From 65d7932ca3f268445f2f0c6eab457189d3af4478 Mon Sep 17 00:00:00 2001 From: Charles Fulton Date: Thu, 3 Jul 2014 11:08:16 -0700 Subject: [PATCH] MDL-46247 auth: Add new language for unauthorised external user --- lang/en/moodle.php | 1 + lib/authlib.php | 2 ++ lib/moodlelib.php | 31 +++++++++++++++---------------- login/index.php | 10 +++++++--- 4 files changed, 25 insertions(+), 19 deletions(-) diff --git a/lang/en/moodle.php b/lang/en/moodle.php index 2b46997636f..c74e820ee07 100644 --- a/lang/en/moodle.php +++ b/lang/en/moodle.php @@ -1848,6 +1848,7 @@ $string['trackforumsyes'] = 'Yes: highlight new posts for me'; $string['trysearching'] = 'Try searching instead.'; $string['turneditingoff'] = 'Turn editing off'; $string['turneditingon'] = 'Turn editing on'; +$string['unauthorisedlogin'] = 'The user account "{$a}" is not available on this site'; $string['undecided'] = 'Undecided'; $string['unfinished'] = 'Unfinished'; $string['unknowncategory'] = 'Unknown category'; diff --git a/lib/authlib.php b/lib/authlib.php index 6740fe22831..50470a8dc0d 100644 --- a/lib/authlib.php +++ b/lib/authlib.php @@ -76,6 +76,8 @@ define('AUTH_LOGIN_FAILED', 3); /** Can not login because user is locked out. */ define('AUTH_LOGIN_LOCKOUT', 4); +/** Can not login becauser user is not authorised. */ +define('AUTH_LOGIN_UNAUTHORISED', 5); /** * Abstract authentication plugin. diff --git a/lib/moodlelib.php b/lib/moodlelib.php index eef42c9ba09..309efeb7641 100644 --- a/lib/moodlelib.php +++ b/lib/moodlelib.php @@ -4426,20 +4426,6 @@ function authenticate_user_login($username, $password, $ignorelockout=false, &$f return false; } - // Do not try to authenticate non-existent accounts when user creation is disabled. - if (!empty($CFG->authpreventaccountcreation)) { - $failurereason = AUTH_LOGIN_NOUSER; - - // Trigger login failed event. - $event = \core\event\user_login_failed::create(array('other' => array('username' => $username, - 'reason' => $failurereason))); - $event->trigger(); - - error_log('[client '.getremoteaddr()."] $CFG->wwwroot Unknown user, can not create new accounts: $username ". - $_SERVER['HTTP_USER_AGENT']); - return false; - } - // User does not exist. $auths = $authsenabled; $user = new stdClass(); @@ -4492,8 +4478,21 @@ function authenticate_user_login($username, $password, $ignorelockout=false, &$f $user = update_user_record_by_id($user->id); } } else { - // Create account, we verified above that user creation is allowed. - $user = create_user_record($username, $password, $auth); + // The user is authenticated but user creation may be disabled. + if (!empty($CFG->authpreventaccountcreation)) { + $failurereason = AUTH_LOGIN_UNAUTHORISED; + + // Trigger login failed event. + $event = \core\event\user_login_failed::create(array('other' => array('username' => $username, + 'reason' => $failurereason))); + $event->trigger(); + + error_log('[client '.getremoteaddr()."] $CFG->wwwroot Unknown user, can not create new accounts: $username ". + $_SERVER['HTTP_USER_AGENT']); + return false; + } else { + $user = create_user_record($username, $password, $auth); + } } $authplugin->sync_roles($user); diff --git a/login/index.php b/login/index.php index a4e29fc9456..587eb0efec4 100644 --- a/login/index.php +++ b/login/index.php @@ -137,7 +137,7 @@ if ($frm and isset($frm->username)) { // Login WITH $frm = false; } else { if (empty($errormsg)) { - $user = authenticate_user_login($frm->username, $frm->password); + $user = authenticate_user_login($frm->username, $frm->password, false, $errorcode); } } @@ -233,8 +233,12 @@ if ($frm and isset($frm->username)) { // Login WITH } else { if (empty($errormsg)) { - $errormsg = get_string("invalidlogin"); - $errorcode = 3; + if ($errorcode == AUTH_LOGIN_UNAUTHORISED) { + $errormsg = get_string("unauthorisedlogin", "", $frm->username); + } else { + $errormsg = get_string("invalidlogin"); + $errorcode = 3; + } } } }