. * * @category Settings * @package StatusNet * @author Craig Andrews * @copyright 2008-2009 StatusNet, Inc. * @license http://www.fsf.org/licensing/licenses/agpl-3.0.html GNU Affero General Public License version 3.0 * @link http://status.net/ */ if (!defined('STATUSNET') && !defined('LACONICA')) { exit(1); } require_once INSTALLDIR.'/lib/action.php'; require_once INSTALLDIR.'/plugins/OpenID/openid.php'; require_once(INSTALLDIR.'/plugins/OpenID/User_openid_trustroot.php'); /** * Settings for OpenID * * Lets users add, edit and delete OpenIDs from their account * * @category Settings * @package StatusNet * @author Craig Andrews * @license http://www.fsf.org/licensing/licenses/agpl-3.0.html GNU Affero General Public License version 3.0 * @link http://status.net/ */ class OpenidserverAction extends Action { function handle($args) { parent::handle($args); $oserver = oid_server(); $request = $oserver->decodeRequest(); if (in_array($request->mode, array('checkid_immediate', 'checkid_setup'))) { $cur = common_current_user(); if(!$cur){ /* Go log in, and then come back. */ common_set_returnto($_SERVER['REQUEST_URI']); common_redirect(common_local_url('login')); return; }else if(common_profile_url($cur->nickname) == $request->identity || $request->idSelect()){ $user_openid_trustroot = User_openid_trustroot::pkeyGet( array('user_id'=>$cur->id, 'trustroot'=>$request->trustroot)); if(empty($user_openid_trustroot)){ if($request->immediate){ //cannot prompt the user to trust this trust root in immediate mode, so answer false $response = &$request->answer(false); }else{ //ask the user to trust this trust root $_SESSION['openid_trust_root'] = $request->trust_root; $allowResponse = $request->answer(true, null, common_profile_url($cur->nickname)); $denyResponse = $request->answer(false); common_ensure_session(); $_SESSION['openid_allow_url'] = $allowResponse->encodeToUrl(); $_SESSION['openid_deny_url'] = $denyResponse->encodeToUrl(); common_redirect(common_local_url('openidtrust')); return; } }else{ //user has previously authorized this trust root $response = &$request->answer(true, null, common_profile_url($cur->nickname)); } } else if ($request->immediate) { $response = &$request->answer(false); } else { //invalid $this->clientError(sprintf(_('You are not authorized to use the identity %s'),$request->identity),$code=403); } } else { $response = &$oserver->handleRequest($request); } if($response){ $webresponse = $oserver->encodeResponse($response); if ($webresponse->code != AUTH_OPENID_HTTP_OK) { header(sprintf("HTTP/1.1 %d ", $webresponse->code), true, $webresponse->code); } if($webresponse->headers){ foreach ($webresponse->headers as $k => $v) { header("$k: $v"); } } $this->raw($webresponse->body); }else{ $this->clientError(_('Just an OpenID provider. Nothing to see here, move along...'),$code=500); } } }