MDL-8973 auth hooks final cleanup
This commit is contained in:
+1
-2
@@ -125,8 +125,7 @@ When creating new plugins you can either extend the abstract auth_plugin_base cl
|
||||
auth_plugin_base.
|
||||
|
||||
The new plugin architecture allows creating of more advanced types such as custom SSO
|
||||
without the need to patch login and logout pages (see prelogin_hook() and prelogout_hook()
|
||||
methods in existing plugins).
|
||||
without the need to patch login and logout pages (see *_hook() methods in existing plugins).
|
||||
|
||||
Configuration
|
||||
-----------------
|
||||
|
||||
+6
-1
@@ -220,7 +220,7 @@ class auth_plugin_cas extends auth_plugin_base {
|
||||
return !empty($this->config->changepasswordurl);
|
||||
}
|
||||
|
||||
function prelogin_hook() {
|
||||
function loginpage_hook() {
|
||||
// Load alternative login screens if necessary
|
||||
// TODO: fix the cas login screen
|
||||
return;
|
||||
@@ -230,6 +230,11 @@ class auth_plugin_cas extends auth_plugin_base {
|
||||
}
|
||||
}
|
||||
|
||||
function prelogout_hook() {
|
||||
global $CFG;
|
||||
|
||||
require($CFG->dirroot.'/auth/cas/logout.php');
|
||||
}
|
||||
|
||||
/**
|
||||
* Prints a form for configuring this authentication plugin.
|
||||
|
||||
+6
-2
@@ -1003,8 +1003,12 @@ class auth_plugin_mnet extends auth_plugin_base {
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
function logout() {
|
||||
function prelogout_hook() {
|
||||
global $MNET, $CFG, $USER;
|
||||
if ($USER->auth != 'mnet') {
|
||||
return;
|
||||
}
|
||||
|
||||
require_once $CFG->dirroot.'/mnet/xmlrpc/client.php';
|
||||
|
||||
// If the user is local to this Moodle:
|
||||
@@ -1334,7 +1338,7 @@ class auth_plugin_mnet extends auth_plugin_base {
|
||||
return $accessctrl == 'allow';
|
||||
}
|
||||
|
||||
function prelogout_hook() {
|
||||
function logoutpage_hook() {
|
||||
global $USER, $CFG, $redirect;
|
||||
|
||||
if (!empty($USER->mnethostid) and $USER->mnethostid != $CFG->mnet_localhost_id) {
|
||||
|
||||
@@ -146,7 +146,7 @@ class auth_plugin_shibboleth extends auth_plugin_base {
|
||||
return false;
|
||||
}
|
||||
|
||||
function prelogin_hook() {
|
||||
function loginpage_hook() {
|
||||
global $SESSION, $CFG;
|
||||
|
||||
//TODO: fix the code
|
||||
|
||||
+28
-16
@@ -273,34 +273,46 @@ class auth_plugin_base {
|
||||
}
|
||||
|
||||
/**
|
||||
* Prelogin actions.
|
||||
* Hook for overriding behavior of login page.
|
||||
* This method is called from login/index.php page for all enabled auth plugins.
|
||||
*/
|
||||
function prelogin_hook() {
|
||||
function loginpage_hook() {
|
||||
global $frm; // can be used to override submitted login form
|
||||
global $user; // can be used to replace authenticate_user_login()
|
||||
|
||||
//override if needed
|
||||
}
|
||||
|
||||
/**
|
||||
* Post authentication hook.
|
||||
* This method is called from authenticate_user_login() for all enabled auth plugins.
|
||||
*
|
||||
* @param object $user user object, later used for $USER
|
||||
* @param string $username (with system magic quotes)
|
||||
* @param string $password plain text password (with system magic quotes)
|
||||
*/
|
||||
function user_authenticated_hook($user, $username, $password) {
|
||||
/// TODO: review following code - looks hackish :-( mnet should obsole this, right?
|
||||
/// Log in to a second system if necessary
|
||||
global $CFG;
|
||||
|
||||
if (!empty($CFG->sso)) {
|
||||
include_once($CFG->dirroot .'/sso/'. $CFG->sso .'/lib.php');
|
||||
if (function_exists('sso_user_login')) {
|
||||
if (!sso_user_login($username, $password)) { // Perform the signon process
|
||||
notify('Second sign-on failed');
|
||||
}
|
||||
}
|
||||
}
|
||||
function user_authenticated_hook(&$user, $username, $password) {
|
||||
//override if needed
|
||||
}
|
||||
|
||||
/**
|
||||
* Prelogout actions.
|
||||
* Pre logout hook.
|
||||
* This method is called from require_logout() for all enabled auth plugins,
|
||||
*/
|
||||
function prelogout_hook() {
|
||||
global $USER; // use $USER->auth to find the plugin used for login
|
||||
|
||||
//override if needed
|
||||
}
|
||||
|
||||
/**
|
||||
* Hook for overriding behavior of logout page.
|
||||
* This method is called from login/logout.php page for all enabled auth plugins.
|
||||
*/
|
||||
function logoutpage_hook() {
|
||||
global $USER; // use $USER->auth to find the plugin used for login
|
||||
global $redirect; // can be used to override redirect after logout
|
||||
|
||||
//override if needed
|
||||
}
|
||||
}
|
||||
|
||||
+21
-13
@@ -1828,16 +1828,10 @@ function require_logout() {
|
||||
if (isloggedin()) {
|
||||
add_to_log(SITEID, "user", "logout", "view.php?id=$USER->id&course=".SITEID, $USER->id, 0, $USER->id);
|
||||
|
||||
//TODO: move following 2 ifs into auth plugins - add new logout hook
|
||||
$authsequence = get_enabled_auth_plugins();
|
||||
|
||||
if (in_array('cas', $authsequence) and $USER->auth == 'cas' and !empty($CFG->cas_enabled)) {
|
||||
require($CFG->dirroot.'/auth/cas/logout.php');
|
||||
}
|
||||
|
||||
if (in_array('mnet', $authsequence) and $USER->auth == 'mnet') {
|
||||
$authplugin = get_auth_plugin('mnet');;
|
||||
$authplugin->logout();
|
||||
$authsequence = get_enabled_auth_plugins(); // auths, in sequence
|
||||
foreach($authsequence as $authname) {
|
||||
$authplugin = get_auth_plugin($authname);
|
||||
$authplugin->prelogout_hook();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2591,8 +2585,8 @@ function guest_user() {
|
||||
* Uses auth_ functions from the currently active auth module
|
||||
*
|
||||
* @uses $CFG
|
||||
* @param string $username User's username
|
||||
* @param string $password User's password
|
||||
* @param string $username User's username (with system magic quotes)
|
||||
* @param string $password User's password (with system magic quotes)
|
||||
* @return user|flase A {@link $USER} object or false if error
|
||||
*/
|
||||
function authenticate_user_login($username, $password) {
|
||||
@@ -2648,7 +2642,21 @@ function authenticate_user_login($username, $password) {
|
||||
|
||||
$authplugin->sync_roles($user);
|
||||
|
||||
$authplugin->user_authenticated_hook($user, $username, $password);
|
||||
foreach ($authsenabled as $hau) {
|
||||
$hauth = get_auth_plugin($hau);
|
||||
$hauth->user_authenticated_hook($user, $username, $password);
|
||||
}
|
||||
|
||||
/// Log in to a second system if necessary
|
||||
/// NOTICE: /sso/ will be moved to auth and deprecated soon; use user_authenticated_hook() instead
|
||||
if (!empty($CFG->sso)) {
|
||||
include_once($CFG->dirroot .'/sso/'. $CFG->sso .'/lib.php');
|
||||
if (function_exists('sso_user_login')) {
|
||||
if (!sso_user_login($username, $password)) { // Perform the signon process
|
||||
notify('Second sign-on failed');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return $user;
|
||||
|
||||
|
||||
+1
-1
@@ -58,7 +58,7 @@ $user = false;
|
||||
$authsequence = get_enabled_auth_plugins(true); // auths, in sequence
|
||||
foreach($authsequence as $authname) {
|
||||
$authplugin = get_auth_plugin($authname);
|
||||
$authplugin->prelogin_hook();
|
||||
$authplugin->loginpage_hook();
|
||||
}
|
||||
|
||||
//HTTPS is potentially required in this page
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
$authsequence = get_enabled_auth_plugins(); // auths, in sequence
|
||||
foreach($authsequence as $authname) {
|
||||
$authplugin = get_auth_plugin($authname);
|
||||
$authplugin->prelogout_hook();
|
||||
$authplugin->logoutpage_hook();
|
||||
}
|
||||
|
||||
require_logout();
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
NOTICE:
|
||||
/sso/ will be moved to /auth/ and deprecated; use user_authenticated_hook() instead
|
||||
Reference in New Issue
Block a user