2013-06-14 13:51:44 +02:00
|
|
|
<?php
|
2015-02-04 10:46:36 +01:00
|
|
|
/* Icinga Web 2 | (c) 2013-2015 Icinga Development Team | GPLv2+ */
|
2013-06-14 13:51:44 +02:00
|
|
|
|
|
|
|
# namespace Icinga\Application\Controllers;
|
|
|
|
|
2014-03-03 17:21:17 +01:00
|
|
|
use Icinga\Application\Config;
|
2014-12-29 14:30:47 +01:00
|
|
|
use Icinga\Application\Icinga;
|
2014-10-31 10:27:17 +01:00
|
|
|
use Icinga\Application\Logger;
|
2014-12-29 14:30:47 +01:00
|
|
|
use Icinga\Authentication\AuthChain;
|
2015-01-27 13:45:13 +01:00
|
|
|
use Icinga\Authentication\Backend\ExternalBackend;
|
2014-06-02 15:47:21 +02:00
|
|
|
use Icinga\Exception\AuthenticationException;
|
2014-03-03 17:21:17 +01:00
|
|
|
use Icinga\Exception\ConfigurationError;
|
2014-12-29 14:30:47 +01:00
|
|
|
use Icinga\Exception\NotReadableError;
|
|
|
|
use Icinga\Forms\Authentication\LoginForm;
|
2014-03-03 17:21:17 +01:00
|
|
|
use Icinga\User;
|
2014-12-29 14:30:47 +01:00
|
|
|
use Icinga\Web\Controller\ActionController;
|
2014-03-06 12:07:24 +01:00
|
|
|
use Icinga\Web\Url;
|
2013-07-12 16:10:56 +02:00
|
|
|
|
2013-06-14 13:51:44 +02:00
|
|
|
/**
|
2013-08-16 14:56:23 +02:00
|
|
|
* Application wide controller for authentication
|
2013-06-14 13:51:44 +02:00
|
|
|
*/
|
|
|
|
class AuthenticationController extends ActionController
|
|
|
|
{
|
|
|
|
/**
|
2014-01-23 16:03:47 +01:00
|
|
|
* This controller does not require authentication
|
2013-08-16 14:56:23 +02:00
|
|
|
*
|
2013-06-14 13:51:44 +02:00
|
|
|
* @var bool
|
|
|
|
*/
|
2013-08-30 15:50:49 +02:00
|
|
|
protected $requiresAuthentication = false;
|
2013-06-14 13:51:44 +02:00
|
|
|
|
|
|
|
/**
|
2013-08-16 14:56:23 +02:00
|
|
|
* Log into the application
|
2013-06-14 13:51:44 +02:00
|
|
|
*/
|
|
|
|
public function loginAction()
|
|
|
|
{
|
2014-12-29 14:30:06 +01:00
|
|
|
$icinga = Icinga::app();
|
|
|
|
if ($icinga->setupTokenExists() && $icinga->requiresSetup()) {
|
2014-11-18 13:13:02 +01:00
|
|
|
$this->redirectNow(Url::fromPath('setup'));
|
2014-09-10 14:48:33 +02:00
|
|
|
}
|
|
|
|
|
2015-01-27 14:26:06 +01:00
|
|
|
$triedOnlyExternalAuth = null;
|
2014-06-22 20:08:55 +02:00
|
|
|
$auth = $this->Auth();
|
2014-08-19 10:14:46 +02:00
|
|
|
$this->view->form = $form = new LoginForm();
|
2014-05-27 23:47:13 +02:00
|
|
|
$this->view->title = $this->translate('Icingaweb Login');
|
2014-03-28 14:45:03 +01:00
|
|
|
|
2013-06-24 18:46:45 +02:00
|
|
|
try {
|
2014-08-19 10:14:46 +02:00
|
|
|
$redirectUrl = $this->view->form->getValue('redirect');
|
|
|
|
if ($redirectUrl) {
|
|
|
|
$redirectUrl = Url::fromPath($redirectUrl);
|
|
|
|
} else {
|
|
|
|
$redirectUrl = Url::fromPath('dashboard');
|
|
|
|
}
|
2014-06-03 17:59:22 +02:00
|
|
|
|
2013-06-24 18:46:45 +02:00
|
|
|
if ($auth->isAuthenticated()) {
|
2014-06-22 20:06:45 +02:00
|
|
|
$this->rerenderLayout()->redirectNow($redirectUrl);
|
2013-06-24 18:46:45 +02:00
|
|
|
}
|
2014-03-28 14:45:03 +01:00
|
|
|
|
2014-06-03 17:59:22 +02:00
|
|
|
try {
|
|
|
|
$config = Config::app('authentication');
|
|
|
|
} catch (NotReadableError $e) {
|
|
|
|
throw new ConfigurationError(
|
2014-11-13 15:41:31 +01:00
|
|
|
$this->translate('Could not read your authentication.ini, no authentication methods are available.'),
|
2014-08-20 13:13:50 +02:00
|
|
|
0,
|
|
|
|
$e
|
2014-06-03 17:59:22 +02:00
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
$chain = new AuthChain($config);
|
2014-07-18 10:23:04 +02:00
|
|
|
$request = $this->getRequest();
|
|
|
|
if ($request->isPost() && $this->view->form->isValid($request->getPost())) {
|
2014-06-02 14:04:45 +02:00
|
|
|
$user = new User($this->view->form->getValue('username'));
|
|
|
|
$password = $this->view->form->getValue('password');
|
2014-03-03 17:21:17 +01:00
|
|
|
$backendsTried = 0;
|
2014-03-28 14:45:03 +01:00
|
|
|
$backendsWithError = 0;
|
2014-06-03 17:59:22 +02:00
|
|
|
|
2014-08-19 10:14:46 +02:00
|
|
|
$redirectUrl = $form->getValue('redirect');
|
|
|
|
|
|
|
|
if ($redirectUrl) {
|
|
|
|
$redirectUrl = Url::fromPath($redirectUrl);
|
|
|
|
} else {
|
|
|
|
$redirectUrl = Url::fromPath('dashboard');
|
|
|
|
}
|
|
|
|
|
2014-03-03 17:21:17 +01:00
|
|
|
foreach ($chain as $backend) {
|
2015-01-27 13:45:13 +01:00
|
|
|
if ($backend instanceof ExternalBackend) {
|
2014-06-03 17:59:22 +02:00
|
|
|
continue;
|
|
|
|
}
|
2014-06-06 09:33:29 +02:00
|
|
|
++$backendsTried;
|
2014-06-02 15:47:21 +02:00
|
|
|
try {
|
|
|
|
$authenticated = $backend->authenticate($user, $password);
|
|
|
|
} catch (AuthenticationException $e) {
|
|
|
|
Logger::error($e);
|
|
|
|
++$backendsWithError;
|
|
|
|
continue;
|
|
|
|
}
|
2014-03-28 14:45:03 +01:00
|
|
|
if ($authenticated === true) {
|
|
|
|
$auth->setAuthenticated($user);
|
2014-06-22 20:06:45 +02:00
|
|
|
$this->rerenderLayout()->redirectNow($redirectUrl);
|
2014-03-03 17:21:17 +01:00
|
|
|
}
|
|
|
|
}
|
2014-07-09 12:53:25 +02:00
|
|
|
if ($backendsTried === 0) {
|
2014-11-12 16:23:55 +01:00
|
|
|
$this->view->form->addError(
|
2014-08-19 18:55:58 +02:00
|
|
|
$this->translate(
|
|
|
|
'No authentication methods available. Did you create'
|
2015-03-11 22:11:10 +01:00
|
|
|
. ' authentication.ini when setting up Icinga Web 2?'
|
2014-08-19 18:55:58 +02:00
|
|
|
)
|
2014-07-09 12:53:25 +02:00
|
|
|
);
|
2014-11-12 16:23:55 +01:00
|
|
|
} else if ($backendsTried === $backendsWithError) {
|
|
|
|
$this->view->form->addError(
|
2014-06-02 15:47:21 +02:00
|
|
|
$this->translate(
|
2014-08-19 18:55:58 +02:00
|
|
|
'All configured authentication methods failed.'
|
2015-03-11 22:11:10 +01:00
|
|
|
. ' Please check the system log or Icinga Web 2 log for more information.'
|
2014-06-02 15:47:21 +02:00
|
|
|
)
|
2014-03-03 17:21:17 +01:00
|
|
|
);
|
2014-11-12 16:23:55 +01:00
|
|
|
} elseif ($backendsWithError) {
|
|
|
|
$this->view->form->addError(
|
2014-06-02 15:47:21 +02:00
|
|
|
$this->translate(
|
2014-09-30 15:59:11 +02:00
|
|
|
'Please note that not all authentication methods were available.'
|
2015-03-11 22:11:10 +01:00
|
|
|
. ' Check the system log or Icinga Web 2 log for more information.'
|
2014-06-02 15:47:21 +02:00
|
|
|
)
|
|
|
|
);
|
|
|
|
}
|
2014-11-12 16:23:55 +01:00
|
|
|
if ($backendsTried > 0 && $backendsTried !== $backendsWithError) {
|
|
|
|
$this->view->form->getElement('password')->addError($this->translate('Incorrect username or password'));
|
|
|
|
}
|
2014-07-18 10:23:04 +02:00
|
|
|
} elseif ($request->isGet()) {
|
2014-07-10 11:15:46 +02:00
|
|
|
$user = new User('');
|
|
|
|
foreach ($chain as $backend) {
|
2015-01-27 14:26:06 +01:00
|
|
|
$triedOnlyExternalAuth = $triedOnlyExternalAuth === null;
|
2015-01-27 13:45:13 +01:00
|
|
|
if ($backend instanceof ExternalBackend) {
|
2014-07-10 11:15:46 +02:00
|
|
|
$authenticated = $backend->authenticate($user);
|
|
|
|
if ($authenticated === true) {
|
|
|
|
$auth->setAuthenticated($user);
|
2014-09-30 15:49:31 +02:00
|
|
|
$this->rerenderLayout()->redirectNow(
|
|
|
|
Url::fromPath(Url::fromRequest()->getParam('redirect', 'dashboard'))
|
|
|
|
);
|
2014-07-10 11:15:46 +02:00
|
|
|
}
|
2015-01-27 14:26:06 +01:00
|
|
|
} else {
|
|
|
|
$triedOnlyExternalAuth = false;
|
2014-07-10 11:15:46 +02:00
|
|
|
}
|
|
|
|
}
|
2013-06-24 18:46:45 +02:00
|
|
|
}
|
2014-02-12 13:57:17 +01:00
|
|
|
} catch (Exception $e) {
|
2015-02-12 09:07:10 +01:00
|
|
|
$this->view->form->addError($e->getMessage());
|
2013-06-24 18:46:45 +02:00
|
|
|
}
|
2014-10-21 16:11:49 +02:00
|
|
|
|
2015-03-11 22:25:52 +01:00
|
|
|
$this->view->requiresExternalAuth = $triedOnlyExternalAuth && ! $auth->isAuthenticated();
|
2014-12-29 14:30:06 +01:00
|
|
|
$this->view->requiresSetup = Icinga::app()->requiresSetup();
|
2013-06-14 13:51:44 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2013-08-16 14:56:23 +02:00
|
|
|
* Log out the current user
|
2013-06-14 13:51:44 +02:00
|
|
|
*/
|
|
|
|
public function logoutAction()
|
|
|
|
{
|
2014-06-22 20:08:55 +02:00
|
|
|
$auth = $this->Auth();
|
2014-10-01 08:13:17 +02:00
|
|
|
if (! $auth->isAuthenticated()) {
|
|
|
|
$this->redirectToLogin();
|
|
|
|
}
|
2014-07-30 12:35:55 +02:00
|
|
|
$isRemoteUser = $auth->getUser()->isRemoteUser();
|
2013-06-24 18:46:45 +02:00
|
|
|
$auth->removeAuthorization();
|
2014-07-30 12:35:55 +02:00
|
|
|
if ($isRemoteUser === true) {
|
2014-02-26 17:36:20 +01:00
|
|
|
$this->_response->setHttpResponseCode(401);
|
|
|
|
} else {
|
2014-10-01 08:13:17 +02:00
|
|
|
$this->redirectToLogin();
|
2014-02-26 17:36:20 +01:00
|
|
|
}
|
2013-06-14 13:51:44 +02:00
|
|
|
}
|
|
|
|
}
|