]> git.vanrenterghem.biz Git - git.ikiwiki.info.git/blobdiff - IkiWiki/Plugin/httpauth.pm
HTML-escape error messages (OVE-20160505-0012)
[git.ikiwiki.info.git] / IkiWiki / Plugin / httpauth.pm
index 202ca11532e357322d1a14b2b285460c2b500f11..76d574b2a899df7e77cb71f2a4f27ee078e76b43 100644 (file)
@@ -7,12 +7,13 @@ use strict;
 use IkiWiki 3.00;
 
 sub import {
 use IkiWiki 3.00;
 
 sub import {
+       hook(type => "checkconfig", id => "httpauth", call => \&checkconfig);
        hook(type => "getsetup", id => "httpauth", call => \&getsetup);
        hook(type => "auth", id => "httpauth", call => \&auth);
        hook(type => "formbuilder_setup", id => "httpauth",
                call => \&formbuilder_setup);
        hook(type => "getsetup", id => "httpauth", call => \&getsetup);
        hook(type => "auth", id => "httpauth", call => \&auth);
        hook(type => "formbuilder_setup", id => "httpauth",
                call => \&formbuilder_setup);
-       hook(type => "canedit", id => "httpauth", call => \&canedit);
-       hook(type => "pagetemplate", id => "httpauth", call => \&pagetemplate);
+       hook(type => "canedit", id => "httpauth", call => \&canedit,
+               first => 1);
 }
 
 sub getsetup () {
 }
 
 sub getsetup () {
@@ -20,6 +21,7 @@ sub getsetup () {
                plugin => {
                        safe => 1,
                        rebuild => 0,
                plugin => {
                        safe => 1,
                        rebuild => 0,
+                       section => "auth",
                },
                cgiauthurl => {
                        type => "string",
                },
                cgiauthurl => {
                        type => "string",
@@ -36,12 +38,27 @@ sub getsetup () {
                        rebuild => 0,
                },
 }
                        rebuild => 0,
                },
 }
+
+sub checkconfig () {
+       if ($config{cgi} && defined $config{cgiauthurl} &&
+           keys %{$IkiWiki::hooks{auth}} < 2) {
+               # There are no other auth hooks registered, so avoid
+               # the normal signin form, and jump right to httpauth.
+               require IkiWiki::CGI;
+               inject(name => "IkiWiki::cgi_signin", call => sub ($$) {
+                       my $cgi=shift;
+                       redir_cgiauthurl($cgi, $cgi->query_string());
+               });
+       }
+}
                        
 sub redir_cgiauthurl ($;@) {
        my $cgi=shift;
 
        IkiWiki::redirect($cgi, 
                        
 sub redir_cgiauthurl ($;@) {
        my $cgi=shift;
 
        IkiWiki::redirect($cgi, 
-               IkiWiki::cgiurl(cgiurl => $config{cgiauthurl}, @_));
+               @_ > 1 ? IkiWiki::cgiurl(cgiurl => $config{cgiauthurl}, @_)
+                      : $config{cgiauthurl}."?@_"
+       );
        exit;
 }
 
        exit;
 }
 
@@ -75,25 +92,21 @@ sub formbuilder_setup (@) {
        }
 }
 
        }
 }
 
-sub test_httpauth_pagespec ($) {
-       my $page=shift;
-
-       return defined $config{httpauth_pagespec} &&
-              length $config{httpauth_pagespec} &&
-              defined $config{cgiauthurl} &&
-              pagespec_match($page, $config{httpauth_pagespec});
-}
-
 sub canedit ($$$) {
        my $page=shift;
        my $cgi=shift;
        my $session=shift;
 
 sub canedit ($$$) {
        my $page=shift;
        my $cgi=shift;
        my $session=shift;
 
-       if (! defined $cgi->remote_user() && test_httpauth_pagespec($page)) {
+       if (! defined $cgi->remote_user() &&
+           (! defined $session->param("name") ||
+             ! IkiWiki::userinfo_get($session->param("name"), "regdate")) &&
+           defined $config{httpauth_pagespec} &&
+           length $config{httpauth_pagespec} &&
+           defined $config{cgiauthurl} &&
+           pagespec_match($page, $config{httpauth_pagespec})) {
                return sub {
                return sub {
-                       IkiWiki::redirect($cgi, 
-                               $config{cgiauthurl}.'?'.$cgi->query_string());
-                       exit;
+                       # bounce thru cgiauthurl and back to edit action
+                       redir_cgiauthurl($cgi, $cgi->query_string());
                };
        }
        else {
                };
        }
        else {
@@ -101,18 +114,4 @@ sub canedit ($$$) {
        }
 }
 
        }
 }
 
-sub pagetemplate (@_) {
-       my %params=@_;
-       my $template=$params{template};
-
-       if ($template->param("editurl") &&
-           test_httpauth_pagespec($params{page})) {
-               # go directly to cgiauthurl when editing a page matching
-               # the pagespec
-               $template->param(editurl => IkiWiki::cgiurl(
-                       cgiurl => $config{cgiauthurl},
-                       do => "edit", page => $params{page}));
-       }
-}
-
 1
 1