00001 <?php
00002
00003
00004
00005
00006
00007
00008
00009
00010
00011
00012
00013
00014
00015
00016
00017
00018
00019
00020
00021
00022
00023
00024
00025
00026
00027
00028
00029
00030
00031
00032
00033
00034
00035
00036
00037
00038
00039
00040
00041
00042
00043
00044
00045
00046
00047
00048
00049
00050
00051
00052
00053
00054
00055
00056
00057
00058
00059
00060
00061
00062
00063
00064
00065
00066
00067
00068 class aliroLoginDetails {
00069 private $_user = '';
00070 private $_password = '';
00071 private $_remember = '';
00072
00073 public function __construct ($user, $password='', $remember='') {
00074 $this->_user = $user;
00075 $this->_password = $password;
00076 $this->_remember = $remember;
00077 }
00078
00079 public function getUser () {
00080 return $this->_user;
00081 }
00082
00083 public function getPassword () {
00084 return $this->_password;
00085 }
00086
00087 public function getRemember () {
00088 return $this->_remember;
00089 }
00090
00091 }
00092
00093 abstract class aliroAuthenticator {
00094
00095
00096 public function logout () {
00097 if (!empty($_SESSION["aliro_{$this->prefix}id"])) {
00098 $currentDate = date('Y-m-d/TH:i:s');
00099 $query = "UPDATE #__users SET lastvisitDate='$currentDate' WHERE id='" . $_SESSION["aliro_{$this->prefix}id"] . "'";
00100 aliroDatabase::getInstance()->doSQL($query);
00101 }
00102 aliroSessionFactory::getSession()->logout();
00103 }
00104
00105 public function makePassword ($syllables = 3) {
00106
00107
00108 $vowels = array ('a', 'o', 'e', 'i', 'y', 'u', 'ou', 'oo');
00109
00110 $consonants = array ('w', 'r', 't', 'p', 's', 'd', 'f', 'g', 'h', 'j', 'k', 'l', 'z', 'x', 'c', 'v', 'b', 'n', 'm', 'qu');
00111
00112 for ($i=0, $password=''; $i<$syllables; $i++) $password .= $this->makeSyllable($vowels, $consonants, $i);
00113
00114 return $password.$this->makeSuffix($vowels, $consonants);
00115 }
00116
00117 private function makeSuffix ($vowels, $consonants) {
00118
00119 $suffix = array ('dom', 'ity', 'ment', 'sion', 'ness', 'ence', 'er', 'ist', 'tion', 'or');
00120 $new = $suffix[array_rand($suffix)];
00121
00122 return (in_array($new[0], $vowels)) ? $consonants[array_rand($consonants)].$new : $new;
00123 }
00124
00125 private function makeSyllable ($vowels, $consonants, $double=false) {
00126 $doubles = array('n', 'm', 't', 's');
00127 $c = $consonants[array_rand($consonants)];
00128
00129 if ($double AND in_array($c, $doubles) AND 1 == mt_rand(0,2)) $c .= $c;
00130 return $c.$vowels[array_rand($vowels)];
00131 }
00132
00133 public function makeSalt () {
00134 return $this->makeRandomString(24);
00135 }
00136
00137 private function makeRandomString ($length=8) {
00138 $chars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!%,-:;@_{}~";
00139 for ($i = 0, $makepass = '', $len = strlen($chars); $i < $length; $i++) $makepass .= $chars[mt_rand(0, $len-1)];
00140 return $makepass;
00141 }
00142
00143 }
00144
00145 class aliroUserAuthenticator extends aliroAuthenticator {
00146 private static $instance = __CLASS__;
00147 protected $prefix = 'user';
00148
00149 public static function getInstance () {
00150 return is_object(self::$instance) ? self::$instance : (self::$instance = new self::$instance());
00151 }
00152
00153 public function userLogin () {
00154 $request = aliroRequest::getInstance();
00155 $username = $request->getParam($_POST, 'username');
00156 $passwd = $request->getParam($_POST, 'passwd');
00157 $remember = $request->getParam($_REQUEST, 'remember');
00158 if (!$username OR !$passwd) {
00159 $message = T_('Please complete the username and password fields.');
00160 $request->redirectSame($message, _ALIRO_ERROR_WARN);
00161 exit;
00162 }
00163 $message = $this->systemLogin ($username, $passwd, $remember);
00164 if ($message) $request->redirectSame ($message, _ALIRO_ERROR_WARN);
00165 if ($return = $request->getParam($_REQUEST, 'return')) $request->redirect($return);
00166 elseif (isset($_SESSION['aliro_redirect_here'])) $request->redirect ($_SESSION['aliro_redirect_here']);
00167 else $request->redirect();
00168 }
00169
00170 function systemLogin ($username=null, $passwd=null, $remember=null) {
00171 $session = aliroSessionFactory::getSession();
00172 if (!$session->cookiesAccepted()) return T_('Your browser is not accepting cookies - login is not possible.');
00173 $my = null;
00174 $mambothandler = aliroMambotHandler::getInstance();
00175 $database = aliroDatabase::getInstance();
00176 $username = $database->getEscaped($username);
00177 $escpasswd = $database->getEscaped($passwd);
00178 $remember = $remember ? true : false;
00179 $loginfo = new aliroLoginDetails($username, $escpasswd, $remember);
00180 $checkuser = true;
00181 $logresults = $mambothandler->trigger('requiredLogin',array($loginfo));
00182 $message = '';
00183 if (count($logresults) == 0) $logresults[] = T_('Logins are not permitted. There is no authentication check active.');
00184 foreach ($logresults as $result) {
00185 if (($result instanceof mosUser) AND $result->id) {
00186 if (!isset($my)) $my = $result;
00187 }
00188 elseif ($result) {
00189 $message = $result;
00190 $checkuser = false;
00191 break;
00192 }
00193 }
00194 if ($checkuser AND isset($my)) {
00195 $session->setNewUserData($my);
00196 $mambothandler->trigger('goodLogin', array($loginfo));
00197 $currentDate = date("Y-m-d/TH:i:s");
00198 $query = "UPDATE #__users SET lastvisitDate='$currentDate', block=0 where id='$my->id'";
00199 if ($remember) {
00200 $lifetime = time() + 365*24*60*60;
00201 setcookie("usercookie[username]", $username, $lifetime, "/");
00202 setcookie("usercookie[password]", $passwd, $lifetime, "/");
00203 }
00204 }
00205 else {
00206 $my = null;
00207 $query = "UPDATE #__users SET block=block+1 where username='$username'";
00208 if ($remember) {
00209 $lifetime = time() - 365*24*60*60;
00210 setcookie("usercookie[username]", $username, $lifetime, "/");
00211 setcookie("usercookie[password]", $passwd, $lifetime, "/");
00212 }
00213 }
00214 $database->doSQL($query);
00215 if (is_null($my)) {
00216 $mambothandler->trigger('badLogin', array($loginfo));
00217 sleep(2);
00218 }
00219 return $message;
00220 }
00221
00222 public function logout () {
00223 $mambothandler = aliroMambotHandler::getInstance();
00224 $loginfo = new aliroLoginDetails($_SESSION['aliro_username']);
00225 $mambothandler->trigger('beforeLogout', array($loginfo));
00226 parent::logout();
00227 }
00228
00229 function authenticate (&$message, &$my, $username, $passwd, $remember=null) {
00230 $message = '';
00231 $database = aliroDatabase::getInstance();
00232 $my = new mosUser();
00233 $database->setQuery( "SELECT id, gid, block, name, username, email, sendEmail, usertype FROM #__users WHERE username='$username'");
00234 if ($database->loadObject($my)) {
00235 if ($my->block > 10) {
00236 $message = T_('Your login has been blocked. Please contact the administrator.');
00237 return false;
00238 }
00239 $database = aliroCoreDatabase::getInstance();
00240 $database->setQuery("SELECT COUNT(*) FROM #__core_users WHERE id=$my->id AND password=MD5(CONCAT(salt,'$passwd'))");
00241 if ($database->loadResult()) {
00242 unset($my->block);
00243 return true;
00244 }
00245 }
00246 $message = T_('Incorrect username or password. Please try again.');
00247 return false;
00248 }
00249
00250 }
00251
00252 class aliroAdminAuthenticator extends aliroAuthenticator {
00253 private static $instance = __CLASS__;
00254 protected $prefix = 'admin';
00255
00256 public static function getInstance () {
00257 return is_object(self::$instance) ? self::$instance : (self::$instance = new self::$instance());
00258 }
00259
00260 function login () {
00261 $session = aliroSessionFactory::getSession();
00262 if (!($session->cookiesAccepted())) return null;
00263
00264 $database = aliroDatabase::getInstance();
00266 $request = aliroRequest::getInstance();
00267
00268 $usrname = $database->getEscaped($request->getParam($_POST, 'usrname'));
00269 $pass = $database->getEscaped($request->getParam($_POST, 'pass'));
00270
00271 $my = null;
00272 if (!$pass) {
00273 $request->setErrorMessage(T_('Please enter a password'), _ALIRO_ERROR_WARN);
00274 return $my;
00275 }
00276
00277 $users = $database->doSQLget("SELECT * FROM #__users WHERE usertype IN ('Administrator', 'Super Administrator') OR (username='$usrname' AND block<=10)");
00278 $admins = count($users);
00279 $database = aliroCoreDatabase::getInstance();
00280 foreach ($users as $key=>$oneuser) {
00281 if ($oneuser->username == $usrname) {
00282 $database->setQuery("SELECT COUNT(*) FROM #__core_users WHERE id=$oneuser->id AND password=MD5(CONCAT(salt,'$pass'))");
00283 if ($database->loadResult()) {
00284 $my =& $users[$key];
00285 if (!in_array($my->usertype, array('Administrator', 'Super Administrator'))) $admins--;
00286 }
00287 }
00288 }
00289 if ($admins == 0) {
00290 $request->setErrorMessage(T_('You cannot login. There are no administrators set up.'), _ALIRO_ERROR_FATAL);
00291 return null;
00292 }
00293 if (isset($my)) {
00294 $session->setNewUserData ($my);
00295 $currentDate = date("Y-m-d/TH:i:s");
00296 $query = "UPDATE #__users SET lastvisitDate='$currentDate', block=0 where id='$my->id'";
00297 }
00298 else {
00299 $request->setErrorMessage(T_('Incorrect Username, Password, or Access Level. Please try again'), _ALIRO_ERROR_WARN);
00300 $query = "UPDATE #__users SET block=block+1 where username='$usrname'";
00301 sleep(2);
00302 }
00303 $database->doSQL("OPTIMIZE TABLE #__error_log, #__session, #__session_data");
00304 $database = aliroDatabase::getInstance();
00305 $database->doSQL($query);
00306 return $my;
00307 }
00308
00309 function logout () {
00310 parent::logout();
00311 $request = aliroRequest::getInstance();
00312 $request->redirect($request->getCfg('live_site'));
00313 }
00314
00315 }