_loginUrl => 'http://myserver/app.cgi',
|
|
|
|
CAS_validationUrl => 'http://myserver/app.cgi',
|
|
|
|
);
|
|
|
|
|
|
|
|
if($portal->process()) {
|
|
|
|
# Write here the menu with CGI methods. This page is displayed ONLY IF
|
|
|
|
# the user was not redirected here.
|
2008-06-06 05:51:39 +02:00
|
|
|
print $portal->header('text/html; charset=utf8'); # DON'T FORGET THIS (see CGI(3))
|
2007-03-01 21:03:19 +01:00
|
|
|
print "...";
|
|
|
|
|
|
|
|
# or redirect the user to the menu
|
|
|
|
print $portal->redirect( -uri => 'https://portal/menu');
|
|
|
|
}
|
|
|
|
else {
|
|
|
|
# If the user enters here, IT MEANS THAT CAS REDIRECTION DOES NOT WORK
|
2008-06-06 05:51:39 +02:00
|
|
|
print $portal->header('text/html; charset=utf8'); # DON'T FORGET THIS (see CGI(3))
|
2007-03-01 21:03:19 +01:00
|
|
|
print "<html><body><h1>Unable to work</h1>";
|
|
|
|
print "This server isn't well configured. Contact your administrator.";
|
|
|
|
print "</body></html>";
|
|
|
|
}
|
|
|
|
|
|
|
|
=head1 DESCRIPTION
|
|
|
|
|
|
|
|
This library just overload few methods of Lemonldap::NG::Portal::Simple to use
|
|
|
|
CAS mechanism: we've just try to get CAS ticket.
|
|
|
|
|
|
|
|
See L<Lemonldap::NG::Portal::Simple> for usage and other methods.
|
|
|
|
|
|
|
|
=head1 SEE ALSO
|
|
|
|
|
2007-04-02 21:13:05 +02:00
|
|
|
L<Lemonldap::NG::Portal>, L<Lemonldap::NG::Portal::Simple>,
|
|
|
|
http://wiki.lemonldap.objectweb.org/xwiki/bin/view/NG/Presentation
|
2007-03-01 21:03:19 +01:00
|
|
|
|
|
|
|
=head1 AUTHOR
|
|
|
|
|
|
|
|
Xavier Guimard, E<lt>x.guimard@free.frE<gt>
|
|
|
|
|
2007-04-14 15:12:11 +02:00
|
|
|
=head1 BUG REPORT
|
|
|
|
|
|
|
|
Use OW2 system to report bug or ask for features:
|
|
|
|
L<http://forge.objectweb.org/tracker/?group_id=274>
|
|
|
|
|
|
|
|
=head1 DOWNLOAD
|
|
|
|
|
|
|
|
Lemonldap::NG is available at
|
|
|
|
L<http://forge.objectweb.org/project/showfiles.php?group_id=274>
|
|
|
|
|
2007-03-01 21:03:19 +01:00
|
|
|
=head1 COPYRIGHT AND LICENSE
|
|
|
|
|
|
|
|
Copyright (C) 2007 by Xavier Guimard E<lt>x.guimard@free.frE<gt>
|
|
|
|
|
|
|
|
This library is free software; you can redistribute it and/or modify
|
|
|
|
it under the same terms as Perl itself, either Perl version 5.8.4 or,
|
|
|
|
at your option, any later version of Perl 5 you may have available.
|
|
|
|
|
|
|
|
=cut
|
|
|
|
|