2011-01-11 08:43:13 +00:00
|
|
|
<?php
|
|
|
|
class Application_Controller_Plugin_Auth extends Zend_Controller_Plugin_Abstract
|
|
|
|
{
|
|
|
|
public function preDispatch(Zend_Controller_Request_Abstract $request)
|
|
|
|
{
|
2011-09-07 12:54:43 +00:00
|
|
|
$checkAuth = true;
|
2012-08-23 20:19:14 +00:00
|
|
|
if ($request->getControllerName()=='user' && $request->getActionName()=='login') {
|
2012-06-20 20:23:01 +00:00
|
|
|
$checkAuth = false;
|
2011-09-07 12:54:43 +00:00
|
|
|
}
|
2013-11-21 16:31:49 +00:00
|
|
|
|
2013-06-14 16:00:22 +00:00
|
|
|
if ($request->getControllerName()=='user' && $request->getActionName()=='motpasse') {
|
|
|
|
$checkAuth = false;
|
|
|
|
}
|
2012-12-26 10:36:47 +00:00
|
|
|
|
2014-12-09 11:28:12 +00:00
|
|
|
if ($request->getControllerName()=='auth') {
|
|
|
|
$checkAuth = false;
|
|
|
|
}
|
|
|
|
|
2012-10-03 10:21:18 +00:00
|
|
|
if ($request->getControllerName()=='fichier'
|
|
|
|
&& $request->getClientIp(false)=='78.31.45.206') {
|
|
|
|
$checkAuth = false;
|
|
|
|
}
|
2012-12-26 10:36:47 +00:00
|
|
|
|
2015-07-05 19:31:11 +00:00
|
|
|
if ($checkAuth) {
|
|
|
|
|
2011-09-07 12:54:43 +00:00
|
|
|
$login = $request->getParam('login');
|
|
|
|
$pass = $request->getParam('pass', '');
|
|
|
|
$hach = $request->getParam('hach');
|
|
|
|
$checkIp = $request->getParam('checkIp');
|
2012-12-26 10:36:47 +00:00
|
|
|
|
2011-01-11 08:43:13 +00:00
|
|
|
$auth = Zend_Auth::getInstance();
|
2012-12-26 10:36:47 +00:00
|
|
|
|
2015-07-05 19:31:11 +00:00
|
|
|
$mode = null;
|
|
|
|
// --- Mode checkIp=only
|
2015-07-04 15:06:35 +00:00
|
|
|
if ($checkIp == 'only') {
|
2011-09-07 12:54:43 +00:00
|
|
|
$hach = 'iponly:'.$_SERVER['REMOTE_ADDR'];
|
2015-07-05 19:31:11 +00:00
|
|
|
$mode = 'iponly';
|
2011-09-07 12:54:43 +00:00
|
|
|
}
|
2012-12-26 10:36:47 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
// --- On vérifie le tout lors d'une connexion par url
|
2012-04-02 16:01:28 +00:00
|
|
|
if ( !empty($login) && !empty($hach) ) {
|
2012-12-26 10:36:47 +00:00
|
|
|
|
2015-07-05 19:31:11 +00:00
|
|
|
// --- Mode hach
|
|
|
|
if ($mode === null) {
|
|
|
|
$mode = 'hach';
|
|
|
|
}
|
|
|
|
|
|
|
|
$authAdapter = new Scores_Auth_Adapter_Ws($login, $hach, $mode);
|
2011-09-07 12:54:43 +00:00
|
|
|
$result = $auth->authenticate($authAdapter);
|
2012-06-25 08:53:54 +00:00
|
|
|
|
2013-05-14 09:32:08 +00:00
|
|
|
if ( $result->isValid() ) {
|
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
// --- Store identity in sesssion
|
2013-05-14 09:32:08 +00:00
|
|
|
$storage = new Zend_Auth_Storage_Session();
|
|
|
|
$session = new Zend_Session_Namespace($storage->getNamespace());
|
|
|
|
$auth->setStorage($storage);
|
|
|
|
|
|
|
|
$user = new Scores_Utilisateur();
|
|
|
|
$info = get_browser();
|
2013-06-14 16:00:22 +00:00
|
|
|
if ( $info ) {
|
|
|
|
$isMobile = ($info->ismobiledevice==1) ? 1 : 0;
|
|
|
|
$user->setBrowserInfo($info->platform, $info->browser, $info->version, $isMobile);
|
|
|
|
} else {
|
|
|
|
//Save botnet information
|
|
|
|
}
|
2013-05-14 09:32:08 +00:00
|
|
|
|
2012-06-20 20:23:01 +00:00
|
|
|
} else {
|
2013-05-14 09:32:08 +00:00
|
|
|
$messageF = '';
|
|
|
|
foreach ($result->getMessages() as $message) {
|
|
|
|
$messageF.= $message."<br/>";
|
|
|
|
}
|
|
|
|
$request->setModuleName('default')
|
|
|
|
->setControllerName('user')
|
|
|
|
->setActionName('logout')
|
|
|
|
->setParam('message', $messageF);
|
2011-05-18 07:44:43 +00:00
|
|
|
}
|
2012-12-26 10:36:47 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
// --- Sinon on reste sur le standard
|
2011-09-07 12:54:43 +00:00
|
|
|
} else {
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
// --- Authentifié
|
|
|
|
if ( $auth->hasIdentity() ) {
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
// --- Mise à jour du délai de connexion
|
|
|
|
if ( time() < $auth->getIdentity()->time ) {
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
$identity = $auth->getIdentity();
|
|
|
|
$identity->time = time() + $identity->timeout;
|
|
|
|
$auth->getStorage()->write($identity);
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
if (Zend_Session::namespaceIsset('login')){
|
|
|
|
Zend_Session::namespaceUnset('login');
|
|
|
|
}
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
// --- Check CGU
|
|
|
|
if ( $request->getControllerName()!='aide' && $request->getActionName()!='cgu'
|
|
|
|
|| $request->getControllerName()!='user' && $request->getActionName()!='logout') {
|
|
|
|
if ( empty($identity->acceptationCGU) || $identity->acceptationCGU=='0000-00-00 00:00:00' ) {
|
|
|
|
$request->setModuleName('default')
|
|
|
|
->setControllerName('aide')
|
|
|
|
->setActionName('cgu');
|
|
|
|
}
|
|
|
|
}
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
// --- Temps de connexion dépassé
|
|
|
|
} elseif ( time() > $auth->getIdentity()->time ) {
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
$auth->clearIdentity();
|
|
|
|
$storage = $auth->getStorage();
|
|
|
|
Zend_Session::namespaceUnset($storage->getNamespace());
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
if ( !$request->isXmlHttpRequest() ) {
|
|
|
|
$session = new Zend_Session_Namespace('login');
|
|
|
|
$session->url = $_SERVER['REQUEST_URI'];
|
|
|
|
}
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
if ( $request->getControllerName()=='index' && $request->getActionName()=='index' ) {
|
|
|
|
$request->setModuleName('default')
|
|
|
|
->setControllerName('user')
|
|
|
|
->setActionName('login');
|
|
|
|
} else {
|
|
|
|
$request->setModuleName('default')
|
|
|
|
->setControllerName('user')
|
|
|
|
->setActionName('logout')
|
|
|
|
->setParam('ajax', $request->isXmlHttpRequest());
|
|
|
|
}
|
2012-11-20 14:06:45 +00:00
|
|
|
}
|
2015-07-04 15:06:35 +00:00
|
|
|
|
2015-01-13 13:05:26 +00:00
|
|
|
}
|
|
|
|
// --- Pas Authentifié
|
|
|
|
else {
|
2012-12-26 10:36:47 +00:00
|
|
|
|
2014-04-24 10:46:36 +00:00
|
|
|
if ( $request->isXmlHttpRequest() ) {
|
|
|
|
|
2012-11-20 14:06:45 +00:00
|
|
|
$request->setModuleName('default')
|
2013-05-23 13:42:00 +00:00
|
|
|
->setControllerName('user')
|
|
|
|
->setActionName('logout')
|
|
|
|
->setParam('ajax', 1);
|
2014-04-24 10:46:36 +00:00
|
|
|
|
2012-11-20 14:06:45 +00:00
|
|
|
} else {
|
2014-04-24 10:46:36 +00:00
|
|
|
|
2013-05-23 13:42:00 +00:00
|
|
|
$session = new Zend_Session_Namespace('login');
|
|
|
|
$session->url = $_SERVER['REQUEST_URI'];
|
2014-04-24 10:46:36 +00:00
|
|
|
|
2012-11-20 14:06:45 +00:00
|
|
|
$request->setModuleName('default')
|
2014-04-24 10:46:36 +00:00
|
|
|
->setControllerName('user')
|
2013-05-23 13:42:00 +00:00
|
|
|
->setActionName('login');
|
2014-04-24 10:46:36 +00:00
|
|
|
|
2012-06-20 20:23:01 +00:00
|
|
|
}
|
2012-12-26 10:36:47 +00:00
|
|
|
|
2011-09-07 12:54:43 +00:00
|
|
|
}
|
2011-01-11 08:43:13 +00:00
|
|
|
}
|
2012-06-20 20:23:01 +00:00
|
|
|
}
|
2011-01-11 08:43:13 +00:00
|
|
|
}
|
|
|
|
}
|