diff --git a/auth/cas/lib.php b/auth/cas/lib.php index 44e771fa0a9..f4399fbde55 100644 --- a/auth/cas/lib.php +++ b/auth/cas/lib.php @@ -41,7 +41,7 @@ function cas_ldap_auth_user_login ($username, $password) { if ($CFG->auth == "cas" && !empty($CFG->cas_enabled)){ //cas specific if ($CFG->cas_create_user=="0"){ - if (get_user_info_from_db("username", $username)){ + if (record_exists('user', 'username', $username)){ return true; }else{ return false; @@ -67,7 +67,7 @@ function cas_ldap_auth_user_login ($username, $password) { ldap_close($ldap_connection); if ($ldap_login) { if ($CFG->cas_create_user=="0"){ //cas specific - if (get_user_info_from_db("username", $username)){ + if (record_exists('user', 'username', $username)){ return true; }else{ return false; @@ -105,8 +105,8 @@ function cas_authenticate_user_login ($username, $password) { phpCAS::authenticateIfNeeded(); } if ($CFG->cas_create_user=="0"){ - if (get_user_info_from_db("username", phpCAS::getUser())){ - $user = authenticate_user_login(phpCAS::getUser(), 'cas'); + if (record_exists('user', 'username', phpCAS::getUser())) { + $user = authenticate_user_login(phpCAS::getUser(), 'cas'); }else{ //login as guest if CAS but not Moodle and not automatic creation if ($CFG->guestloginbutton){ @@ -142,7 +142,7 @@ function cas_automatic_authenticate ($user="") { } if (phpCAS::isAuthenticated()){ if ($CFG->cas_create_user=="0"){ - if (get_user_info_from_db("username", phpCAS::getUser())){ + if (record_exists('user', 'username', phpCAS::getUser())) { $user = authenticate_user_login(phpCAS::getUser(), 'cas'); }else{ //login as guest if CAS but not Moodle and not automatic creation @@ -166,4 +166,4 @@ function cas_automatic_authenticate ($user="") { } } -?> \ No newline at end of file +?> diff --git a/auth/email/lib.php b/auth/email/lib.php index 84dd0ca538c..6807f268d26 100644 --- a/auth/email/lib.php +++ b/auth/email/lib.php @@ -7,7 +7,7 @@ function auth_user_login ($username, $password) { global $CFG; - if (! $user = get_user_info_from_db("username", $username)) { + if (! $user = get_record('user', 'username', $username)) { return false; } diff --git a/auth/manual/lib.php b/auth/manual/lib.php index 657e95a428e..301d17f0428 100644 --- a/auth/manual/lib.php +++ b/auth/manual/lib.php @@ -5,7 +5,7 @@ function auth_user_login ($username, $password) { // Returns false if the username doesn't exist yet // Returns true if the username and password work - if ($user = get_user_info_from_db("username", $username)) { + if ($user = get_record('user', 'username', $username)) { return ($user->password == md5($password)); } diff --git a/auth/none/lib.php b/auth/none/lib.php index e7a1a2c8760..a1b3f100f01 100644 --- a/auth/none/lib.php +++ b/auth/none/lib.php @@ -5,11 +5,11 @@ function auth_user_login ($username, $password) { // Returns true if the username doesn't exist yet // Returns true if the username and password work - if (! $user = get_user_info_from_db("username", $username)) { - return true; + if ($user = get_record('user', 'username', $username)) { + return ($user->password == md5($password)); } - return ($user->password == md5($password)); + return false; } diff --git a/auth/shibboleth/lib.php b/auth/shibboleth/lib.php index 4024a0d59fe..28cbf505dd6 100755 --- a/auth/shibboleth/lib.php +++ b/auth/shibboleth/lib.php @@ -5,12 +5,9 @@ function auth_user_login ($username, $password) { global $CFG; - if($_SERVER[$CFG->shib_user_attribute] == $username) { - return true; - } // Returns false if the username doesn't exist yet // Returns true if the username and password work - if ($user = get_user_info_from_db("username", $username)) { + if ($user = get_record('user', 'username', $username)) { if($user->auth == "shibboleth") { return false; exit; @@ -34,7 +31,7 @@ function auth_get_userinfo($username) { $search_attribs = array(); foreach ($attrmap as $key=>$value) { - $result[$key]=$_SERVER[$value]; + $result[$key]=utf8_decode($_SERVER[$value]); } return $result; } @@ -50,8 +47,8 @@ function auth_shib_attributes (){ $moodleattributes = array(); foreach ($fields as $field) { - if ($config["auth_user_$field"]) { - $moodleattributes[$field] = $config["auth_user_$field"]; + if ($config["auth_shib_user_$field"]) { + $moodleattributes[$field] = $config["auth_shib_user_$field"]; } } $moodleattributes['username']=$config["shib_user_attribute"]; diff --git a/course/loginas.php b/course/loginas.php index d46a407cedb..6dfd5cd3732 100644 --- a/course/loginas.php +++ b/course/loginas.php @@ -17,10 +17,7 @@ } if (isset($USER->realuser)) { /// Reset user back to their real self - $USER = get_user_info_from_db("id", $USER->realuser); - $USER->loggedin = true; - $USER->site = $CFG->wwwroot; - $USER->sessionIP = md5(getremoteaddr()); // Store the current IP in the session + $USER = get_complete_user_data('id', $USER->realuser); if (isset($SESSION->oldcurrentgroup)) { // Restore previous "current group" cache. $SESSION->currentgroup = $SESSION->oldcurrentgroup; @@ -64,11 +61,8 @@ $teacher_name = fullname($USER, true); $teacher_id = "$USER->id"; - $USER = get_user_info_from_db("id", $user); // Create the new USER object with all details - $USER->loggedin = true; - $USER->site = $CFG->wwwroot; + $USER = get_complete_user_data('id', $user); // Create the new USER object with all details $USER->realuser = $teacher_id; - $USER->sessionIP = md5(getremoteaddr()); // Store the current IP in the session if (isset($SESSION->currentgroup)) { // Remember current cache setting for later $SESSION->oldcurrentgroup = $SESSION->currentgroup; @@ -89,4 +83,4 @@ notice($strloggedinas, "$CFG->wwwroot/course/view.php?id=$course->id"); -?> \ No newline at end of file +?> diff --git a/lib/datalib.php b/lib/datalib.php index 78d421e9c12..51c96108419 100644 --- a/lib/datalib.php +++ b/lib/datalib.php @@ -1230,74 +1230,6 @@ function update_record($table, $dataobject) { /// USER DATABASE //////////////////////////////////////////////// -/** - * Get a complete user record, which includes all the info - * - * in the user record, as well as membership information - * Suitable for setting as $USER session cookie. - * - * @uses $CFG - * @uses SITEID - * @param string $field The first table field to be checked for a given value. - * @param string $value The value to match for $field. - * @return user A {@link $USER} object. - * @todo Finish documenting this function - */ -function get_user_info_from_db($field, $value) { - - global $CFG; - - if (!$field or !$value) { - return false; - } - -/// Get all the basic user data - - if (! $user = get_record_select('user', $field .' = \''. $value .'\' AND deleted <> \'1\'')) { - return false; - } - -/// Add membership information - - if ($admins = get_records('user_admins', 'userid', $user->id)) { - $user->admin = true; - } - - $user->student[SITEID] = isstudent(SITEID, $user->id); - -/// Determine enrolments based on current enrolment module - - require_once($CFG->dirroot .'/enrol/'. $CFG->enrol .'/enrol.php'); - $enrol = new enrolment_plugin(); - $enrol->get_student_courses($user); - $enrol->get_teacher_courses($user); - -/// Get various settings and preferences - - if ($displays = get_records('course_display', 'userid', $user->id)) { - foreach ($displays as $display) { - $user->display[$display->course] = $display->display; - } - } - - if ($preferences = get_records('user_preferences', 'userid', $user->id)) { - foreach ($preferences as $preference) { - $user->preference[$preference->name] = $preference->value; - } - } - - if ($groups = get_records('groups_members', 'userid', $user->id)) { - foreach ($groups as $groupmember) { - $courseid = get_field('groups', 'courseid', 'id', $groupmember->groupid); - $user->groupmember[$courseid] = $groupmember->groupid; - } - } - - - return $user; -} - - /** * Does this username and password specify a valid admin user? * @@ -1325,7 +1257,7 @@ function adminlogin($username, $md5password) { * @todo Is object(user) a correct return type? Or is array the proper return type with a note that the contents include all details for a user. */ function get_guest() { - return get_user_info_from_db('username', 'guest'); + return get_complete_user_data('username', 'guest'); } diff --git a/lib/moodlelib.php b/lib/moodlelib.php index c20d27c3d70..e1134f01a5c 100644 --- a/lib/moodlelib.php +++ b/lib/moodlelib.php @@ -1670,6 +1670,19 @@ function remove_from_metacourse($metacourseid, $courseid) { } +/** + * Determines if a user is currently logged in + * + * @uses $USER + * @return boolean + */ +function isloggedin() { + global $USER; + + return (!empty($USER->id)); +} + + /** * Determines if a user an admin * @@ -2097,7 +2110,7 @@ function create_user_record($username, $password, $auth='') { $newuser->timemodified = time(); if (insert_record('user', $newuser)) { - $user = get_user_info_from_db('username', $newuser->username); + $user = get_complete_user_data('username', $newuser->username); if($CFG->{'auth_'.$newuser->auth.'_forcechangepassword'}){ set_user_preference('auth_forcepasswordchange', 1, $user); } @@ -2128,7 +2141,7 @@ function update_user_record($username) { } } } - return get_user_info_from_db('username', $username); + return get_complete_user_data('username', $username); } function truncate_userinfo($info) { @@ -2204,7 +2217,7 @@ function authenticate_user_login($username, $password) { // First try to find the user in the database - if (!$user = get_user_info_from_db('username', $username)) { + if (!$user = get_complete_user_data('username', $username)) { $user->id = 0; // Not a user $user->auth = $CFG->auth; } @@ -2273,9 +2286,6 @@ function authenticate_user_login($username, $password) { } } } - if ($user) { - $user->sessionIP = md5(getremoteaddr()); // Store the current IP in the session - } return $user; } else { @@ -2285,6 +2295,111 @@ function authenticate_user_login($username, $password) { } } +/** + * Get a complete user record, which includes all the info + * in the user record, as well as membership information + * Intended for setting as $USER session variable + * + * @uses $CFG + * @uses SITEID + * @param string $field The user field to be checked for a given value. + * @param string $value The value to match for $field. + * @return user A {@link $USER} object. + */ +function get_complete_user_data($field, $value) { + + global $CFG; + + if (!$field || !$value) { + return false; + } + +/// Get all the basic user data + + if (! $user = get_record_select('user', $field .' = \''. $value .'\' AND deleted <> \'1\'')) { + return false; + } + +/// Add membership information + + if ($admins = get_records('user_admins', 'userid', $user->id)) { + $user->admin = true; + } + + $user->student[SITEID] = isstudent(SITEID, $user->id); + +/// Determine enrolments based on current enrolment module + + require_once($CFG->dirroot .'/enrol/'. $CFG->enrol .'/enrol.php'); + $enrol = new enrolment_plugin(); + $enrol->get_student_courses($user); + $enrol->get_teacher_courses($user); + +/// Get various settings and preferences + + if ($displays = get_records('course_display', 'userid', $user->id)) { + foreach ($displays as $display) { + $user->display[$display->course] = $display->display; + } + } + + if ($preferences = get_records('user_preferences', 'userid', $user->id)) { + foreach ($preferences as $preference) { + $user->preference[$preference->name] = $preference->value; + } + } + + if ($groups = get_records('groups_members', 'userid', $user->id)) { + foreach ($groups as $groupmember) { + $courseid = get_field('groups', 'courseid', 'id', $groupmember->groupid); + $user->groupmember[$courseid] = $groupmember->groupid; + } + } + +/// Rewrite some variables if necessary + if (!empty($user->description)) { + $user->description = true; // No need to cart all of it around + } + if ($user->username == 'guest') { + $user->lang = $CFG->lang; // Guest language always same as site + $user->firstname = get_string('guestuser'); // Name always in current language + $user->lastname = ' '; + } + + $user->loggedin = true; + $user->site = $CFG->wwwroot; // for added security, store the site in the session + $user->sesskey = random_string(10); + $user->sessionIP = md5(getremoteaddr()); // Store the current IP in the session + + return $user; + +} + +function get_user_info_from_db($field, $value) { // For backward compatibility + return get_complete_user_data($field, $value); +} + +/* + * When logging in, this function is run to set certain preferences + * for the current SESSION + */ +function set_login_session_preferences() { + global $SESSION; + + $SESSION->justloggedin = true; + + unset($SESSION->lang); + unset($SESSION->encoding); + $SESSION->encoding = get_string('thischarset'); + + // Restore the calendar filters, if saved + if (intval(get_user_preferences('calendar_persistflt', 0))) { + include_once($CFG->dirroot.'/calendar/lib.php'); + calendar_set_filters_status(get_user_preferences('calendar_savedflt', 0xff)); + } +} + + /** * Enrols (or re-enrols) a student in a given course * diff --git a/lib/setup.php b/lib/setup.php index 2ac3c32f3dd..b26f00a5bf9 100644 --- a/lib/setup.php +++ b/lib/setup.php @@ -371,9 +371,7 @@ global $THEME; if (empty($_SESSION['USER']->id)) { // Allow W3CValidator in as user called w3cvalidator (or guest) if ((strpos($_SERVER['HTTP_USER_AGENT'], 'W3C_Validator') !== false) or (strpos($_SERVER['HTTP_USER_AGENT'], 'Cynthia') !== false )) { - if ($USER = get_user_info_from_db("username", "w3cvalidator")) { - $USER->loggedin = true; - $USER->site = $CFG->wwwroot; + if ($USER = get_complete_user_data("username", "w3cvalidator")) { $USER->ignoresesskey = true; } else { $USER = guest_user(); diff --git a/login/change_password.php b/login/change_password.php index 02d0257cb49..62bbe727003 100644 --- a/login/change_password.php +++ b/login/change_password.php @@ -22,7 +22,7 @@ $username = $frm->username; $password = md5($frm->newpassword1); - $user = get_user_info_from_db("username", $username); + $user = get_complete_user_data("username", $username); if (isguest($user->id)) { error("Can't change guest password!"); @@ -55,8 +55,6 @@ } $USER = $user; - $USER->loggedin = true; - $USER->site = $CFG->wwwroot; // for added security // register success changing password unset_user_preference('auth_forcepasswordchange'); diff --git a/login/confirm.php b/login/confirm.php index 5befc8b21ac..e4d10570591 100644 --- a/login/confirm.php +++ b/login/confirm.php @@ -5,7 +5,7 @@ if (isset($_GET['p']) and isset($_GET['s']) ) { # p = user.secret s = user.username - $user = get_user_info_from_db("username", $_GET['s']); + $user = get_complete_user_data('username', $_GET['s']); if (!empty($user)) { @@ -34,15 +34,12 @@ // The user has confirmed successfully, let's log them in - if (!$USER = get_user_info_from_db("username", $user->username)) { + if (!$USER = get_complete_user_data('username', $user->username)) { error("Something serious is wrong with the database"); } set_moodle_cookie($USER->username); - $USER->loggedin = true; - $USER->site = $CFG->wwwroot; - if ( ! empty($SESSION->wantsurl) ) { // Send them where they were going $goto = $SESSION->wantsurl; unset($SESSION->wantsurl); diff --git a/login/forgot_password.php b/login/forgot_password.php index 910abc50324..1782080d114 100644 --- a/login/forgot_password.php +++ b/login/forgot_password.php @@ -9,7 +9,7 @@ update_login_count(); - $user = get_user_info_from_db("username", "$s"); + $user = get_complete_user_data("username", "$s"); if (!empty($user)) { if ($user->secret == $p) { // They have provided the secret key to get in @@ -42,7 +42,7 @@ if (count((array)$err) == 0) { - if (!$user = get_user_info_from_db("email", $frm->email)) { + if (!$user = get_complete_user_data("email", $frm->email)) { error("No such user with this address: $frm->email"); } diff --git a/mod/attendance/view.php b/mod/attendance/view.php index f22c187a896..4e03aad93e2 100644 --- a/mod/attendance/view.php +++ b/mod/attendance/view.php @@ -115,7 +115,7 @@ if (isteacher($course->id)){ $students = attendance_get_course_students($form->course, "u.lastname ASC"); } else { // must be a student - $students[0] = get_user_info_from_db("id", $USER->id); + $students[0] = $USER; } $i=0; $A = get_string("absentshort","attendance"); diff --git a/mod/attendance/viewall.php b/mod/attendance/viewall.php index e0ede0137ab..385417b0c70 100644 --- a/mod/attendance/viewall.php +++ b/mod/attendance/viewall.php @@ -113,7 +113,7 @@ if ($dlsub== "all") { /// generate the attendance rolls for the body of the spreadsheet if (isstudent($course->id) && !isteacher($course->id)) { - $students[0] = get_user_info_from_db("id", $USER->id); + $students[0] = $USER; } else { // must be a teacher $students = attendance_get_course_students($attendance->course, "u.lastname ASC"); } @@ -179,7 +179,7 @@ if ($dlsub== "all") { /// generate the attendance rolls for the body of the spreadsheet if (isstudent($course->id) && !isteacher($course->id)) { - $students[0] = get_user_info_from_db("id", $USER->id); + $students[0] = $USER; } else { // must be a teacher $students = attendance_get_course_students($attendance->course, "u.lastname ASC"); } @@ -388,7 +388,7 @@ while (($multipage || $onepage) && (!$endonepage)) { if (isstudent($course->id) && !isteacher($course->id)) { - $students[0] = get_user_info_from_db("id", $USER->id); + $students[0] = $USER; } else { // must be a teacher $students = attendance_get_course_students($attendance->course, "u.lastname ASC"); } diff --git a/mod/attendance/viewweek.php b/mod/attendance/viewweek.php index 79c97392989..ed51b553655 100644 --- a/mod/attendance/viewweek.php +++ b/mod/attendance/viewweek.php @@ -114,7 +114,7 @@ if ($dlsub== "all") { /// generate the attendance rolls for the body of the spreadsheet if (isstudent($course->id)) { - $students[0] = get_user_info_from_db("id", $USER->id); + $students[0] = $USER; } else { // must be a teacher $students = attendance_get_course_students($attendance->course, "u.lastname ASC"); } diff --git a/mod/scorm/api.php b/mod/scorm/api.php index 7117ee70aae..a68e3b95a2a 100644 --- a/mod/scorm/api.php +++ b/mod/scorm/api.php @@ -36,7 +36,7 @@ if (empty($userid) || !isteacher($course->id)) { $user = $USER; } else { - $user = get_user_info_from_db('id', $userid); + $user = get_complete_user_data('id', $userid); } ?>