Version 3.2.3

This commit is contained in:
Neo committed 2025-12-19 00:34:03 -08:00
1 parent ae5c01cc78
commit 78706903a2
2641 files changed
+228363 -201264

No files matched your search

@@ -0,0 +1,49 @@
<?php
/**
* This is the base class for any authentication object.
*
* @package Sabre
* @subpackage DAV
* @copyright Copyright (C) 2007-2010 Rooftop Solutions. All rights reserved.
* @author Evert Pot (http://www.rooftopsolutions.nl/)
* @license http://code.google.com/p/sabredav/wiki/License Modified BSD License
*/
abstract class Sabre_DAV_Auth_Backend_Abstract {
/**
* Authenticates the user based on the current request.
*
* If authentication is succesful, true must be returned.
* If authentication fails, an exception must be thrown.
*
* @return bool
*/
abstract public function authenticate(Sabre_DAV_Server $server,$realm);
/**
* Returns information about the currently logged in user.
*
* If nobody is currently logged in, this method should return null.
*
* @return array|null
*/
abstract public function getCurrentUser();
/**
* Returns the full list of users.
*
* This method must at least return a uri for each user.
*
* It is optional to implement this.
*
* @return array
*/
public function getUsers() {
return array();
}
}
@@ -0,0 +1,85 @@
<?php
/**
* HTTP Basic authentication backend class
*
* This class can be used by authentication objects wishing to use HTTP Basic
* Most of the digest logic is handled, implementors just need to worry about
* the authenticateInternal and getUserInfo methods
*
* @package Sabre
* @subpackage DAV
* @copyright Copyright (C) 2007-2010 Rooftop Solutions. All rights reserved.
* @author James David Low (http://jameslow.com/)
* @author Evert Pot (http://www.rooftopsolutions.nl/)
* @license http://code.google.com/p/sabredav/wiki/License Modified BSD License
*/
abstract class Sabre_DAV_Auth_Backend_AbstractBasic extends Sabre_DAV_Auth_Backend_Abstract {
/**
* This variable holds information about the currently
* logged in user.
*
* @var array|null
*/
protected $currentUser;
/**
* Validates a username and password
*
* If the username and password were correct, this method must return
* an array with at least a 'uri' key.
*
* If the credentials are incorrect, this method must return false.
*
* @return bool|array
*/
abstract protected function validateUserPass($username, $password);
/**
* Returns information about the currently logged in user.
*
* If nobody is currently logged in, this method should return null.
*
* @return array|null
*/
public function getCurrentUser() {
return $this->currentUser;
}
/**
* Authenticates the user based on the current request.
*
* If authentication is succesful, true must be returned.
* If authentication fails, an exception must be thrown.
*
* @throws Sabre_DAV_Exception_NotAuthenticated
* @return bool
*/
public function authenticate(Sabre_DAV_Server $server,$realm) {
$auth = new Sabre_HTTP_BasicAuth();
$auth->setHTTPRequest($server->httpRequest);
$auth->setHTTPResponse($server->httpResponse);
$auth->setRealm($realm);
$userpass = $auth->getUserPass();
if (!$userpass) {
$auth->requireLogin();
throw new Sabre_DAV_Exception_NotAuthenticated('No basic authentication headers were found');
}
// Authenticates the user
if (!($userData = $this->validateUserPass($userpass[0],$userpass[1]))) {
$auth->requireLogin();
throw new Sabre_DAV_Exception_NotAuthenticated('Username or password does not match');
}
if (!isset($userData['uri'])) {
throw new Sabre_DAV_Exception('The returned array from validateUserPass must contain at a uri element');
}
$this->currentUser = $userData;
return true;
}
}
@@ -0,0 +1,105 @@
<?php
/**
* HTTP Digest authentication backend class
*
* This class can be used by authentication objects wishing to use HTTP Digest
* Most of the digest logic is handled, implementors just need to worry about
* the getUserInfo method
*
* @package Sabre
* @subpackage DAV
* @copyright Copyright (C) 2007-2010 Rooftop Solutions. All rights reserved.
* @author Evert Pot (http://www.rooftopsolutions.nl/)
* @license http://code.google.com/p/sabredav/wiki/License Modified BSD License
*/
abstract class Sabre_DAV_Auth_Backend_AbstractDigest extends Sabre_DAV_Auth_Backend_Abstract {
/**
* This variable holds information about the currently
* logged in user.
*
* @var array|null
*/
protected $currentUser;
/**
* Returns a users information based on its username
*
* The returned struct must contain at least a uri
* element (which can be identical to username) as well as a digestHash
* element.
*
* If the user was not known, false must be returned.
*
* @param string $realm
* @param string $username
* @return array
*/
abstract public function getUserInfo($realm, $username);
/**
* Authenticates the user based on the current request.
*
* If authentication is succesful, true must be returned.
* If authentication fails, an exception must be thrown.
*
* @throws Sabre_DAV_Exception_NotAuthenticated
* @return bool
*/
public function authenticate(Sabre_DAV_Server $server,$realm) {
$digest = new Sabre_HTTP_DigestAuth();
// Hooking up request and response objects
$digest->setHTTPRequest($server->httpRequest);
$digest->setHTTPResponse($server->httpResponse);
$digest->setRealm($realm);
$digest->init();
$username = $digest->getUsername();
// No username was given
if (!$username) {
$digest->requireLogin();
throw new Sabre_DAV_Exception_NotAuthenticated('No digest authentication headers were found');
}
$userData = $this->getUserInfo($realm, $username);
// If this was false, the user account didn't exist
if ($userData===false) {
$digest->requireLogin();
throw new Sabre_DAV_Exception_NotAuthenticated('The supplied username was not on file');
}
if (!is_array($userData)) {
throw new Sabre_DAV_Exception('The returntype for getUserInfo must be either false or an array');
}
if (!isset($userData['uri']) || !isset($userData['digestHash'])) {
throw new Sabre_DAV_Exception('The returned array from getUserInfo must contain at least a uri and digestHash element');
}
// If this was false, the password or part of the hash was incorrect.
if (!$digest->validateA1($userData['digestHash'])) {
$digest->requireLogin();
throw new Sabre_DAV_Exception_NotAuthenticated('Incorrect username');
}
$this->currentUser = $userData;
return true;
}
/**
* Returns information about the currently logged in user.
*
* @return array|null
*/
public function getCurrentUser() {
return $this->currentUser;
}
}
@@ -0,0 +1,77 @@
<?php
/**
* Apache authenticator
*
* This authentication backend assumes that auhtentication has been
* conifgured in apache, rather than within SabreDAV.
*
* Make sure apache is properly configured for this to work.
*
* @package Sabre
* @subpackage DAV
* @copyright Copyright (C) 2007-2010 Rooftop Solutions. All rights reserved.
* @author Evert Pot (http://www.rooftopsolutions.nl/)
* @license http://code.google.com/p/sabredav/wiki/License Modified BSD License
*/
class Sabre_DAV_Auth_Backend_Apache extends Sabre_DAV_Auth_Backend_Abstract {
/**
* Current apache user
*
* @var string
*/
protected $remoteUser;
/**
* Authenticates the user based on the current request.
*
* If authentication is succesful, true must be returned.
* If authentication fails, an exception must be thrown.
*
* @return bool
*/
public function authenticate(Sabre_DAV_Server $server,$realm) {
$remoteUser = $server->httpRequest->getRawServerValue('REMOTE_USER');
if (is_null($remoteUser)) {
throw new Sabre_DAV_Exception('We did not receive the $_SERVER[REMOTE_USER] property. This means that apache might have been misconfigured');
}
$this->remoteUser = $remoteUser;
return true;
}
/**
* Returns information about the currently logged in user.
*
* If nobody is currently logged in, this method should return null.
*
* @return array|null
*/
public function getCurrentUser() {
return array(
'uri' => 'principals/' . $this->remoteUser,
);
}
/**
* Returns the full list of users.
*
* This method must at least return a uri for each user.
*
* It is optional to implement this.
*
* @return array
*/
public function getUsers() {
return array($this->getCurrentUser());
}
}
@@ -0,0 +1,102 @@
<?php
/**
* This is an authentication backend that uses a file to manage passwords.
*
* The backend file must conform to Apache's htdigest format
*
* @package Sabre
* @subpackage DAV
* @copyright Copyright (C) 2007-2010 Rooftop Solutions. All rights reserved.
* @author Evert Pot (http://www.rooftopsolutions.nl/)
* @license http://code.google.com/p/sabredav/wiki/License Modified BSD License
*/
class Sabre_DAV_Auth_Backend_File extends Sabre_DAV_Auth_Backend_AbstractDigest {
/**
* List of users
*
* @var array
*/
protected $users = array();
/**
* Creates the backend object.
*
* If the filename argument is passed in, it will parse out the specified file fist.
*
* @param string $filename
* @return void
*/
public function __construct($filename=null) {
if (!is_null($filename))
$this->loadFile($filename);
}
/**
* Loads an htdigest-formatted file. This method can be called multiple times if
* more than 1 file is used.
*
* @param string $filename
* @return void
*/
public function loadFile($filename) {
foreach(file($filename,FILE_IGNORE_NEW_LINES) as $line) {
if (substr_count($line, ":") !== 2)
throw new Sabre_DAV_Exception('Malformed htdigest file. Every line should contain 2 colons');
list($username,$realm,$A1) = explode(':',$line);
if (!preg_match('/^[a-zA-Z0-9]{32}$/', $A1))
throw new Sabre_DAV_Exception('Malformed htdigest file. Invalid md5 hash');
$this->users[$username] = array(
'digestHash' => $A1,
'uri' => 'principals/' . $username
);
}
}
/**
* Returns a users' information
*
* @param string $realm
* @param string $username
* @return string
*/
public function getUserInfo($realm, $username) {
return isset($this->users[$username])?$this->users[$username]:false;
}
/**
* Returns the full list of users.
*
* This method must at least return a uri for each user.
*
* @return array
*/
public function getUsers() {
$re = array();
foreach($this->users as $userName=>$A1) {
$re[] = array(
'uri'=>'principals/' . $userName
);
}
return $re;
}
}
@@ -0,0 +1,79 @@
<?php
/**
* This is an authentication backend that uses a file to manage passwords.
*
* The backend file must conform to Apache's htdigest format
*
* @package Sabre
* @subpackage DAV
* @copyright Copyright (C) 2007-2010 Rooftop Solutions. All rights reserved.
* @author Evert Pot (http://www.rooftopsolutions.nl/)
* @license http://code.google.com/p/sabredav/wiki/License Modified BSD License
*/
class Sabre_DAV_Auth_Backend_PDO extends Sabre_DAV_Auth_Backend_AbstractDigest {
private $pdo;
/**
* Creates the backend object.
*
* If the filename argument is passed in, it will parse out the specified file fist.
*
* @param string $filename
* @return void
*/
public function __construct(PDO $pdo) {
$this->pdo = $pdo;
}
/**
* Returns a users' information
*
* @param string $realm
* @param string $username
* @return string
*/
public function getUserInfo($realm,$username) {
$stmt = $this->pdo->prepare('SELECT username, digesta1, email FROM users WHERE username = ?');
$stmt->execute(array($username));
$result = $stmt->fetchAll();
if (!count($result)) return false;
$user = array(
'uri' => 'principals/' . $result[0]['username'],
'digestHash' => $result[0]['digesta1'],
);
if ($result[0]['email']) $user['{http://sabredav.org/ns}email-address'] = $result[0]['email'];
return $user;
}
/**
* Returns a list of all users
*
* @return array
*/
public function getUsers() {
$result = $this->pdo->query('SELECT username, email FROM users')->fetchAll();
$rv = array();
foreach($result as $user) {
$r = array(
'uri' => 'principals/' . $user['username'],
);
if ($user['email']) $r['{http://sabredav.org/ns}email-address'] = $user['email'];
$rv[] = $r;
}
return $rv;
}
}
@@ -0,0 +1,10 @@
<html>
<head><title>IP.Board - Bulletin Board System</title></head>
<body>
<h1>403: IP.Board -&gt; Forbidden</h1>
<hr>
You have reached this page in error, please use your back button to return to the forum.
<hr>
<a href="http://www.invisionpower.com/">IP.Board</a>
</body>
</html>