Overview

Packages

  • awl
    • caldav-client-v2
    • RRule
  • davical
    • authentication
      • drivers
    • caldav
    • DAViCalSession
    • DAVTicket
    • external-bind
    • feed
    • HTTPAuthSession
    • iSchedule
    • iSchedule-POST
    • logging
    • metrics
    • Principal
    • propfind
    • PublicSession
    • Request
    • Resource
    • tzservice
  • None

Classes

  • AtomEntry
  • AtomFeed
  • AtomXHTMLContent
  • CalDAVClient
  • CalDAVRequest
  • CalendarInfo
  • CheckResult
  • DAViCalSession
  • DAVPrincipal
  • DAVResource
  • DAVTicket
  • FakeSession
  • HTTPAuthSession
  • imapPamDriver
  • iSchedule
  • ldapDriver
  • Principal
  • PublicSession
  • pwauthPamDriver
  • RepeatRule
  • RepeatRuleDateRange
  • RepeatRuleDateTime
  • RepeatRuleTimeZone
  • Rfc5545Duration
  • rimapPamDriver
  • setupFakeSession
  • squidPamDriver
  • Tools
  • VCard
  • VTimezone
  • WritableCollection

Functions

  • access_ticket_browser
  • add_failure
  • add_proxy_response
  • array_values_mapping
  • auth_functions_deprecated
  • AuthExternalAWL
  • binding_row_editor
  • bindings_to_other_browser
  • bindings_to_us_browser
  • bits_to_privilege
  • build_dependencies_table
  • build_privileges_html
  • build_site_statistics
  • BuildSqlFilter
  • caldav_get_feed
  • calquery_apply_filter
  • cardquery_apply_filter
  • catch_setup_errors
  • check_awl_version
  • check_calendar
  • check_curl
  • check_database_connection
  • check_datetime
  • check_davical_version
  • check_for_expansion
  • check_gettext
  • check_iconv
  • check_ldap
  • check_magic_quotes_gpc
  • check_magic_quotes_runtime
  • check_pdo
  • check_pdo_pgsql
  • check_pgsql
  • check_real_php
  • check_schema_version
  • check_string
  • check_suhosin_server_strip
  • check_xml
  • checkiSchedule
  • collection_privilege_format_function
  • component_to_xml
  • confirm_delete_bind_in
  • confirm_delete_binding
  • confirm_delete_collection
  • confirm_delete_principal
  • confirm_delete_ticket
  • ConstructURL
  • controlRequestContainer
  • create_external
  • CreateDefaultRelationships
  • CreateHomeCalendar
  • CreateHomeCollections
  • DateToISODate
  • DeconstructURL
  • delete_collection
  • deliverItipCancel
  • display_status
  • do_error
  • do_scheduling_for_delete
  • do_scheduling_reply
  • do_scheduling_requests
  • doImipMessage
  • doItipAttendeeReply
  • doItipOrganizerCancel
  • early_catch_fatal_error
  • early_exception_handler
  • edit_binding_row
  • edit_grant_row_collection
  • edit_grant_row_principal
  • edit_group_row
  • edit_ticket_row
  • errorResponse
  • expand_event_instances
  • expand_properties
  • expand_timezone_onsets
  • export_iCalendar
  • fetch_external
  • fix_unique_member
  • generateKeys
  • get_address_properties
  • get_collection_contents
  • get_freebusy
  • get_href_containers
  • get_phpinfo
  • getComponentRange
  • GetItip
  • getPrincipalByID
  • getStaticLdap
  • getStatusMessage
  • GetTZID
  • getUserByEMail
  • getUserByID
  • getUserByName
  • getVCalendarRange
  • grant_row_editor
  • group_members_browser
  • group_memberships_browser
  • group_row_editor
  • handle_cancel_request
  • handle_freebusy_request
  • handle_schedule_reply
  • handle_schedule_request
  • handle_subaction
  • hyperlink
  • i18n
  • IMAP_PAM_check
  • import_addressbook_collection
  • import_calendar_collection
  • import_collection
  • ischedule_cancel
  • ischedule_freebusy_request
  • ischedule_get
  • ischedule_request
  • ISODateToHTTPDate
  • late_catch_fatal_error
  • LDAP_check
  • local_session_sql
  • log_caldav_action
  • log_setup_error
  • logRequestHeaders
  • make_help_link
  • obfuscated_event
  • olson_from_vtimezone
  • principal_collection_browser
  • principal_editor
  • principal_grants_browser
  • principal_privilege_format_function
  • print_metric
  • privilege_to_bits
  • privileges_to_XML
  • process_ace
  • processItipCancel
  • property_response
  • public_events_only
  • PWAUTH_PAM_check
  • rdate_expand
  • RIMAP_check
  • rollback
  • rollback_on_error
  • rrule_expand
  • send_dav_header
  • send_page_header
  • simple_write_resource
  • SqlFilterCardDAV
  • SqlFilterFragment
  • SQUID_PAM_check
  • SRVFormat
  • SRVOk
  • sync_LDAP
  • sync_LDAP_groups
  • sync_user_from_LDAP
  • ticket_row_editor
  • unicodeToUtf8
  • update_external
  • UpdateCollectionTimezones
  • UpdateUserFromExternal
  • utf8ToUnicode
  • write_alarms
  • write_attendees
  • write_resource
  • Overview
  • Package
  • Class
  • Tree
  • Deprecated
  • Todo
  1:   2:   3:   4:   5:   6:   7:   8:   9:  10:  11:  12:  13:  14:  15:  16:  17:  18:  19:  20:  21:  22:  23:  24:  25:  26:  27:  28:  29:  30:  31:  32:  33:  34:  35:  36:  37:  38:  39:  40:  41:  42:  43:  44:  45:  46:  47:  48:  49:  50:  51:  52:  53:  54:  55:  56:  57:  58:  59:  60:  61:  62:  63:  64:  65:  66:  67:  68:  69:  70:  71:  72:  73:  74:  75:  76:  77:  78:  79:  80:  81:  82:  83:  84:  85:  86:  87:  88:  89:  90:  91:  92:  93:  94:  95:  96:  97:  98:  99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 153: 154: 155: 156: 157: 158: 159: 160: 161: 162: 163: 164: 165: 166: 167: 168: 169: 170: 171: 172: 173: 174: 175: 176: 177: 178: 179: 180: 181: 182: 183: 184: 185: 186: 187: 188: 189: 190: 191: 192: 193: 194: 195: 196: 197: 198: 199: 200: 201: 202: 203: 204: 205: 206: 207: 208: 209: 210: 211: 212: 213: 214: 215: 216: 217: 218: 219: 220: 221: 222: 223: 224: 225: 226: 227: 228: 229: 230: 231: 232: 233: 234: 235: 236: 237: 238: 239: 240: 241: 242: 243: 244: 245: 246: 247: 248: 249: 250: 251: 252: 253: 254: 255: 256: 257: 258: 259: 260: 261: 262: 263: 264: 265: 266: 267: 268: 269: 270: 271: 272: 273: 274: 275: 276: 277: 278: 279: 280: 281: 282: 283: 
<?php
/**
* iScheduling POST handle remote iSchedule requests
*
* @package   davical
* @subpackage   iSchedule-POST
* @author    Rob Ostensen <rob@boxacle.net>
* @copyright Rob Ostensen
* @license   http://gnu.org/copyleft/gpl.html GNU GPL v3 or later
*/

require_once('iSchedule.php');
require_once('vComponent.php');
require_once('vCalendar.php');
require_once('WritableCollection.php');
include_once('freebusy-functions.php');


class FakeSession {
  function __construct($principal) {
    // Assign each field in the selected record to the object
    foreach( $principal AS $k => $v ) {
      $this->{$k} = $v;
    }
    $this->username = $principal->username();
    $this->user_no  = $principal->user_no();
    $this->principal_id = $principal->principal_id();
    $this->email = $principal->email();
    $this->dav_name = $principal->dav_name();
    $this->principal = $principal;

    $this->logged_in = true;

  }

  function AllowedTo($do_something) {
    return true;
  }
}

$d = new iSchedule ();
if ( $d->validateRequest ( ) ) {
  $ical = new vCalendar( $request->raw_post );
  $attendee = Array ();
  $addresses = Array ();
  $attendees = $ical->GetAttendees();
  foreach( $attendees AS $v ) {
    $email = preg_replace( '/^mailto:/i', '', $v->Value() );
    $addresses[] = $email;
  }
  $organizer = $ical->GetOrganizer();
  $addresses[] =  preg_replace( '/^mailto:/i', '', $organizer->Value() );
  $recipients = Array ();
  $attendees_ok = Array ();
  $attendees_fail = Array ();
  if ( strpos ( $_SERVER['HTTP_RECIPIENT'], ',' ) === false ) { // single recipient
    $recipients[] = $_SERVER['HTTP_RECIPIENT'];
  }
  else {
    $rcpt = explode ( ',', $_SERVER['HTTP_RECIPIENT'] );
    foreach ( $rcpt as $k => $v ) {
      $recipients[$k] = preg_replace( '/^mailto:/i', '', trim ( $v ) );
    }
  }
  if ( ! in_array ( preg_replace( '/^mailto:/i', '', $_SERVER['HTTP_ORIGINATOR'] ), $addresses ) ) { // should this be case sensitive?
    $request->DoResponse( 412, translate('sender must be organizer or attendee of event') );
  }
  foreach ( $recipients as $v ) {
    if ( ! in_array ( preg_replace( '/^mailto:/i', '', $v ), $addresses ) ) { // should this be case sensitive?
      dbg_error_log('ischedule','recipient missing from event ' . $v );
      $reply->XMLResponse( 403, translate('recipient must be organizer or attendee of event') . $v );
      continue;
    }
    $email = preg_replace( '/^mailto:/', '', $v );
    dbg_error_log('ischedule','recipient ' . $v );
    $schedule_target = new Principal('email',$email);
    if ( $schedule_target == false ){
      array_push ( $attendees_fail, $schedule_target );
      continue;
    }
    array_push ( $attendees_ok, $schedule_target );
    // TODO: add originator addressbook and existing event lookup as whitelist
  }
  $method =  $ical->GetPValue('METHOD');
  $content_type = explode ( ';', $_SERVER['CONTENT_TYPE'] );
  if ( $content_type[0] != 'text/calendar' )
    $reply->XMLResponse( 406, 'content must be text/calendar' );
  $content_parts = Array ();
  foreach ( $content_type as $v ) {
    list ( $a, $b ) = explode ( '=', trim ( $v ), 2 );
    $content_parts[strtolower($a)] = strtoupper($b);
  }
  if ( isset ( $content_parts['method'] ) )
    $method = $content_parts['method']; // override method from icalendar
  switch ( $method )
  {
    case 'REQUEST':
      if ( $content_parts['component'] == 'VFREEBUSY' ) {
        ischedule_freebusy_request ( $ical, $attendees_ok, $attendees_fail );
      }
      if ( $content_parts['component'] == 'VEVENT' ) {
        ischedule_request ( $ical, $attendees_ok, $attendees_fail );
        // scheduling event request
      }
      if ( $content_parts['component'] == 'VTODO' ) {
        ischedule_request ( $ical, $attendees_ok, $attendees_fail );
        // scheduling todo request
      }
      if ( $content_parts['component'] == 'VJOURNAL' ) {
        // scheduling journal request, not sure how to handle this or if it will ever by used
      }
      break;
    case 'REPLY':
        ischedule_request ( $ical, $attendees_ok, $attendees_fail );
      break;
    case 'ADD':
        ischedule_request ( $ical, $attendees_ok, $attendees_fail );
      break;
    case 'CANCEL':
        ischedule_request ( $ical, $attendees_ok, $attendees_fail );
      break;
    case 'PUBLISH':
      break;
    case 'REFRESH':
      break;
    case 'COUNTER':
      break;
    case 'DECLINECOUNTER':
      break;
    default:
      dbg_error_log('ischedule','invalid request' );
      $request->DoResponse( 400, translate('invalid request') );
  }
}
else {
  dbg_error_log('ischedule','invalid request' );
  $request->DoResponse( 400, translate('invalid request') );
}

function ischedule_freebusy_request( $ic, $attendees, $attendees_fail) {
  global $c, $session, $request;
  $reply = new XMLDocument( array( "urn:ietf:params:xml:ns:ischedule" => "I" ) );
  $icalAttendees = $ic->GetAttendees();
  $responses = array();
  $ical = $ic->GetComponents('VFREEBUSY');
  $ical = $ical[0];
  $fbq_start = $ical->GetPValue('DTSTART');
  $fbq_end   = $ical->GetPValue('DTEND');
  if ( ! ( isset($fbq_start) || isset($fbq_end) ) ) {
    $request->DoResponse( 400, 'All valid freebusy requests MUST contain a DTSTART and a DTEND' );
  }

  $range_start = new RepeatRuleDateTime($fbq_start);
  $range_end   = new RepeatRuleDateTime($fbq_end);

  foreach( $attendees AS $k => $attendee ) {
    $response = $reply->NewXMLElement("response", false, false, 'urn:ietf:params:xml:ns:ischedule');
    $fb = get_freebusy( '^'.$attendee->dav_name, $range_start, $range_end );

    $fb->AddProperty( 'UID',       $ical->GetPValue('UID') );
    $fb->SetProperties( $ical->GetProperties('ORGANIZER'), 'ORGANIZER');
    foreach ( $ical->GetProperties('ATTENDEE') as $at ) {
      if ( $at->Value() == 'mailto:' . $attendee->email )
        $fb->AddProperty( $at );
    }

    $vcal = new vCalendar( array('METHOD' => 'REPLY') );
    $vcal->AddComponent( $fb );

    $response = $reply->NewXMLElement( "response", false, false, 'urn:ietf:params:xml:ns:ischedule' );
    $response->NewElement( "recipient", 'mailto:'.$attendee->email, false, 'urn:ietf:params:xml:ns:ischedule' );
    $response->NewElement( "request-status", "2.0;Success", false, 'urn:ietf:params:xml:ns:ischedule' );
    $response->NewElement( "calendar-data", $vcal->Render(), false, 'urn:ietf:params:xml:ns:ischedule' );

    $responses[] = $response;
  }

  foreach ( $attendees_fail AS $k => $attendee ) {
    $XMLresponse = $reply->NewXMLElement("response", false, false, 'urn:ietf:params:xml:ns:ischedule');
    $XMLresponse->NewElement( "recipient", $reply->href('mailto:'.$attendee));
    $XMLresponse->NewElement( "request-status",'5.3;cannot schedule this user, unknown or access denied');
    $responses[] = $XMLresponse;
  }
  $response = $reply->NewXMLElement( "schedule-response", $responses, $reply->GetXmlNsArray(), 'urn:ietf:params:xml:ns:ischedule' );
  $request->XMLResponse( 200, $response );
}

function ischedule_request( $ic, $attendees, $attendees_fail ) {
  global $c, $session, $request;
  $oldSession = $session;
  $reply = new XMLDocument( array( "urn:ietf:params:xml:ns:ischedule" => "I" ) );
  $responses = array();
  $ical = $ic->GetComponents('VEVENT');
  $ical = $ical[0];

  foreach ( $attendees AS $k => $attendee ) {
    $XMLresponse = $reply->NewXMLElement("response", false, false, 'urn:ietf:params:xml:ns:ischedule');
    dbg_error_log('ischedule','scheduling event for ' .$attendee->email);
    $schedule_target = new Principal('email',$attendee->email);
    $response = '3.7'; // Attendee was not found on server.
    if ( $schedule_target->Exists() ) {
      $session = new FakeSession($schedule_target);
      $attendee_calendar = new WritableCollection(array('path' => $schedule_target->internal_url('schedule-default-calendar')));
      if ( !$attendee_calendar->Exists() ) {
        dbg_error_log('ERROR','Default calendar at "%s" does not exist for user "%s"',
        $attendee_calendar->dav_name(), $schedule_target->username());
        $response = '5.3;cannot schedule this user, unknown or access denied'; // No scheduling support for user
      }
      else {
        $attendee_inbox = new WritableCollection(array('path' => $schedule_target->internal_url('schedule-inbox')));
        if ( ! $attendee_inbox->HavePrivilegeTo('schedule-deliver-invite') ) {
          $response = '3.8;denied'; //  No authority to deliver invitations to user.
        }
        else if ( $attendee_inbox->WriteCalendarMember($ic, false) !== false ) {
          $response = '2.0;delivered'; // Scheduling invitation delivered successfully
        }
      }
      $session = $oldSession;
    }
    dbg_error_log( 'ischedule', 'Status for attendee <%s> set to "%s"', $attendee->email, $response );
    $XMLresponse->NewElement("recipient", 'mailto:'.$attendee->email, false, 'urn:ietf:params:xml:ns:ischedule' );
    $XMLresponse->NewElement("request-status", $response, false, 'urn:ietf:params:xml:ns:ischedule' );
    $responses[] = $XMLresponse;
  }

  foreach ( $attendees_fail AS $k => $attendee ) {
    $XMLresponse = $reply->NewXMLElement("response", false, false, 'urn:ietf:params:xml:ns:ischedule');
    $XMLresponse->NewElement("recipient", 'mailto:'.$attendee->email, false, 'urn:ietf:params:xml:ns:ischedule' );
    $XMLresponse->NewElement("request-status", '5.3;cannot schedule this user, unknown or access denied', false, 'urn:ietf:params:xml:ns:ischedule' );
    $responses[] = $XMLresponse;
  }

  $response = $reply->NewXMLElement( "schedule-response", $responses, $reply->GetXmlNsArray(), 'urn:ietf:params:xml:ns:ischedule' );
  $request->XMLResponse( 200, $response );
}

function ischedule_cancel( $ic, $attendees, $attendees_fail ) {
  global $c, $session, $request;
  $reply = new XMLDocument( array("DAV:" => "", "urn:ietf:params:xml:ns:caldav" => "C", "urn:ietf:params:xml:ns:ischedule" => "I" ) );
  $responses = array();
  $ical = $ic->GetComponents('VEVENT');
  $ical = $ical[0];

  foreach ( $attendees AS $k => $attendee ) {
    $XMLresponse = $reply->NewXMLElement("response", false, false, 'urn:ietf:params:xml:ns:ischedule');
    dbg_error_log('ischedule','scheduling event for ' .$attendee->email);
    $schedule_target = new Principal('email',$attendee->email);
    $response = '3.7'; // Attendee was not found on server.
    if ( $schedule_target->Exists() ) {
      $attendee_calendar = new WritableCollection(array('path' => $schedule_target->internal_url('schedule-default-calendar')));
      if ( !$attendee_calendar->Exists() ) {
        dbg_error_log('ERROR','Default calendar at "%s" does not exist for user "%s"',
        $attendee_calendar->dav_name(), $schedule_target->username());
        $response = '5.3;cannot schedule this user, unknown or access denied'; // No scheduling support for user
      }
      else {
        $attendee_inbox = new WritableCollection(array('path' => $schedule_target->internal_url('schedule-inbox')));
        if ( ! $attendee_inbox->HavePrivilegeTo('schedule-deliver-invite') ) {
          $response = '3.8;denied'; //  No authority to deliver invitations to user.
        }
        else if ( $attendee_inbox->WriteCalendarMember($ic, false) !== false ) {
          $response = '2.0;delivered'; // Scheduling invitation delivered successfully
        }
      }
    }
    dbg_error_log( 'PUT', 'Status for attendee <%s> set to "%s"', $attendee->email, $response );
    $XMLresponse->NewElement("recipient", $reply->href('mailto:'.$attendee->email), false, 'urn:ietf:params:xml:ns:ischedule' );
    $XMLresponse->NewElement("request-status", $response, false, 'urn:ietf:params:xml:ns:ischedule' );
    $responses[] = $XMLresponse;
  }

  foreach ( $attendees_fail AS $k => $attendee ) {
    $XMLresponse = $reply->NewXMLElement("response", false, false, 'urn:ietf:params:xml:ns:ischedule');
    $XMLresponse->NewElement("recipient", $reply->href('mailto:'.$attendee->email), false, 'urn:ietf:params:xml:ns:ischedule' );
    $XMLresponse->NewElement("request-status", '5.3;cannot schedule this user, unknown or access denied', false, 'urn:ietf:params:xml:ns:ischedule' );
    $responses[] = $XMLresponse;
  }

  $response = $reply->NewXMLElement( "schedule-response", $responses, $reply->GetXmlNsArray(), 'urn:ietf:params:xml:ns:ischedule' );
  $request->XMLResponse( 200, $response );
}

DAViCal API documentation generated by ApiGen