ILIAS  release_5-4 Revision v5.4.26-12-gabc799a52e6
class.ilAuthProviderShibboleth.php
Go to the documentation of this file.
1 <?php
2 
3 /* Copyright (c) 1998-2010 ILIAS open source, Extended GPL, see docs/LICENSE */
4 
5 include_once './Services/Authentication/classes/Provider/class.ilAuthProvider.php';
6 include_once './Services/Authentication/interfaces/interface.ilAuthProviderInterface.php';
7 include_once './Services/Authentication/interfaces/interface.ilAuthProviderAccountMigrationInterface.php';
8 
9 
10 require_once('./Services/AuthShibboleth/classes/class.ilShibbolethRoleAssignmentRules.php');
11 require_once('include/Unicode/UtfNormal.php');
12 require_once('./Services/AuthShibboleth/classes/class.ilShibbolethPluginWrapper.php');
13 require_once('./Services/AuthShibboleth/classes/Config/class.shibConfig.php');
14 require_once('./Services/AuthShibboleth/classes/ServerData/class.shibServerData.php');
15 require_once('./Services/AuthShibboleth/classes/User/class.shibUser.php');
16 
22 {
23  private $migration_account = '';
24 
25 
31  {
32  parent::__construct($credentials);
33  }
34 
40  {
41  global $DIC; // for backword compatibility of hook environment variables
42  $ilias = $DIC['ilias'];
43  $ilSetting = $DIC['ilSetting'];
44  $shibServerData = shibServerData::getInstance();
45 
46  //$this->getLogger()->dump($shibServerData);
47 
48  if ($shibServerData->getLogin()) {
49  $shibUser = shibUser::buildInstance($shibServerData);
50  // for backword compatibility of hook environment variables
51  $userObj = &$shibUser; // For shib_data_conv included Script
52  $newUser = $shibUser->isNew(); // For shib_data_conv included Script
53  if ($shibUser->isNew()) {
54  $shibUser->createFields();
55  $shibUser->setPref('hits_per_page', $ilSetting->get('hits_per_page'));
56 
57  // Modify user data before creating the user
58  // Include custom code that can be used to further modify
59  // certain Shibboleth user attributes
60  if ($ilias->getSetting('shib_data_conv') and $ilias->getSetting('shib_data_conv') != ''
61  and is_readable($ilias->getSetting('shib_data_conv'))
62  ) {
63  include($ilias->getSetting('shib_data_conv'));
64  }
65  $shibUser = ilShibbolethPluginWrapper::getInstance()->beforeCreateUser($shibUser);
66  $shibUser->create();
67  $shibUser->updateOwner();
68  $shibUser->saveAsNew();
69  $shibUser->writePrefs();
70  $shibUser = ilShibbolethPluginWrapper::getInstance()->afterCreateUser($shibUser);
72  } else {
73  $shibUser->updateFields();
74  // Include custom code that can be used to further modify
75  // certain Shibboleth user attributes
76  if ($ilias->getSetting('shib_data_conv') and $ilias->getSetting('shib_data_conv') != ''
77  and is_readable($ilias->getSetting('shib_data_conv'))
78  ) {
79  include($ilias->getSetting('shib_data_conv'));
80  }
81  // $shibUser->update();
82  $shibUser = ilShibbolethPluginWrapper::getInstance()->beforeUpdateUser($shibUser);
83  $shibUser->update();
84  $shibUser = ilShibbolethPluginWrapper::getInstance()->afterUpdateUser($shibUser);
86  }
87 
89  if (($newUser && !$c->isActivateNew()) || !$newUser) {
91  $status->setAuthenticatedUserId(ilObjUser::_lookupId($shibUser->getLogin()));
92  } elseif ($newUser && $c->isActivateNew()) {
94  $status->setReason('err_inactive');
95  }
96  } else {
97  $this->getLogger()->info('Shibboleth authentication failed.');
98  $this->handleAuthenticationFail($status, 'err_wrong_login');
99  return false;
100  }
101  }
102 }
if((!isset($_SERVER['DOCUMENT_ROOT'])) OR(empty($_SERVER['DOCUMENT_ROOT']))) $_SERVER['DOCUMENT_ROOT']
Interface of auth credentials.
global $DIC
Definition: saml.php:7
const STATUS_AUTHENTICATION_FAILED
__construct(\ilAuthCredentials $credentials)
Constructor.
static _lookupId($a_user_str)
Lookup id by login.
static getInstance()
doAuthentication(\ilAuthStatus $status)
Do apache auth.
setAuthenticatedUserId($a_id)
Base class for authentication providers (radius, ldap, apache, ...)
Standard interface for auth provider implementations.
setStatus($a_status)
Set auth status.
static buildInstance(shibServerData $shibServerData)
setReason($a_reason)
Set reason.
getLogger()
Get logger.
global $ilSetting
Definition: privfeed.php:17
Shibboleth authentication provider.
handleAuthenticationFail(ilAuthStatus $status, $a_reason)
Handle failed authentication.
Auth status implementation.