Cleanup: Updated copyright comments
[Packages/TYPO3.CMS.git] / typo3 / classes / class.ajaxlogin.php
1 <?php
2 /***************************************************************
3 * Copyright notice
4 *
5 * (c) 2008-2010 Christoph Koehler (christoph@webempoweredchurch.org)
6 * All rights reserved
7 *
8 * This script is part of the TYPO3 project. The TYPO3 project is
9 * free software; you can redistribute it and/or modify
10 * it under the terms of the GNU General Public License as published by
11 * the Free Software Foundation; either version 2 of the License, or
12 * (at your option) any later version.
13 *
14 * The GNU General Public License can be found at
15 * http://www.gnu.org/copyleft/gpl.html.
16 * A copy is found in the textfile GPL.txt and important notices to the license
17 * from the author is found in LICENSE.txt distributed with these scripts.
18 *
19 *
20 * This script is distributed in the hope that it will be useful,
21 * but WITHOUT ANY WARRANTY; without even the implied warranty of
22 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
23 * GNU General Public License for more details.
24 *
25 * This copyright notice MUST APPEAR in all copies of the script!
26 ***************************************************************/
27 /**
28 * This is the ajax handler for backend login after timeout.
29 *
30 * @author Christoph Koehler <christoph@webempoweredchurch.org>
31 */
32 class AjaxLogin {
33
34 /**
35 * Handles the actual login process, more specifically it defines the response.
36 * The login details were sent in as part of the ajax request and automatically logged in
37 * the user inside the init.php part of the ajax call. If that was successful, we have
38 * a BE user and reset the timer and hide the login window.
39 * If it was unsuccessful, we display that and show the login box again.
40 *
41 * @param array $parameters: Parameters (not used)
42 * @param TYPO3AJAX $ajaxObj: The calling parent AJAX object
43 * @return void
44 */
45 public function login(array $parameters, TYPO3AJAX $ajaxObj) {
46 if ($GLOBALS['BE_USER']->user['uid']) {
47 $json = array('success' => TRUE);
48 } else {
49 $json = array('success' => FALSE);
50 }
51 $ajaxObj->addContent('login', $json);
52 $ajaxObj->setContentFormat('json');
53 }
54
55 /**
56 * Logs out the current BE user
57 *
58 * @param array $parameters: Parameters (not used)
59 * @param TYPO3AJAX $ajaxObj: The calling parent AJAX object
60 * @return void
61 */
62 public function logout(array $parameters, TYPO3AJAX $ajaxObj) {
63 $GLOBALS['BE_USER']->logoff();
64 if($GLOBALS['BE_USER']->user['uid']) {
65 $ajaxObj->addContent('logout', array('success' => FALSE));
66 } else {
67 $ajaxObj->addContent('logout', array('success' => TRUE));
68 }
69 $ajaxObj->setContentFormat('json');
70 }
71
72 /**
73 * Refreshes the login without needing login information. We just refresh the session.
74 *
75 *
76 * @param array $parameters: Parameters (not used)
77 * @param TYPO3AJAX $ajaxObj: The calling parent AJAX object
78 * @return void
79 */
80 public function refreshLogin(array $parameters, TYPO3AJAX $ajaxObj) {
81 $GLOBALS['BE_USER']->checkAuthentication();
82 $ajaxObj->addContent('refresh', array('success' => TRUE));
83 $ajaxObj->setContentFormat('json');
84 }
85
86
87 /**
88 * Checks if the user session is expired yet
89 *
90 * @param array $parameters: Parameters (not used)
91 * @param TYPO3AJAX $ajaxObj: The calling parent AJAX object
92 * @return void
93 */
94 function isTimedOut(array $parameters, TYPO3AJAX $ajaxObj) {
95 if(is_object($GLOBALS['BE_USER'])) {
96 $ajaxObj->setContentFormat('json');
97 if (@is_file(PATH_typo3conf.'LOCK_BACKEND')) {
98 $ajaxObj->addContent('login', array('timed_out' => FALSE, 'locked' => TRUE));
99 $ajaxObj->setContentFormat('json');
100 } else {
101 $GLOBALS['BE_USER']->fetchUserSession(TRUE);
102 $ses_tstamp = $GLOBALS['BE_USER']->user['ses_tstamp'];
103 $timeout = $GLOBALS['BE_USER']->auth_timeout_field;
104
105 // if 120 seconds from now is later than the session timeout, we need to show the refresh dialog.
106 // 120 is somewhat arbitrary to allow for a little room during the countdown and load times, etc.
107 if ($GLOBALS['EXEC_TIME'] >= $ses_tstamp + $timeout - 120) {
108 $ajaxObj->addContent('login', array('timed_out' => TRUE));
109 } else {
110 $ajaxObj->addContent('login', array('timed_out' => FALSE));
111 }
112 }
113 } else {
114 $ajaxObj->addContent('login', array('success' => FALSE, 'error' => 'No BE_USER object'));
115 }
116 }
117
118 /**
119 * Gets a MD5 challenge.
120 *
121 * @param array $parameters: Parameters (not used)
122 * @param TYPO3AJAX $parent: The calling parent AJAX object
123 * @return void
124 */
125 public function getChallenge(array $parameters, TYPO3AJAX $parent) {
126 session_start();
127
128 $_SESSION['login_challenge'] = md5(uniqid('') . getmypid());
129
130 session_commit();
131
132 $parent->addContent('challenge', $_SESSION['login_challenge']);
133 $parent->setContentFormat('json');
134 }
135 }
136
137 if (defined('TYPO3_MODE') && $TYPO3_CONF_VARS[TYPO3_MODE]['XCLASS']['typo3/classes/class.ajaxlogin.php']) {
138 include_once($TYPO3_CONF_VARS[TYPO3_MODE]['XCLASS']['typo3/classes/class.ajaxlogin.php']);
139 }
140
141 ?>