Overview

Packages

  • awl
    • caldav-client-v2
    • RRule
  • davical
    • authentication
      • drivers
    • caldav
    • DAViCalSession
    • DAVTicket
    • external-bind
    • feed
    • HTTPAuthSession
    • iSchedule
    • iSchedule-POST
    • logging
    • metrics
    • Principal
    • propfind
    • PublicSession
    • Request
    • Resource
    • tzservice
  • None

Classes

  • AtomEntry
  • AtomFeed
  • AtomXHTMLContent
  • CalDAVClient
  • CalDAVRequest
  • CalendarInfo
  • CheckResult
  • DAViCalSession
  • DAVPrincipal
  • DAVResource
  • DAVTicket
  • FakeSession
  • HTTPAuthSession
  • imapPamDriver
  • iSchedule
  • ldapDriver
  • Principal
  • PublicSession
  • pwauthPamDriver
  • RepeatRule
  • RepeatRuleDateRange
  • RepeatRuleDateTime
  • RepeatRuleTimeZone
  • Rfc5545Duration
  • rimapPamDriver
  • setupFakeSession
  • squidPamDriver
  • Tools
  • VCard
  • VTimezone
  • WritableCollection

Functions

  • access_ticket_browser
  • add_failure
  • add_proxy_response
  • array_values_mapping
  • auth_functions_deprecated
  • AuthExternalAWL
  • binding_row_editor
  • bindings_to_other_browser
  • bindings_to_us_browser
  • bits_to_privilege
  • build_dependencies_table
  • build_privileges_html
  • build_site_statistics
  • BuildSqlFilter
  • caldav_get_feed
  • calquery_apply_filter
  • cardquery_apply_filter
  • catch_setup_errors
  • check_awl_version
  • check_calendar
  • check_curl
  • check_database_connection
  • check_datetime
  • check_davical_version
  • check_for_expansion
  • check_gettext
  • check_iconv
  • check_ldap
  • check_magic_quotes_gpc
  • check_magic_quotes_runtime
  • check_pdo
  • check_pdo_pgsql
  • check_pgsql
  • check_real_php
  • check_schema_version
  • check_string
  • check_suhosin_server_strip
  • check_xml
  • checkiSchedule
  • collection_privilege_format_function
  • component_to_xml
  • confirm_delete_bind_in
  • confirm_delete_binding
  • confirm_delete_collection
  • confirm_delete_principal
  • confirm_delete_ticket
  • ConstructURL
  • controlRequestContainer
  • create_external
  • CreateDefaultRelationships
  • CreateHomeCalendar
  • CreateHomeCollections
  • DateToISODate
  • DeconstructURL
  • delete_collection
  • deliverItipCancel
  • display_status
  • do_error
  • do_scheduling_for_delete
  • do_scheduling_reply
  • do_scheduling_requests
  • doImipMessage
  • doItipAttendeeReply
  • doItipOrganizerCancel
  • early_catch_fatal_error
  • early_exception_handler
  • edit_binding_row
  • edit_grant_row_collection
  • edit_grant_row_principal
  • edit_group_row
  • edit_ticket_row
  • errorResponse
  • expand_event_instances
  • expand_properties
  • expand_timezone_onsets
  • export_iCalendar
  • fetch_external
  • fix_unique_member
  • generateKeys
  • get_address_properties
  • get_collection_contents
  • get_freebusy
  • get_href_containers
  • get_phpinfo
  • getComponentRange
  • GetItip
  • getPrincipalByID
  • getStaticLdap
  • getStatusMessage
  • GetTZID
  • getUserByEMail
  • getUserByID
  • getUserByName
  • getVCalendarRange
  • grant_row_editor
  • group_members_browser
  • group_memberships_browser
  • group_row_editor
  • handle_cancel_request
  • handle_freebusy_request
  • handle_schedule_reply
  • handle_schedule_request
  • handle_subaction
  • hyperlink
  • i18n
  • IMAP_PAM_check
  • import_addressbook_collection
  • import_calendar_collection
  • import_collection
  • ischedule_cancel
  • ischedule_freebusy_request
  • ischedule_get
  • ischedule_request
  • ISODateToHTTPDate
  • late_catch_fatal_error
  • LDAP_check
  • local_session_sql
  • log_caldav_action
  • log_setup_error
  • logRequestHeaders
  • make_help_link
  • obfuscated_event
  • olson_from_vtimezone
  • principal_collection_browser
  • principal_editor
  • principal_grants_browser
  • principal_privilege_format_function
  • print_metric
  • privilege_to_bits
  • privileges_to_XML
  • process_ace
  • processItipCancel
  • property_response
  • public_events_only
  • PWAUTH_PAM_check
  • rdate_expand
  • RIMAP_check
  • rollback
  • rollback_on_error
  • rrule_expand
  • send_dav_header
  • send_page_header
  • simple_write_resource
  • SqlFilterCardDAV
  • SqlFilterFragment
  • SQUID_PAM_check
  • SRVFormat
  • SRVOk
  • sync_LDAP
  • sync_LDAP_groups
  • sync_user_from_LDAP
  • ticket_row_editor
  • unicodeToUtf8
  • update_external
  • UpdateCollectionTimezones
  • UpdateUserFromExternal
  • utf8ToUnicode
  • write_alarms
  • write_attendees
  • write_resource
  • Overview
  • Package
  • Class
  • Tree
  • Deprecated
  • Todo
  1:   2:   3:   4:   5:   6:   7:   8:   9:  10:  11:  12:  13:  14:  15:  16:  17:  18:  19:  20:  21:  22:  23:  24:  25:  26:  27:  28:  29:  30:  31:  32:  33:  34:  35:  36:  37:  38:  39:  40:  41:  42:  43:  44:  45:  46:  47:  48:  49:  50:  51:  52:  53:  54:  55:  56:  57:  58:  59:  60:  61:  62:  63:  64:  65:  66:  67:  68:  69:  70:  71:  72:  73:  74:  75:  76:  77:  78:  79:  80:  81:  82:  83:  84:  85:  86:  87:  88:  89:  90:  91:  92:  93:  94:  95:  96:  97:  98:  99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 
<?php
/**
 * Authentication against PAM with pwauth
 *
 * @package   davical
 * @category  Technical
 * @subpackage authentication/drivers
 * @author    Eric Seigne <eric.seigne@ryxeo.com>,
 *            Michael B. Trausch <mike@trausch.us>,
 *            Andrew McMillan <andrew@mcmillan.net.nz>
 * @copyright Eric Seigne
 * @license   http://gnu.org/copyleft/gpl.html GNU GPL v2 or later
 *
 * Based on drivers_squid_pam.php
 */

require_once("auth-functions.php");

/**
 * Plugin to authenticate against PAM with pwauth
 */
class pwauthPamDriver
{
  /**#@+
   * @access private
   */

  /**#@-*/


  /**
   * The constructor
   *
   * @param string $config path where pwauth is
   */
  function __construct($config)
  {
    global $c;
    if(!file_exists($config)) {
      $c->messages[] = sprintf(i18n('drivers_pwauth_pam : Unable to find %s file'), $config);
      $this->valid=false;
      return ;
    }
  }
}


/**
 * Check the username / password against the PAM system
 */
function PWAUTH_PAM_check($username, $password) {
  global $c;
  $program = $c->authenticate_hook['config']['path'];
  $email_base = $c->authenticate_hook['config']['email_base'];

  $pipe = popen(escapeshellarg($program), 'w');
  $authinfo = sprintf("%s\n%s\n", $username, $password);
  $written = fwrite($pipe, $authinfo);
  dbg_error_log('PAM', 'Bytes written: %d of %d', $written, strlen($authinfo));
  $return_status = pclose($pipe);

  switch($return_status) {
    case 0:
      // STATUS_OK: Authentication succeeded.
      dbg_error_log('PAM', 'User %s successfully authenticated', $username);
      $principal = new Principal('username',$username);
      if ( !$principal->Exists() ) {
        dbg_error_log('PAM', 'User %s does not exist in local db, creating', $username);
        $pwent = posix_getpwnam($username);
        $gecos = explode(',',$pwent['gecos']);
        $fullname = $gecos[0];
        $principal->Create( array(
                              'username' => $username,
                              'user_active' => 't',
                              'email' => sprintf('%s@%s', $username, $email_base),
                              'fullname' => $fullname
                          ));
        if ( ! $principal->Exists() ) {
          dbg_error_log( "PAM", "Unable to create local principal for '%s'", $username );
          return false;
        }
        CreateHomeCollections($username, $c->default_timezone);
    CreateDefaultRelationships($username);
      }
      return $principal;
      break;

    /*
     * Note that for system configurations using PAM instead of
     * reading the password database directly, if PAM is unable to
     * read the password database, pwauth will return status 1.
     */
    case 1:
    case 2:
      // (1) STATUS_UNKNOWN: Invalid username or password.
      // (2) STATUS_INVALID: Invalid password.
      dbg_error_log('PAM', 'Invalid username or password (username: %s)', $username);
      break;

    case 3:
      // STATUS_BLOCKED: UID for username is < pwauth's MIN_UNIX_UID
      dbg_error_log('PAM', 'UID for username %s is < pwauth MIN_UNIX_UID', $username);
      break;

    case 4:
      // STATUS_EXPIRED: The user account has expired.
      dbg_error_log('PAM', 'The account for %s has expired', $username);
      break;

    case 5:
      // STATUS_PW_EXPIRED: The user account's password has expired.
      dbg_error_log('PAM', 'The account password for user %s has expired', $username);
      break;

    case 6:
      // STATUS_NOLOGIN: Logins to the system are administratively disabled.
      dbg_error_log('PAM', 'Logins administratively disabled (%s)', $username);
      break;

    case 7:
      // STATUS_MANYFAILS: Too many login failures for user account.
      dbg_error_log('PAM', 'Login rejected for %s, too many failures', $username);
      break;

    case 50:
      // STATUS_INT_USER: Configuration error, Web server cannot use pwauth
      dbg_error_log('PAM', 'config error: see pwauth man page (%s)', 'STATUS_INT_USER');
      break;

    case 51:
      // STATUS_INT_ARGS: pwauth received no username/passwd to check
      dbg_error_log('PAM', 'error: pwauth received no username/password');
      break;

    case 52:
      // STATUS_INT_ERR: unknown error
      dbg_error_log('PAM', 'error: see pwauth man page (%s)', 'STATUS_INT_ERR');
      break;

    case 53:
      // STATUS_INT_NOROOT: pwauth could not read the password database
      dbg_error_log('PAM', 'config error: cannot read password database (%s)', 'STATUS_INT_NOROOT');
      break;

    default:
      // Unknown error code.
      dbg_error_log('PAM', 'An unknown error (%d) has occurred', $return_status);
  }

  return(FALSE);
}
DAViCal API documentation generated by ApiGen