Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 Programming Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 01-27-2010, 11:01 PM
Vig Vig is offline
 
Join Date: Jan 2010
Posts: 3
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default HTTP Auth using $_SERVER["PHP_AUTH_USER"] and PHP_AUTH_PW...

I put together a basic plugin to reuse HTTP Auth for vBulletin login. In our environment, the webserver has HTTP Auth to access it and PHP shares the username and password as $_SERVER['PHP_AUTH_USER'] and $_SERVER['PHP_AUTH_PW'].

In the admin control panel, I created a new plugin named "HTTP Authentication" attached to the global_bootstrap_init_complete hook:

Code:
error_reporting(E_ALL & ~E_NOTICE);

// some basic requirements
require_once(DIR . '/includes/functions_login.php');

$newuser =& datamanager_init('User', $vbulletin, ERRTYPE_ARRAY);
$newuser->set('username', $_SERVER["PHP_AUTH_USER"]);
$newuser->set('password', $_SERVER["PHP_AUTH_PW"]);
$newuser->set('email', $_SERVER["PHP_AUTH_USER"]);
$newuser->set('usergroupid', 2);
$newuser->set('timezoneoffset', -6);
$newuser->set('showblogcss', 1);
$newuser->pre_save();

$vbulletin->GPC['vb_login_username'] = $_SERVER["PHP_AUTH_USER"]; //$vbulletin->GPC['vb_login_username'];
$vbulletin->GPC['cookieuser'] = $_SERVER["PHP_AUTH_USER"]; //$vbulletin->GPC['vb_login_username'];
$vbulletin->GPC['cookieuser'] = 1;

// try to create the user in vBulletin; if it works save the dataset else just login
if (empty($newuser->errors))
{
    $newuser->set_info('coppauser', false);
    $vbulletin->userinfo['userid'] = $newuser->save();
}

verify_authentication($vbulletin->GPC['vb_login_username'], '','','',$vbulletin->GPC['cookieuser'], true);
exec_unstrike_user($vbulletin->GPC['vb_login_username']);
process_new_login($vbulletin->GPC['logintype'], $vbulletin->GPC['cookieuser'], $vbulletin->GPC['cssprefs']);
Current problem:

When logged in with the above method, the CSS/display isn't quite right. The "Home", "Forum", "Blogs", etc is on the right and the search box on the left. When logged in with the admin account or not logged in at all, the search box is on the right and the "Home", "Forum", etc is on the left.

So somehow things are getting swapped right to left with the above code...

--------------- Added [DATE]1264656982[/DATE] at [TIME]1264656982[/TIME] ---------------

If I attach this plugin to the "global_complete" hook location the CSS is not affected so it looks like that was the issue.

--------------- Added [DATE]1264723923[/DATE] at [TIME]1264723923[/TIME] ---------------

Updated version: This version uses the same password for everyone. Sounds crazy right? Well HTTP Authentication has to work 100% on our site to ensure security. So nobody can login as anyone else unless they can do so also via HTTP Auth. So the plugin now sets the same password for everyone. The reason for this is that it can now handle the case where the HTTP Auth password changes.

The cleaner way would be to update the password in the vBulletin system when the login fails however I do not know how to do that yet.

Code:
rror_reporting(E_ALL & ~E_NOTICE);

// some basic requirements
require(DIR . '/includes/functions_login.php');

$newuser =& datamanager_init('User', $vbulletin, ERRTYPE_ARRAY);
$newuser->set('username', $_SERVER['PHP_AUTH_USER']);
$newuser->set('password', 'SOME_STRING_HERE');  // http auth is 100% of security, to avoid password issues when passwords change...
$newuser->set('email', $_SERVER['PHP_AUTH_USER']);
$newuser->set('usergroupid', 2);
$newuser->set('timezoneoffset', -6);
$newuser->set('showblogcss', true);
$newuser->set('styleid', 1);
$newuser->pre_save();

$vbulletin->GPC['vb_login_username'] = $_SERVER['PHP_AUTH_USER'];
$vbulletin->GPC['cookieuser'] = $_SERVER['PHP_AUTH_USER'];
$vbulletin->GPC['cssprefs'] = '';

// try to create the user in vBulletin; if it works save the dataset else just login
if (empty($newuser->errors))
{
    $newuser->set_info('coppauser', false);
    $vbulletin->userinfo['userid'] = $newuser->save();
}

verify_authentication($vbulletin->GPC['vb_login_username'], '','','',$vbulletin->GPC['cookieuser'], true);
exec_unstrike_user($vbulletin->GPC['vb_login_username']);
process_new_login($vbulletin->GPC['logintype'], $vbulletin->GPC['cookieuser'], $vbulletin->GPC['cssprefs']);
Reply With Quote
  #2  
Old 01-29-2010, 02:12 AM
Vig Vig is offline
 
Join Date: Jan 2010
Posts: 3
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Version 0.3:

- if session expires, resets session and redirects to reload page

Code:
error_reporting(E_ALL & ~E_NOTICE);

// some basic requirements
require(DIR . '/includes/functions_login.php');

// check if already logged in
$logged_in = (empty($_COOKIE[COOKIE_PREFIX . 'lastvisit'])) ? false : true;

// clean up expired session *before* logging in again
if ($logged_in)
{
    $vbulletin->session->do_lastvisit_update($vbulletin->GPC[COOKIE_PREFIX . 'lastvisit'], $vbulletin->GPC[COOKIE_PREFIX . 'lastactivity']);
}

$newuser =& datamanager_init('User', $vbulletin, ERRTYPE_ARRAY);
$newuser->set('username', $_SERVER['PHP_AUTH_USER']);
$newuser->set('password', 'SOME_STRING_MAKE_IT_UP');  // http auth is 100% of security, to avoid password issues when passwords change...
$newuser->set('email', $_SERVER['PHP_AUTH_USER']);
$newuser->set('usergroupid', 2);
$newuser->set('timezoneoffset', -6);
$newuser->set('showblogcss', true);
$newuser->set('styleid', 1);
$newuser->pre_save();

$vbulletin->GPC['vb_login_username'] = $_SERVER['PHP_AUTH_USER'];
$vbulletin->GPC['cookieuser'] = $_SERVER['PHP_AUTH_USER'];
$vbulletin->GPC['cssprefs'] = '';

// try to create the user in vBulletin; if it works save the dataset else just login
if (empty($newuser->errors))
{
    $newuser->set_info('coppauser', false);
    $vbulletin->userinfo['userid'] = $newuser->save();
}

verify_authentication($vbulletin->GPC['vb_login_username'], '','','',$vbulletin->GPC['cookieuser'], true);
exec_unstrike_user($vbulletin->GPC['vb_login_username']);
process_new_login($vbulletin->GPC['logintype'], $vbulletin->GPC['cookieuser'], $vbulletin->GPC['cssprefs']);

// redirect back so page reloads with logged in cookie-based session active
if (!$logged_in)
{
    header('Location: ' . $_SERVER['PHP_SELF']);
}
--------------- Added [DATE]1264810892[/DATE] at [TIME]1264810892[/TIME] ---------------

Version 0.4:

- Password issue appears to be a non-issue (further testing needed, in mean time, just use $_SERVER['PHP_AUTH_PW']).
- Handle case where session expires and next page load means the user is not logged in (but session cookies are set) and then refresh shows as logged in. Now there is a redirect in this case so user doesn't not see self as ever logged out.
- Handle case where user tries to access a session as someone other than who they are HTTP authenticated as.

Code:
error_reporting(E_ALL & ~E_NOTICE);

// some basic requirements
require(DIR . '/includes/functions_login.php');

if (!$vbulletin->session->vars['loggedin'])
{
    httpauth_login();
    redirect_self();
}
elseif ($userinfo = $vbulletin->session->fetch_userinfo())
{
    if ($userinfo['username'] !== $_SERVER['PHP_AUTH_USER'])
    {
        httpauth_login();
        process_logout();
        redirect_self();
    }
    else
    {
    }
}

function httpauth_login()
{
    global $vbulletin;

    $newuser =& datamanager_init('User', $vbulletin, ERRTYPE_ARRAY);
    $newuser->set('username', $_SERVER['PHP_AUTH_USER']);
    $newuser->set('password', $_SERVER['PHP_AUTH_PW']);
    $newuser->set('email', $_SERVER['PHP_AUTH_USER']);
    $newuser->set('usergroupid', 2);
    $newuser->set('timezoneoffset', -6);
    $newuser->set('showblogcss', true);
    $newuser->set('styleid', 1);
    $newuser->pre_save();

    $vbulletin->GPC['vb_login_username'] = $_SERVER['PHP_AUTH_USER'];
    $vbulletin->GPC['cookieuser'] = $_SERVER['PHP_AUTH_USER'];
    $vbulletin->GPC['cssprefs'] = '';

    // try to create the user in vBulletin; if it works save the dataset else just login
    if (empty($newuser->errors))
    {
        $newuser->set_info('coppauser', false);
        $vbulletin->userinfo['userid'] = $newuser->save();
    }

    verify_authentication($vbulletin->GPC['vb_login_username'], '','','',$vbulletin->GPC['cookieuser'], true);
    exec_unstrike_user($vbulletin->GPC['vb_login_username']);
    process_new_login($vbulletin->GPC['logintype'], $vbulletin->GPC['cookieuser'], $vbulletin->GPC['cssprefs']);
}

function redirect_self()
{
    // may need adjustment for non-Apache servers!
    header('Location: ' . $_SERVER['PHP_SELF']);
}
Reply With Quote
  #3  
Old 10-21-2010, 09:48 AM
PepiMK PepiMK is offline
 
Join Date: Mar 2006
Posts: 10
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Version 0.4 is missing the require_once from version 0.1 - without that, some things will fail (just tested on saw with post preview and post promotion to article on vanilla 4.08 Suite).
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 05:11 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03736 seconds
  • Memory Usage 2,190KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (4)bbcode_code
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (3)post_thanks_box
  • (3)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (3)post_thanks_postbit_info
  • (3)postbit
  • (3)postbit_onlinestatus
  • (3)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete