#!/usr/bin/perl -Tw -I. -I/usr/local/positive/WebInterface/Pos/Webtop -I/usr/local/positive/Perl use strict; use Digest::MD5(); use MIME::Base64; use HTML::Entities; use URI::Escape; use Config::General; use Pos::Webtop::Web::ContentModule::Intranet; use Pos::Webtop::Toolbox; package webtopFormBuilder; my $tb = Pos::Webtop::Toolbox->new(); my $client = $tb->getClient(); my %cookies = CGI::Cookie->fetch; my $imageDirectory = "LocalWebLib/OEM/1"; my $db = $tb->getWebtopDbWriter(); my $conf = new Config::General("/usr/local/positive/conf/PosPerl.conf"); my %config = $conf->getall; my( $sessionId, $sessionHash ) = "0"; my $minKeySize = 1; my $ERR100 = "ERROR: An unknown internal error has occurred."; my $ERR101 = "ERROR: Unknown request."; my $raddr = $ENV{'REMOTE_ADDR'}; # # Make certain origin is valid # my $valid = 0; my $referrer = $ENV{'HTTP_REFERER'}; my( @referrerArr ) = split( "/", $referrer ); #for( my $i=0; $inew(); # $md5->add( $fileArr[$0] . "\n" ); # my $digest = $md5->hexdigest(); # # if( $digest eq $config{'webtopReferrer'} ) { # $valid = 1; # last; # } # } #} #warn "$config{'webtopRelease'}:$raddr:Pos/Webtop/webtopFormBuilder.pm:Bad referrer\n" && signOut() unless( $valid ); warn "$config{'webtopRelease'}:$raddr:Pos/Webtop/webtopFormBuilder.pm:Bad referrer\n" unless( $valid ); # # # sub new { my $this = shift; my $class = ref($this) || $this; my $self = {}; bless($self,$class); return $self; } # # Begin utilities # sub getClientSessionId { my $clientSessionId = $client->getSessionId(); if( ! length( $clientSessionId ) ) { ( $clientSessionId ) = $db->query( sql=> " SELECT client_session_id FROM client_sessions WHERE rawip32_to_dotted_quad(public_ip_address) = '$raddr' AND client_session_type_id IN (1,4) " ); } return( $clientSessionId ); } sub getCustomerId { my $customerId = $client->getCustomerId(); if( ! defined( $customerId ) ) { my $userId = getUserId(); ( $customerId ) = $db->query( sql=> "SELECT customer_id FROM users AS u JOIN groups AS g ON g.group_id = u.group_id WHERE user_id = $userId "); } fatal( issue=> "getCustomerId(): No customerId " ) unless( length( $customerId ) ); return( $customerId ); } sub getUserId { my $userId = $client->getUserId(); my $sql; if( ! length( $userId ) ) { #my $clientSessionId = $client->getSessionId(); my $clientSessionId = getClientSessionId(); if( length( $clientSessionId ) ) { $sql = "SELECT user_id FROM client_sessions WHERE client_session_id = " . $clientSessionId . " AND client_session_type_id IN (1,4)"; } else { $sql = "SELECT user_id FROM client_sessions WHERE rawip32_to_dotted_quad(public_ip_address) = '$raddr' AND client_session_type_id IN (1,4)"; } ($userId) = $db->query( sql=> $sql ); } fatal( issue=> "getUserId(): No userId" ) unless( length( $userId ) ); return( $userId ); } sub getUserName { my $userId = getUserId(); my( $userName ) = $db->query( sql=> "SELECT user_name FROM users WHERE user_id = $userId" ); fatal( issue=> "getUserName(): No userId" ) unless( length( $userName ) ); return( $userName ); } sub fatal { my($issue) = @{{@_}}{qw/issue/}; warn "ERROR:$config{'webtopRelease'}:$raddr:fatal():$issue\n"; print "Content-Type: text/html\nCache-Control: no-cache\n\n Hmmm, that request appears to be invalid. "; exit(); } sub strim { my($str) = @{{@_}}{qw/str/}; !defined $str and return undef; $str =~ s/^\s+//; $str =~ s/\s+$//; return $str; } sub resetCookies { #my $session_id_cookie = Apache2::Cookie->new($r,-name=>'session_id',-value=>"",-expires=>-1); #my $session_hash_cookie = Apache2::Cookie->new($r,-name=>'session_hash',-value=>"",-expires=>-1); #my $oem_id_cookie = Apache2::Cookie->new($r,-name=>'oem_id',-value=>"",-expires=>-1); #my $user_id_cookie = Apache2::Cookie->new($r,-name=>'guid',-value=>"",-expires=>-1); #my $user_name_cookie = Apache2::Cookie->new($r,-name=>'un',-value=>"",-expires=>-1); #$session_id_cookie->bake($r); #$session_hash_cookie->bake($r); #$oem_id_cookie->bake($r); ##$user_id_cookie->bake($r); #$user_name_cookie->bake($r); } # # End utilities # sub showHeader { shift; my( $request, $mode, $isCorporate ) = @{{@_}}{qw/request mode isCorporate/}; $isCorporate = 0 unless( defined( $isCorporate ) && length( $isCorporate ) ); my ( $key, $kkey ) = "BAD"; my $pos = length( $config{'webtopLanding'} ); my $page = substr( $request, 0, $pos ); if( pageOkay( page=> $page ) ) { $key = substr( $request, $pos ); $kkey = $key; $key = "NR" unless( length( $key ) > $minKeySize ); } else { signOutNow( request=> $config{'webtopSignoff'} ); } print "Content-Type: text/html\nCache-Control: no-cache\n\n $config{'webtopRelease'}
"; showBranding( mode=> $mode ); showBreadCrumb( mode=> $mode, isCorporate=>$isCorporate ); } sub showBranding { my( $mode ) = @{{@_}}{qw/mode/}; my $tempKey = reverse( $config{'webtopSignoff'} ); my $userName = getUserName(); print "

"; if( length( $mode ) ) { print "

"; } print "
"; if( length( $mode ) == 0 ) { print " "; } print "
"; } sub showBreadCrumb { my( $mode, $isCorporate ) = @{{@_}}{qw/mode isCorporate/}; $mode = 0 unless( defined( $mode ) && length( $mode ) ); return() unless( $mode == 1 ); print "
"; if( ! $isCorporate ) { print " "; } print "
"; } sub init { shift; my($request, $data) = @{{@_}}{qw/request data/}; my $pos = length( $config{'webtopLanding'} ); my $page = substr( $request, 0, $pos ); my ( $key, $kkey ) = "BAD"; my $rv = ""; $data = "" unless( defined( $data ) ); if( pageOkay( page=> $page ) ) { $key = substr( $request, $pos ); $kkey= $key; $key = "NR" unless( length( $key ) > $minKeySize ); } else { signOutNow( request=> $config{'webtopSignoff'} ); } if( $page eq $config{'webtopDeleteBookmark'} ) { $rv = deleteBookmark( key=> $key, data=> $data ); } elsif( $page eq $config{'webtopSaveBookmark'} ) { $rv = saveBookmark( key=> $key, data=> $data ); } elsif( $page eq $config{'webtopDeleteBookmarkGroup'} ) { $rv = deleteBookmarkGroup( key=> $key, data=> $data ); } elsif( $page eq $config{'webtopSaveBookmarkGroup'} ) { $rv = saveBookmarkGroup( key=> $key, data=> $data ); } elsif( $page eq $config{'webtopDeleteFileshare'} ) { $rv = deleteFileShare( key=> $key, data=> $data ); } elsif( $page eq $config{'webtopSaveFileshare'} ) { $rv = saveFileShare( key=> $key, data=> $data ); } elsif( $page eq $config{'webtopSaveCaptivePortalized'} ) { $rv = saveCaptivePortalized( key=> $key, data=> $data ); } elsif( $page eq $config{'webtopSavePassword'} ) { $rv = savePassword( key=> $key, data=> $data ); } else { $rv = $ERR101; } return( ${rv} ); } sub deleteBookmark { my($key, $data) = @{{@_}}{qw/key data/}; my $rc = 0; my $rv = $ERR100; my $buf = URI::Escape::uri_unescape($data); my $decoded = HTML::Entities::decode($buf); my @pairArr = split( ",", $decoded ); my $bookmarkCategoryId = 0; my $oldBookmarkCategoryId = 0; my $bookmarkName = ""; my $categoryName = ""; foreach my $pair( @pairArr ) { my $buf = $pair; $buf =~ s/{//; $buf =~ s/}//; my @cell = split( ";", $buf ); if( index( $cell[0], "ba0" ) == 0 ) { $bookmarkCategoryId = strim( str=> $cell[1] ); } elsif( index( $cell[0], "bb0" ) == 0 ) { $oldBookmarkCategoryId = strim( str=> $cell[1] ); } elsif( index( $cell[0], "bc0" ) == 0 ) { $categoryName = strim( str=> $cell[1] ); } elsif( index( $cell[0], "bd0" ) == 0 ) { $bookmarkName = strim( str=> $cell[1] ); if( $bookmarkCategoryId != $oldBookmarkCategoryId ) { $rv = "ERROR: Cannot delete, \"Group Name\" changed."; next; } my( @arr ) = {}; push( @arr, 'bookmark' . ';' . $categoryName . ';' . $bookmarkName ); my $intranet = Pos::Webtop::Web::ContentModule::Intranet->new(); $rc = $intranet->manageRemoveThings( things=>\@arr, isAPI=> 1 ); if( $rc == 1 ) { $rv = "OK"; } } } return( $rv ); } sub saveBookmark { my($key, $data) = @{{@_}}{qw/key data/}; my $rc = 0; my $rv = $ERR100; my $buf = URI::Escape::uri_unescape($data); my $decoded = HTML::Entities::decode($buf); my @pairArr = split( ",", $decoded ); my $bookmarkCategoryId = 0; my $oldBookmarkCategoryId = 0; my $bookmarkId = 0; my $bookmarkName = "", my $bookmarkUrl = ""; foreach my $pair( @pairArr ) { my $buf = $pair; $buf =~ s/{//; $buf =~ s/}//; my @cell = split( ";", $buf ); if( index( $cell[0], "ba0" ) == 0 ) { $bookmarkId = strim( str=> $cell[1] ); } elsif( index( $cell[0], "bb0" ) == 0 ) { $bookmarkCategoryId = strim( str=> $cell[1] ); } elsif( index( $cell[0], "bc0" ) == 0 ) { $oldBookmarkCategoryId = strim( str=> $cell[1] ); } elsif( index( $cell[0], "bd0" ) == 0 ) { $bookmarkName = strim( str=> $cell[1] ); } elsif( index( $cell[0], "be0" ) == 0 ) { $bookmarkUrl = strim( str=> $cell[1] ); my $intranet = Pos::Webtop::Web::ContentModule::Intranet->new(); if( $bookmarkId == 0 ) { $rc = $intranet->manageCreateBookmark( bookmarkName=> $bookmarkName, bookmarkUrl=> $bookmarkUrl, bookmarkCategory=> $bookmarkCategoryId, isAPI=> 1 ); } else { $rc = $intranet->updateBookmark( categoryId=> $bookmarkCategoryId, oldCategoryId=> $oldBookmarkCategoryId, bookmarkId=> $bookmarkId, bookmarkName=> $bookmarkName, bookmarkUrl=> $bookmarkUrl ); } if( $rc == 0 ) { $rv = "ERROR:Bookmark \"$bookmarkName\" already exists."; } elsif( $rc == 1 ) { $rv = "OK"; } } } return( $rv ); } sub deleteBookmarkGroup { my($key, $data) = @{{@_}}{qw/key data/}; my $rc = 0; my $rv = $ERR100; my $buf = URI::Escape::uri_unescape($data); my $decoded = HTML::Entities::decode($buf); my @pairArr = split( ",", $decoded ); my $categoryName = ""; my $oldCategoryName = ""; foreach my $pair( @pairArr ) { my $buf = $pair; $buf =~ s/{//; $buf =~ s/}//; my @cell = split( ";", $buf ); if( index( $cell[0], "bga0" ) == 0 ) { $categoryName = strim( str=> $cell[1] ); } elsif( index( $cell[0], "bgb0" ) == 0 ) { $oldCategoryName = strim( str=> $cell[1] ); if( $categoryName ne $oldCategoryName ) { $rv = "ERROR: Cannot delete, \"Group Name\" changed."; next; } my( @arr ) = {}; push( @arr, 'category' . ';' . $categoryName . ';' . $oldCategoryName ); my $intranet = Pos::Webtop::Web::ContentModule::Intranet->new(); $rc = $intranet->manageRemoveThings( things=>\@arr, isAPI=> 1 ); if( $rc == 1 ) { $rv = "OK"; } } } return( $rv ); } sub saveBookmarkGroup { my($key, $data) = @{{@_}}{qw/key data/}; my $rc = 0; my $rv = $ERR100; my $buf = URI::Escape::uri_unescape($data); my $decoded = HTML::Entities::decode($buf); my @pairArr = split( ",", $decoded ); my $categoryId = 0; my $categoryName = ""; foreach my $pair( @pairArr ) { my $buf = $pair; $buf =~ s/{//; $buf =~ s/}//; my @cell = split( ";", $buf ); if( index( $cell[0], "bga0" ) == 0 ) { $categoryId = strim( str=> $cell[1] ); } elsif( index( $cell[0], "bgb0" ) == 0 ) { $categoryName = strim( str=> $cell[1] ); my $intranet = Pos::Webtop::Web::ContentModule::Intranet->new(); if( $categoryId == 0 ) { $rc = $intranet->manageCreateCategory( categoryName=> $categoryName, isAPI=> 1 ); } else { $rc = $intranet->updateCategory( categoryId=> $categoryId, categoryName=> $categoryName ); } if( $rc == 0 ) { $rv = "ERROR:Group name \"$categoryName\" already exists."; } elsif( $rc == 1 ) { $rv = "OK"; } } } return( $rv ); } sub deleteFileShare { my($key, $data) = @{{@_}}{qw/key data/}; my $rc = 0; my $rv = $ERR100; my $buf = URI::Escape::uri_unescape($data); my $decoded = HTML::Entities::decode($buf); my @pairArr = split( ",", $decoded ); my $fileServerId = 0; my $fileShareId = 0; foreach my $pair( @pairArr ) { my $buf = $pair; $buf =~ s/{//; $buf =~ s/}//; my @cell = split( ";", $buf ); if( index( $cell[0], "fa0" ) == 0 ) { $fileServerId = strim( str=> $cell[1] ); } elsif( index( $cell[0], "fb0" ) == 0 ) { $fileShareId = strim( str=> $cell[1] ); my( $fileserverHostname ) = $db->query( sql=> " SELECT fileserver_hostname FROM w_smb_fileservers WHERE fileserver_id = $fileServerId " ); my( $fileshareName ) = $db->query( sql=> " SELECT fileshare_name FROM w_smb_fileshares WHERE fileshare_id = $fileShareId " ); if( length( $fileserverHostname ) && length( $fileshareName ) ) { my $networkPath = "\\\\" .$fileserverHostname . "\\" . $fileshareName; my $userId = getUserId(); my( $cnt ) = $db->query( sql=> " SELECT COUNT(1) FROM netresource_auth_cache WHERE user_id = $userId AND network_path = '\\\\\\\\" . $db->escape( dirty => $fileserverHostname ) . "\\\\" . $db->escape( dirty => $fileshareName ) . "' " ); if( $cnt ) { $db->do( sql=> " DELETE FROM netresource_auth_cache WHERE user_id = $userId AND network_path = '\\\\\\\\" . $db->escape( dirty => $fileserverHostname ) . "\\\\" . $db->escape( dirty => $fileshareName ) . "' " ); $db->commit(); $rv = "OK"; } else { $rv = "ERROR:Nothing to delete."; } } else { $rv = "ERROR:Cannot locate server and sharename."; } } } return( $rv ); } sub saveFileShare { my($key, $data) = @{{@_}}{qw/key data/}; my $rc = 0; my $rv = $ERR100; my $buf = URI::Escape::uri_unescape($data); my $decoded = HTML::Entities::decode($buf); my @pairArr = split( ",", $decoded ); my $fileServerId = 0; my $fileShareId = 0; my $oldFileServerId = 0; my $oldFileShareId = 0; my $serverName = ""; my $shareName = ""; my $dirtyServerName = ""; my $dirtyShareName = ""; my $remoteAddr = ""; my $oldRemoteAddr = ""; my $oldServerName = ""; my $oldShareName = ""; my $userName = ""; my $password = ""; my $newFileServerId = 0; my $customerId = getCustomerId(); my $userId = getUserId(); foreach my $pair( @pairArr ) { my $buf = $pair; $buf =~ s/{//; $buf =~ s/}//; my @cell = split( ";", $buf ); if( index( $cell[0], "fa0" ) == 0 ) { $fileServerId = strim( str=> $cell[1] ); } elsif( index( $cell[0], "fb0" ) == 0 ) { $fileShareId = strim( str=> $cell[1] ); } elsif( index( $cell[0], "fc0" ) == 0 ) { $remoteAddr = strim( str=> $cell[1] ); my( @work ) = split( "\\\\", $remoteAddr ); $remoteAddr = $db->escape( dirty => "$remoteAddr" ); $serverName = strim( str=> $work[2] ); $dirtyServerName = $db->escape( dirty => $serverName ); $shareName = strim( str=> $work[3] ); $dirtyShareName = $db->escape( dirty => $shareName ); ( $oldFileServerId ) = $db->query( sql=> " SELECT fileserver_id FROM w_smb_fileservers WHERE fileserver_hostname = '$dirtyServerName' AND customer_id = $customerId " ); $oldFileServerId = 0 unless( $oldFileServerId > 0 ); $oldServerName = $dirtyServerName unless( $oldFileServerId == 0 ); if( $fileServerId == 0 && $oldFileServerId == 0 ) { $fileServerId = $db->getNextSequenceValue(sequence => "w_smb_fileservers_pk"); $db->do( sql => " INSERT INTO w_smb_fileservers (fileserver_id, customer_id, fileserver_hostname, display_name) VALUES ($fileServerId, $customerId, '$dirtyServerName', '$dirtyServerName') "); $newFileServerId = 1; } elsif( $fileServerId > 0 && ( $fileServerId == $oldFileServerId ) ) { $db->do( sql=> " UPDATE w_smb_fileservers SET fileserver_hostname = '$dirtyServerName', display_name = '$dirtyServerName' WHERE fileserver_id = $fileServerId AND customer_id = $customerId " ); } elsif( $fileServerId > 0 && ( $fileServerId != $oldFileServerId ) ) { $rv = "ERROR:Server name \"$dirtyServerName\" cannot be re-used."; last; } ( $oldFileShareId ) = $db->query( sql=> " SELECT fileshare_id FROM w_smb_fileshares WHERE fileshare_name = '$dirtyShareName' AND fileserver_id = $oldFileServerId " ); if( $fileShareId > 0 && $oldFileShareId == 0 ) { $oldFileShareId = $fileShareId; } $oldFileShareId = 0 unless( $oldFileShareId > 0 ); $oldShareName = $dirtyShareName unless( $oldFileShareId == 0 ); if( $fileShareId == 0 && $oldFileShareId == 0 ) { $fileShareId = $db->getNextSequenceValue( sequence => "w_smb_fileshares_pk"); my $thisFileServerId = 0; if( $newFileServerId ) { $thisFileServerId = $fileServerId; } else { $thisFileServerId = $oldFileServerId; } $db->do( sql => " INSERT INTO w_smb_fileshares (fileshare_id, fileserver_id, fileshare_name) VALUES ($fileShareId, $thisFileServerId, '$dirtyShareName') " ); $db->do( sql => " INSERT INTO w_smb_fileshare_users (fileshare_id, user_id) VALUES ($fileShareId, $userId) " ); $db->commit(); } elsif( $fileShareId > 0 && ( $fileServerId == $oldFileServerId ) && ( $fileShareId == $oldFileShareId ) ) { $db->do( sql=> " UPDATE w_smb_fileshares SET fileshare_name = '$dirtyShareName' WHERE fileshare_id = $fileShareId AND fileserver_id = $fileServerId " ); $db->commit(); } elsif( $fileServerId > 0 && $oldFileServerId > 0 && $fileShareId > 0 && $oldFileShareId > 0 && ( ( $fileServerId == $oldFileServerId ) && ( $fileShareId != $oldFileShareId ) ) ) { $rv = "ERROR:Fileshare name \"$dirtyShareName\" cannot be re-used."; last; } elsif( $fileServerId == 0 && $oldFileServerId > 0 && $fileShareId == 0 && $oldFileShareId > 0 ) { $rv = "ERROR:Fileshare name \"$dirtyShareName\" cannot be re-used."; last; } } elsif( index( $cell[0], "fd0" ) == 0 ) { $userName = strim( str=> $cell[1] ); } elsif( index( $cell[0], "fe0" ) == 0 ) { $password = strim( str=> $cell[1] ); my $dirtyPassword = $db->escape( dirty => $password ); my $dirtyUserName = $db->escape( dirty => $userName); my $exists = 0; if( length( $oldServerName ) && length( $oldShareName ) ) { $oldRemoteAddr = "\\\\$oldServerName\\$oldShareName"; my( $cnt ) = $db->query( sql=> " SELECT COUNT(network_path) FROM netresource_auth_cache WHERE user_id = $userId AND network_path = '" . $db->escape( dirty=> "$oldRemoteAddr" ) . "' " ); $exists = 1 unless( $cnt == 0 ); } if( $exists && length( $dirtyUserName ) && length( $dirtyPassword ) ) { $db->do( sql=> " UPDATE netresource_auth_cache SET network_path = '$remoteAddr', net_user = '$dirtyUserName', net_pass = '$dirtyPassword' WHERE network_path = '$oldRemoteAddr' AND user_id = $userId " ); } else { $db->do( sql=> " INSERT INTO netresource_auth_cache (user_id, network_path, net_user, net_pass) VALUES ($userId, '$remoteAddr', '$dirtyUserName', '$dirtyPassword') " ); } $db->commit(); $rv = "OK"; } } return( $rv ); } sub saveCaptivePortalized { my($key, $data) = @{{@_}}{qw/key data/}; my $rc = 0; my $rv = $ERR100; my $buf = URI::Escape::uri_unescape($data); my $decoded = HTML::Entities::decode($buf); my @pairArr = split( ",", $decoded ); my $clientSessionId = getClientSessionId(); foreach my $pair( @pairArr ) { my $buf = $pair; $buf =~ s/{//; $buf =~ s/}//; my @cell = split( ";", $buf ); if( index( $cell[0], "soma0" ) == 0 ) { my $captivePortalized = strim( str=> $cell[1] ); $db->do( sql=> "UPDATE client_sessions SET captive_portalized=$captivePortalized WHERE client_session_id=$clientSessionId" ); $db->commit(); $rv = "OK"; } } return( $rv ); } sub savePassword { my($key, $data) = @{{@_}}{qw/key data/}; my $rc = 0; my $rv = $ERR100; my $currentPwd; my $newPwd; my $confirmPwd; my $buf = URI::Escape::uri_unescape($data); my $decoded = HTML::Entities::decode($buf); my @pairArr = split( ",", $decoded ); my $userId = getUserId(); foreach my $pair( @pairArr ) { my $buf = $pair; $buf =~ s/{//; $buf =~ s/}//; my @cell = split( ";", $buf ); if( index( $cell[0], "pwa0" ) == 0 ) { $currentPwd = $cell[1]; } elsif( index( $cell[0], "pwb0" ) == 0 ) { $newPwd = $cell[1]; } elsif( index( $cell[0], "pwc0" ) == 0 ) { $confirmPwd = $cell[1]; $rv = checkPassword( currentPwd=> $currentPwd, newPwd=> $newPwd, confirmPwd=> $confirmPwd ); if( $rv eq "OK" ) { my( $authTypeName ) = $db->query( sql => " SELECT UPPER( auth_type_name ) FROM user_auth_types AS uat JOIN auth_types AS at ON uat.auth_type_id = at.auth_type_id WHERE user_id = $userId " ); $rv = "ERROR: Password change failed."; if( $authTypeName eq 'STANDARD' || $authTypeName eq 'PHONEFACTOR - STANDARD') { $db->do( sql => " UPDATE users SET password = MD5('${newPwd}'), last_password_reset = NOW(), ext_password_expired = '0' WHERE user_id = $userId " ); $db->commit(); $rv = "OK"; } elsif( $authTypeName eq 'NTLM' || $authTypeName eq 'PHONEFACTOR - NTLM') { my $ntlmExec = "/usr/local/positive/Binary/ChangeNtlmPassword"; my $cmd; my $rc; $currentPwd =~ s/(\W)/\\$1/g; $newPwd =~ s/(\W)/\\$1/g; my $oldPath = $ENV{'PATH'}; my $oldLd = $ENV{'LD_LIBRARY_PATH'}; $ENV{'PATH'} = '/usr/local/bin:/usr/bin:/bin'; $ENV{'LD_LIBRARY_PATH'} = "/usr/local/positive/Library"; "$ntlmExec $userId $currentPwd $newPwd" =~ /^(.*)$/; warn "running: $1\n"; open( RAD, $1 ); $rc = ; close(RAD); chomp( $rc ); $rv =~ s/(\d+)/$1/g; $ENV{'PATH'} = $oldPath; $ENV{'LD_LIBRARY_PATH'} = $oldLd; if($rc == 0) { $rv = "OK"; } } } } } return( $rv ); } # # Password validations # sub checkPassword { my($currentPwd, $newPwd, $confirmPwd) = @{{@_}}{qw/currentPwd newPwd confirmPwd/}; my $complexity = getPasswordComplexity(); my $rv = "OK"; my $rc = 0; foreach my $key ( keys %{ $complexity } ) { my( $required, $message, $method ) = @{ $complexity->{$key} }; next unless( $required ); my $rc = &{\&{$method}}( currentPwd=> $currentPwd, newPwd=> $newPwd, confirmPwd=> $confirmPwd ); if( ! $rc ) { $rv = $message; last; } } return( $rv ); } sub getPasswordComplexity { my $userId = getUserId(); my $hash = {}; my( @complexity ) = $db->query( sql => " SELECT 1 AS eight_characters, one_number, upper_lower_case, non_alpha_numeric, 1 AS password_must_differ FROM user_auth_requirements WHERE user_id = $userId " ); $hash->{'ol_oldpass'} = [ 1, "ERROR: Current password is incorrect.", "validateOldPassword" ]; $hash->{'ne_match'} = [ 1, "ERROR: New and confirmed passwords do not match.", "validatePasswordMatch" ]; $hash->{'at_eight'} = [ 1, "ERROR: Password must be at least 8 characters.", "validatePasswordEightCharacters" ]; $hash->{'di_mustdiffer'}= [ 1, "ERROR: Password cannot be reused.", "validatePasswordNotReused" ]; $hash->{'bd_password'} = [ 1, "ERROR: Password is too weak.", "validatePasswordStrength" ]; if( scalar( @complexity ) ) { $hash->{'at_digit'} = [ $complexity[0]->[1],"ERROR: Password must contain at least 1 digit.", "validatePasswordOneNumber" ]; $hash->{'up_upperlowercase'} = [ $complexity[0]->[2],"ERROR: Password must be lower and upper case.", "validatePasswordMixedCase" ]; $hash->{'at_nonalphanum'} = [ $complexity[0]->[3],"ERROR: Password must contain a special character.","validatePasswordAlphaNumeric" ]; } return $hash; } sub validateNoop { return 1; } sub validatePasswordEightCharacters { my ($currentPwd, $newPwd) = @{{@_}}{qw/currentPwd newPwd/}; return( length( $newPwd ) >= 8 ); } sub validatePasswordOneNumber { my ($currentPwd, $newPwd) = @{{@_}}{qw/currentPwd newPwd/}; return( $newPwd =~ /\d/ ); } sub validatePasswordMixedCase { my ($currentPwd, $newPwd) = @{{@_}}{qw/currentPwd newPwd/}; return( ( $newPwd =~ /[A-Z]/) && ( $newPwd =~ /[a-z]/ ) ); } sub validatePasswordAlphaNumeric { my ($currentPwd, $newPwd) = @{{@_}}{qw/currentPwd newPwd/}; return( $newPwd =~ /\W/ ); } sub validatePasswordNotReused { my ($currentPwd, $newPwd) = @{{@_}}{qw/currentPwd newPwd/}; my $rc = 0; if( "$currentPwd" ne "$newPwd" ) { $rc = 1; } return( $currentPwd ne $newPwd ); } sub validatePasswordMatch { my ($newPwd, $confirmPwd) = @{{@_}}{qw/newPwd confirmPwd/}; my $rc = 0; if( "$newPwd" eq "$confirmPwd" ) { $rc = 1; } return( $rc ); } sub validateOldPassword { my( $currentPwd ) = @{{@_}}{qw/currentPwd/}; #my $hashPwd = Digest::MD5::md5_hex( $currentPwd ); my $userId = getUserId(); my( $cnt ) = $db->query(sql => " SELECT COUNT(1) FROM users WHERE UPPER(password) = UPPER(MD5('$currentPwd')) AND user_id = $userId " ); return( $cnt ); } sub validatePasswordStrength { my( $newPwd ) = @{{@_}}{qw/newPwd/}; my( @list ) = split( ";", $config{'webtopBadPassword'} ); my $rc = 1; foreach my $value ( @list ) { if( lc( "$newPwd" ) eq lc( "$value" ) ) { $rc = 0; last; } } if( $rc ) { if( lc( $newPwd ) =~ m/password/ ) { $rc = 0; } } return( $rc ); } # # End # sub signOutNow { my($request) = @{{@_}}{qw/request/}; my $pos = length( $config{'webtopLanding'} ); my $page = substr( $request, 0, $pos ); fatal( issue=> "signOutNow(): Bad request $request" ) unless $request eq $config{'webtopSignoff'}; if( $cookies{'session_id'} ) { my $sessionIdEncoded = $cookies{'session_id'}->value; $sessionId = MIME::Base64::decode_base64( $sessionIdEncoded ); if( length( $sessionId ) && ( $sessionId =~ /^\d+$/ ) ) { $db->doSproc("admintool_ElnkTerms_239_del", $sessionId); $db->commit; resetCookies(); } else { warn "ERROR:$config{'webtopRelease'}:$raddr:():signOutNow():Failed to sign-out\n"; } } else { warn "ERROR:$config{'webtopRelease'}:$raddr:():signOutNow():Hmmm, no valid sessionId\n"; } showSignIn(); } sub signOut { shift; my($request) = @{{@_}}{qw/request/}; my $pos = length( $config{'webtopLanding'} ); my $page = substr( $request, 0, $pos ); fatal( issue=> "signOut(): Bad request $request" ) unless $request eq $config{'webtopSignoff'}; if( $cookies{'session_id'} ) { my $sessionIdEncoded = $cookies{'session_id'}->value; $sessionId = MIME::Base64::decode_base64( $sessionIdEncoded ); if( length( $sessionId ) && ( $sessionId =~ /^\d+$/ ) ) { $db->doSproc("admintool_ElnkTerms_239_del", $sessionId); $db->commit; resetCookies(); } else { warn "ERROR:$config{'webtopRelease'}:$raddr:():signOut():Failed to sign-out\n"; } } else { warn "ERROR:$config{'webtopRelease'}:$raddr:():signOut():Hmmm, no valid sessionId\n"; } showSignIn(); } sub showSignIn { print "Content-Type: text/html\nCache-Control: no-cache\n\n "; } sub pageOkay { my($page) = @{{@_}}{qw/page/}; my $rc = 0; my( @pageArr ) = ($config{'webtopSignoff'},$config{'webtopTimedout'},$config{'webtopLanding'},$config{'webtopNetconDownload'},$config{'webtopVPNDownload'},$config{'webtopSaveBookmark'},$config{'webtopSaveBookmarkGroup'},$config{'webtopSaveFileshare'},$config{'webtopDeleteBookmark'},$config{'webtopDeleteBookmarkGroup'},$config{'webtopDeleteFileshare'},$config{'webtopSaveCaptivePortalized'},$config{'webtopSavePassword'},$config{'webtopShowFileShare'}); foreach my $val ( @pageArr ) { if( $page eq $val ) { $rc = 1; next; } } warn "ERROR:$config{'webtopRelease'}:$raddr:():pageOkay():Invalid page $page" unless( $rc == 1 ); return( $rc ); } sub showFooter { shift; my($content) = @{{@_}}{qw/content/}; $content = "" unless( length( $content ) ); if( length( $content ) ) { print " "; } my( $tunnelName ) = $db->query( sql=> " SELECT tunnel_name FROM client_sessions WHERE user_id = " . getUserId() . " AND client_session_type_id IN (1,4) " ); my $docImg = "LocalWebLib/mime_document32-1.svg"; my $profileImg = "LocalWebLib/mime_tcpip_profile32.svg"; print "
"; } 1;