dadasd
This commit is contained in:
@@ -5,12 +5,26 @@ declare(strict_types=1);
|
|||||||
require_once dirname(__DIR__, 3) . '/src/App/bootstrap.php';
|
require_once dirname(__DIR__, 3) . '/src/App/bootstrap.php';
|
||||||
|
|
||||||
use App\ConfigLoader;
|
use App\ConfigLoader;
|
||||||
|
use App\AccountGate;
|
||||||
use App\RegistrationService;
|
use App\RegistrationService;
|
||||||
|
|
||||||
session_start();
|
session_start();
|
||||||
|
|
||||||
$projectRoot = dirname(__DIR__, 3);
|
$projectRoot = dirname(__DIR__, 3);
|
||||||
|
$accountGate = new AccountGate(ConfigLoader::load($projectRoot, 'registration'));
|
||||||
$registration = new RegistrationService($projectRoot, ConfigLoader::load($projectRoot, 'registration'));
|
$registration = new RegistrationService($projectRoot, ConfigLoader::load($projectRoot, 'registration'));
|
||||||
|
|
||||||
|
if (isset($_SESSION['desktop_auth']) && is_array($_SESSION['desktop_auth'])) {
|
||||||
|
$currentAuthUser = is_array($_SESSION['desktop_auth']['user'] ?? null) ? $_SESSION['desktop_auth']['user'] : [];
|
||||||
|
$accountCheck = $accountGate->checkUsername((string) ($currentAuthUser['username'] ?? ''));
|
||||||
|
|
||||||
|
if (!($accountCheck['allowed'] ?? false)) {
|
||||||
|
unset($_SESSION['desktop_auth']);
|
||||||
|
header('Location: /auth/inactive/?message=' . urlencode((string) ($accountCheck['message'] ?? 'Dieses Konto ist noch nicht freigeschaltet.')), true, 302);
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
$currentUser = is_array($_SESSION['desktop_auth']['user'] ?? null) ? $_SESSION['desktop_auth']['user'] : [];
|
$currentUser = is_array($_SESSION['desktop_auth']['user'] ?? null) ? $_SESSION['desktop_auth']['user'] : [];
|
||||||
$currentGroups = array_map(static fn (string $group): string => strtolower(trim($group, '/')), array_values(array_map('strval', (array) ($currentUser['groups'] ?? []))));
|
$currentGroups = array_map(static fn (string $group): string => strtolower(trim($group, '/')), array_values(array_map('strval', (array) ($currentUser['groups'] ?? []))));
|
||||||
|
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ declare(strict_types=1);
|
|||||||
require_once dirname(__DIR__, 3) . '/src/App/bootstrap.php';
|
require_once dirname(__DIR__, 3) . '/src/App/bootstrap.php';
|
||||||
|
|
||||||
use App\ConfigLoader;
|
use App\ConfigLoader;
|
||||||
|
use App\AccountGate;
|
||||||
use App\KeycloakAuth;
|
use App\KeycloakAuth;
|
||||||
use MiningChecker\LegacyModuleStore;
|
use MiningChecker\LegacyModuleStore;
|
||||||
use MiningChecker\MiningCheckerUserScope;
|
use MiningChecker\MiningCheckerUserScope;
|
||||||
@@ -13,9 +14,20 @@ session_start();
|
|||||||
|
|
||||||
$projectRoot = dirname(__DIR__, 3);
|
$projectRoot = dirname(__DIR__, 3);
|
||||||
$auth = new KeycloakAuth(ConfigLoader::load($projectRoot, 'keycloak'));
|
$auth = new KeycloakAuth(ConfigLoader::load($projectRoot, 'keycloak'));
|
||||||
|
$accountGate = new AccountGate(ConfigLoader::load($projectRoot, 'registration'));
|
||||||
|
|
||||||
header('Content-Type: application/json; charset=utf-8');
|
header('Content-Type: application/json; charset=utf-8');
|
||||||
|
|
||||||
|
if ($auth->isAuthenticated()) {
|
||||||
|
$currentUser = is_array($_SESSION['desktop_auth']['user'] ?? null) ? $_SESSION['desktop_auth']['user'] : [];
|
||||||
|
$accountCheck = $accountGate->checkUsername((string) ($currentUser['username'] ?? ''));
|
||||||
|
|
||||||
|
if (!($accountCheck['allowed'] ?? false)) {
|
||||||
|
$auth->logout();
|
||||||
|
respond(['error' => (string) ($accountCheck['message'] ?? 'Dieses Konto ist noch nicht freigeschaltet.')], 403);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if (!$auth->shouldShowDesktop()) {
|
if (!$auth->shouldShowDesktop()) {
|
||||||
respond(['error' => 'Nicht autorisiert.'], 401);
|
respond(['error' => 'Nicht autorisiert.'], 401);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ declare(strict_types=1);
|
|||||||
require_once dirname(__DIR__, 5) . '/src/App/bootstrap.php';
|
require_once dirname(__DIR__, 5) . '/src/App/bootstrap.php';
|
||||||
|
|
||||||
use App\ConfigLoader;
|
use App\ConfigLoader;
|
||||||
|
use App\AccountGate;
|
||||||
use App\KeycloakAuth;
|
use App\KeycloakAuth;
|
||||||
use MiningChecker\LegacyModuleStore;
|
use MiningChecker\LegacyModuleStore;
|
||||||
use MiningChecker\MiningCheckerUserScope;
|
use MiningChecker\MiningCheckerUserScope;
|
||||||
@@ -13,9 +14,22 @@ session_start();
|
|||||||
|
|
||||||
$projectRoot = dirname(__DIR__, 5);
|
$projectRoot = dirname(__DIR__, 5);
|
||||||
$auth = new KeycloakAuth(ConfigLoader::load($projectRoot, 'keycloak'));
|
$auth = new KeycloakAuth(ConfigLoader::load($projectRoot, 'keycloak'));
|
||||||
|
$accountGate = new AccountGate(ConfigLoader::load($projectRoot, 'registration'));
|
||||||
|
|
||||||
header('Content-Type: application/json; charset=utf-8');
|
header('Content-Type: application/json; charset=utf-8');
|
||||||
|
|
||||||
|
if ($auth->isAuthenticated()) {
|
||||||
|
$currentUser = is_array($_SESSION['desktop_auth']['user'] ?? null) ? $_SESSION['desktop_auth']['user'] : [];
|
||||||
|
$accountCheck = $accountGate->checkUsername((string) ($currentUser['username'] ?? ''));
|
||||||
|
|
||||||
|
if (!($accountCheck['allowed'] ?? false)) {
|
||||||
|
$auth->logout();
|
||||||
|
http_response_code(403);
|
||||||
|
echo json_encode(['error' => (string) ($accountCheck['message'] ?? 'Dieses Konto ist noch nicht freigeschaltet.')], JSON_UNESCAPED_UNICODE);
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if (!$auth->shouldShowDesktop()) {
|
if (!$auth->shouldShowDesktop()) {
|
||||||
http_response_code(401);
|
http_response_code(401);
|
||||||
echo json_encode(['error' => 'Nicht autorisiert.'], JSON_UNESCAPED_UNICODE);
|
echo json_encode(['error' => 'Nicht autorisiert.'], JSON_UNESCAPED_UNICODE);
|
||||||
|
|||||||
@@ -5,12 +5,25 @@ declare(strict_types=1);
|
|||||||
require_once dirname(__DIR__, 3) . '/src/App/bootstrap.php';
|
require_once dirname(__DIR__, 3) . '/src/App/bootstrap.php';
|
||||||
|
|
||||||
use App\ConfigLoader;
|
use App\ConfigLoader;
|
||||||
|
use App\AccountGate;
|
||||||
use App\KeycloakAuth;
|
use App\KeycloakAuth;
|
||||||
|
|
||||||
session_start();
|
session_start();
|
||||||
|
|
||||||
$projectRoot = dirname(__DIR__, 3);
|
$projectRoot = dirname(__DIR__, 3);
|
||||||
$auth = new KeycloakAuth(ConfigLoader::load($projectRoot, 'keycloak'));
|
$auth = new KeycloakAuth(ConfigLoader::load($projectRoot, 'keycloak'));
|
||||||
|
$accountGate = new AccountGate(ConfigLoader::load($projectRoot, 'registration'));
|
||||||
|
|
||||||
|
if ($auth->isAuthenticated()) {
|
||||||
|
$currentUser = is_array($_SESSION['desktop_auth']['user'] ?? null) ? $_SESSION['desktop_auth']['user'] : [];
|
||||||
|
$accountCheck = $accountGate->checkUsername((string) ($currentUser['username'] ?? ''));
|
||||||
|
|
||||||
|
if (!($accountCheck['allowed'] ?? false)) {
|
||||||
|
$auth->logout();
|
||||||
|
header('Location: /auth/inactive/?message=' . urlencode((string) ($accountCheck['message'] ?? 'Dieses Konto ist noch nicht freigeschaltet.')), true, 302);
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if (!$auth->shouldShowDesktop()) {
|
if (!$auth->shouldShowDesktop()) {
|
||||||
header('Location: /auth/keycloak', true, 302);
|
header('Location: /auth/keycloak', true, 302);
|
||||||
|
|||||||
@@ -5,12 +5,14 @@ declare(strict_types=1);
|
|||||||
require_once dirname(__DIR__, 3) . '/src/App/bootstrap.php';
|
require_once dirname(__DIR__, 3) . '/src/App/bootstrap.php';
|
||||||
|
|
||||||
use App\ConfigLoader;
|
use App\ConfigLoader;
|
||||||
|
use App\AccountGate;
|
||||||
use App\KeycloakAuth;
|
use App\KeycloakAuth;
|
||||||
|
|
||||||
session_start();
|
session_start();
|
||||||
|
|
||||||
$projectRoot = dirname(__DIR__, 3);
|
$projectRoot = dirname(__DIR__, 3);
|
||||||
$auth = new KeycloakAuth(ConfigLoader::load($projectRoot, 'keycloak'));
|
$auth = new KeycloakAuth(ConfigLoader::load($projectRoot, 'keycloak'));
|
||||||
|
$accountGate = new AccountGate(ConfigLoader::load($projectRoot, 'registration'));
|
||||||
$state = (string) ($_GET['state'] ?? '');
|
$state = (string) ($_GET['state'] ?? '');
|
||||||
$expectedState = (string) ($_SESSION['keycloak_oauth_state'] ?? '');
|
$expectedState = (string) ($_SESSION['keycloak_oauth_state'] ?? '');
|
||||||
$code = (string) ($_GET['code'] ?? '');
|
$code = (string) ($_GET['code'] ?? '');
|
||||||
@@ -50,12 +52,22 @@ if ($state === '' || $expectedState === '' || !hash_equals($expectedState, $stat
|
|||||||
} else {
|
} else {
|
||||||
/** @var array<string, mixed> $userPayload */
|
/** @var array<string, mixed> $userPayload */
|
||||||
$userPayload = $userInfo['data'];
|
$userPayload = $userInfo['data'];
|
||||||
|
$username = (string) ($userPayload['preferred_username'] ?? '');
|
||||||
|
$accountCheck = $accountGate->checkUsername($username);
|
||||||
|
|
||||||
|
if (!($accountCheck['allowed'] ?? false)) {
|
||||||
|
$auth->logout();
|
||||||
|
http_response_code(403);
|
||||||
|
$title = 'Zugriff gesperrt';
|
||||||
|
$message = (string) ($accountCheck['message'] ?? 'Dieses Konto ist noch nicht freigeschaltet.');
|
||||||
|
} else {
|
||||||
$auth->establishSession($tokenPayload, $userPayload);
|
$auth->establishSession($tokenPayload, $userPayload);
|
||||||
header('Location: ' . $redirectTarget, true, 302);
|
header('Location: ' . $redirectTarget, true, 302);
|
||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
?><!DOCTYPE html>
|
?><!DOCTYPE html>
|
||||||
<html lang="de">
|
<html lang="de">
|
||||||
|
|||||||
35
public/auth/inactive/index.php
Normal file
35
public/auth/inactive/index.php
Normal file
@@ -0,0 +1,35 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
require_once dirname(__DIR__, 3) . '/src/App/bootstrap.php';
|
||||||
|
|
||||||
|
$message = trim((string) ($_GET['message'] ?? ''));
|
||||||
|
|
||||||
|
if ($message === '') {
|
||||||
|
$message = 'Dieses Konto ist noch nicht freigeschaltet.';
|
||||||
|
}
|
||||||
|
?><!DOCTYPE html>
|
||||||
|
<html lang="de">
|
||||||
|
<head>
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||||
|
<title>Konto nicht freigeschaltet</title>
|
||||||
|
<link rel="stylesheet" href="/assets/auth/login.css">
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
<main class="login-shell">
|
||||||
|
<section class="login-panel">
|
||||||
|
<div class="login-panel-top">
|
||||||
|
<p class="login-kicker">Kusche.Berlin</p>
|
||||||
|
<h1>Konto nicht freigeschaltet</h1>
|
||||||
|
<p class="login-copy"><?= htmlspecialchars($message, ENT_QUOTES) ?></p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="login-actions">
|
||||||
|
<a class="login-button login-button-primary" href="/auth/keycloak">Zum Login</a>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
</main>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -39,8 +39,7 @@ unset($_SESSION['registration_confirmation']);
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="login-actions">
|
<div class="login-actions">
|
||||||
<a class="login-button login-button-primary" href="/auth/keycloak">Weiter zu Keycloak</a>
|
<a class="login-button login-button-primary" href="/auth/keycloak">Zum Login</a>
|
||||||
<a class="login-button login-button-secondary" href="/auth/register/">Neue Registrierung</a>
|
|
||||||
</div>
|
</div>
|
||||||
</section>
|
</section>
|
||||||
</main>
|
</main>
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ declare(strict_types=1);
|
|||||||
require_once dirname(__DIR__) . '/src/App/bootstrap.php';
|
require_once dirname(__DIR__) . '/src/App/bootstrap.php';
|
||||||
|
|
||||||
use App\App;
|
use App\App;
|
||||||
|
use App\AccountGate;
|
||||||
use App\ConfigLoader;
|
use App\ConfigLoader;
|
||||||
use App\KeycloakAuth;
|
use App\KeycloakAuth;
|
||||||
|
|
||||||
@@ -12,7 +13,20 @@ session_start();
|
|||||||
|
|
||||||
$projectRoot = dirname(__DIR__);
|
$projectRoot = dirname(__DIR__);
|
||||||
$keycloakConfig = ConfigLoader::load($projectRoot, 'keycloak');
|
$keycloakConfig = ConfigLoader::load($projectRoot, 'keycloak');
|
||||||
|
$registrationConfig = ConfigLoader::load($projectRoot, 'registration');
|
||||||
$auth = new KeycloakAuth($keycloakConfig);
|
$auth = new KeycloakAuth($keycloakConfig);
|
||||||
|
$accountGate = new AccountGate($registrationConfig);
|
||||||
|
|
||||||
|
if ($auth->isAuthenticated()) {
|
||||||
|
$currentUser = is_array($_SESSION['desktop_auth']['user'] ?? null) ? $_SESSION['desktop_auth']['user'] : [];
|
||||||
|
$accountCheck = $accountGate->checkUsername((string) ($currentUser['username'] ?? ''));
|
||||||
|
|
||||||
|
if (!($accountCheck['allowed'] ?? false)) {
|
||||||
|
$auth->logout();
|
||||||
|
header('Location: /auth/inactive/?message=' . urlencode((string) ($accountCheck['message'] ?? 'Dieses Konto ist noch nicht freigeschaltet.')), true, 302);
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if (!$auth->shouldShowDesktop()) {
|
if (!$auth->shouldShowDesktop()) {
|
||||||
if ($auth->isConfigured()) {
|
if ($auth->isConfigured()) {
|
||||||
|
|||||||
65
src/App/AccountGate.php
Normal file
65
src/App/AccountGate.php
Normal file
@@ -0,0 +1,65 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App;
|
||||||
|
|
||||||
|
final class AccountGate
|
||||||
|
{
|
||||||
|
private LdapProvisioner $ldap;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $config
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
private readonly array $config,
|
||||||
|
) {
|
||||||
|
$this->ldap = new LdapProvisioner($config);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array{allowed: bool, message: string}
|
||||||
|
*/
|
||||||
|
public function checkUsername(string $username): array
|
||||||
|
{
|
||||||
|
$username = strtolower(trim($username));
|
||||||
|
|
||||||
|
if ($username === '') {
|
||||||
|
return [
|
||||||
|
'allowed' => false,
|
||||||
|
'message' => 'Für dieses Konto konnte kein Benutzername ermittelt werden.',
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!$this->ldap->isEnabled() || !$this->ldap->canUseLdap()) {
|
||||||
|
return [
|
||||||
|
'allowed' => false,
|
||||||
|
'message' => 'Der Kontostatus konnte nicht sicher geprüft werden.',
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
$user = $this->ldap->getUserByUsername($username, ['uid', 'shadowExpire']);
|
||||||
|
|
||||||
|
if (!is_array($user)) {
|
||||||
|
return [
|
||||||
|
'allowed' => false,
|
||||||
|
'message' => 'Dieses Konto ist nicht freigeschaltet.',
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
$shadowExpire = (string) ($user['shadowexpire'] ?? $user['shadowExpire'] ?? '');
|
||||||
|
$activeShadowExpire = (string) ($this->config['ldap']['active_shadow_expire'] ?? -1);
|
||||||
|
|
||||||
|
if ($shadowExpire !== $activeShadowExpire) {
|
||||||
|
return [
|
||||||
|
'allowed' => false,
|
||||||
|
'message' => 'Dieses Konto ist noch nicht freigeschaltet.',
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
return [
|
||||||
|
'allowed' => true,
|
||||||
|
'message' => 'Konto ist aktiv.',
|
||||||
|
];
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -64,7 +64,8 @@ final class RegistrationService
|
|||||||
$note = trim((string) ($input['note'] ?? ''));
|
$note = trim((string) ($input['note'] ?? ''));
|
||||||
$password = (string) ($input['password'] ?? '');
|
$password = (string) ($input['password'] ?? '');
|
||||||
$passwordConfirm = (string) ($input['password_confirm'] ?? '');
|
$passwordConfirm = (string) ($input['password_confirm'] ?? '');
|
||||||
$displayName = trim($givenName . ' ' . $familyName);
|
$displayName = $givenName;
|
||||||
|
$fullName = trim($givenName . ' ' . $familyName);
|
||||||
$errors = [];
|
$errors = [];
|
||||||
|
|
||||||
if (!preg_match('/^[a-z0-9._-]{3,32}$/', $username)) {
|
if (!preg_match('/^[a-z0-9._-]{3,32}$/', $username)) {
|
||||||
@@ -128,7 +129,7 @@ final class RegistrationService
|
|||||||
'apple_generateduid' => '',
|
'apple_generateduid' => '',
|
||||||
'display_name' => $displayName,
|
'display_name' => $displayName,
|
||||||
'cn' => $displayName !== '' ? $displayName : $username,
|
'cn' => $displayName !== '' ? $displayName : $username,
|
||||||
'gecos' => $displayName,
|
'gecos' => $fullName !== '' ? $fullName : $displayName,
|
||||||
'admin_note' => '',
|
'admin_note' => '',
|
||||||
'ldap_created_at' => gmdate('c'),
|
'ldap_created_at' => gmdate('c'),
|
||||||
];
|
];
|
||||||
|
|||||||
Reference in New Issue
Block a user