Файловый менеджер - Редактировать - /home/wuectly/www/03cbe/authentication.zip
Назад
PK �Q!]l��;� � ldap/ldap.xmlnu &1i� <?xml version="1.0" encoding="utf-8"?> <extension version="3.1" type="plugin" group="authentication" method="upgrade"> <name>plg_authentication_ldap</name> <author>Joomla! Project</author> <creationDate>November 2005</creationDate> <copyright>(C) 2005 Open Source Matters, Inc.</copyright> <license>GNU General Public License version 2 or later; see LICENSE.txt</license> <authorEmail>admin@joomla.org</authorEmail> <authorUrl>www.joomla.org</authorUrl> <version>3.0.0</version> <description>PLG_LDAP_XML_DESCRIPTION</description> <files> <filename plugin="ldap">ldap.php</filename> </files> <languages> <language tag="en-GB">en-GB.plg_authentication_ldap.ini</language> <language tag="en-GB">en-GB.plg_authentication_ldap.sys.ini</language> </languages> <config> <fields name="params"> <fieldset name="basic"> <field name="host" type="text" label="PLG_LDAP_FIELD_HOST_LABEL" description="PLG_LDAP_FIELD_HOST_DESC" size="20" /> <field name="port" type="number" label="PLG_LDAP_FIELD_PORT_LABEL" description="PLG_LDAP_FIELD_PORT_DESC" min="1" max="65535" default="389" hint="389" validate="number" filter="integer" size="5" /> <field name="use_ldapV3" type="radio" label="PLG_LDAP_FIELD_V3_LABEL" description="PLG_LDAP_FIELD_V3_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> <field name="negotiate_tls" type="radio" label="PLG_LDAP_FIELD_NEGOCIATE_LABEL" description="PLG_LDAP_FIELD_NEGOCIATE_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> <field name="ignore_reqcert_tls" type="radio" label="PLG_LDAP_FIELD_IGNORE_REQCERT_TLS_LABEL" description="PLG_LDAP_FIELD_IGNORE_REQCERT_TLS_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> <field name="no_referrals" type="radio" label="PLG_LDAP_FIELD_REFERRALS_LABEL" description="PLG_LDAP_FIELD_REFERRALS_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> <field name="auth_method" type="list" label="PLG_LDAP_FIELD_AUTHMETHOD_LABEL" description="PLG_LDAP_FIELD_AUTHMETHOD_DESC" default="bind" > <option value="search">PLG_LDAP_FIELD_VALUE_BINDSEARCH</option> <option value="bind">PLG_LDAP_FIELD_VALUE_BINDUSER</option> </field> <field name="base_dn" type="text" label="PLG_LDAP_FIELD_BASEDN_LABEL" description="PLG_LDAP_FIELD_BASEDN_DESC" size="20" /> <field name="search_string" type="text" label="PLG_LDAP_FIELD_SEARCHSTRING_LABEL" description="PLG_LDAP_FIELD_SEARCHSTRING_DESC" size="20" /> <field name="users_dn" type="text" label="PLG_LDAP_FIELD_USERSDN_LABEL" description="PLG_LDAP_FIELD_USERSDN_DESC" size="20" /> <field name="username" type="text" label="PLG_LDAP_FIELD_USERNAME_LABEL" description="PLG_LDAP_FIELD_USERNAME_DESC" size="20" /> <field name="password" type="password" label="PLG_LDAP_FIELD_PASSWORD_LABEL" description="PLG_LDAP_FIELD_PASSWORD_DESC" size="20" /> <field name="ldap_fullname" type="text" label="PLG_LDAP_FIELD_FULLNAME_LABEL" description="PLG_LDAP_FIELD_FULLNAME_DESC" default="fullName" size="20" /> <field name="ldap_email" type="text" label="PLG_LDAP_FIELD_EMAIL_LABEL" description="PLG_LDAP_FIELD_EMAIL_DESC" default="mail" size="20" /> <field name="ldap_uid" type="text" label="PLG_LDAP_FIELD_UID_LABEL" description="PLG_LDAP_FIELD_UID_DESC" default="uid" size="20" /> <field name="ldap_debug" type="radio" label="PLG_LDAP_FIELD_LDAPDEBUG_LABEL" description="PLG_LDAP_FIELD_LDAPDEBUG_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> </fieldset> </fields> </config> </extension> PK �Q!]2� � � ldap/ldap.phpnu &1i� <?php /** * @package Joomla.Plugin * @subpackage Authentication.ldap * * @copyright (C) 2006 Open Source Matters, Inc. <https://www.joomla.org> * @license GNU General Public License version 2 or later; see LICENSE.txt */ defined('_JEXEC') or die; use Joomla\Ldap\LdapClient; /** * LDAP Authentication Plugin * * @since 1.5 */ class PlgAuthenticationLdap extends JPlugin { /** * This method should handle any authentication and report back to the subject * * @param array $credentials Array holding the user credentials * @param array $options Array of extra options * @param object &$response Authentication response object * * @return boolean * * @since 1.5 */ public function onUserAuthenticate($credentials, $options, &$response) { $userdetails = null; $success = 0; $userdetails = array(); // For JLog $response->type = 'LDAP'; // Strip null bytes from the password $credentials['password'] = str_replace(chr(0), '', $credentials['password']); // LDAP does not like Blank passwords (tries to Anon Bind which is bad) if (empty($credentials['password'])) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_EMPTY_PASS_NOT_ALLOWED'); return false; } // Load plugin params info $ldap_email = $this->params->get('ldap_email'); $ldap_fullname = $this->params->get('ldap_fullname'); $ldap_uid = $this->params->get('ldap_uid'); $auth_method = $this->params->get('auth_method'); $ldap = new LdapClient($this->params); if (!$ldap->connect()) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NOT_CONNECT'); return; } switch ($auth_method) { case 'search': { // Bind using Connect Username/password // Force anon bind to mitigate misconfiguration like [#7119] if ($this->params->get('username', '') !== '') { $bindtest = $ldap->bind(); } else { $bindtest = $ldap->anonymous_bind(); } if ($bindtest) { // Search for users DN $binddata = $this->searchByString( str_replace( '[search]', str_replace(';', '\3b', $ldap->escape($credentials['username'], null, LDAP_ESCAPE_FILTER)), $this->params->get('search_string') ), $ldap ); if (isset($binddata[0], $binddata[0]['dn'])) { // Verify Users Credentials $success = $ldap->bind($binddata[0]['dn'], $credentials['password'], 1); // Get users details $userdetails = $binddata; } else { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NO_USER'); } } else { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NOT_CONNECT'); } } break; case 'bind': { // We just accept the result here $success = $ldap->bind($ldap->escape($credentials['username'], null, LDAP_ESCAPE_DN), $credentials['password']); if ($success) { $userdetails = $this->searchByString( str_replace( '[search]', str_replace(';', '\3b', $ldap->escape($credentials['username'], null, LDAP_ESCAPE_FILTER)), $this->params->get('search_string') ), $ldap ); } else { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_PASS'); } } break; } if (!$success) { $response->status = JAuthentication::STATUS_FAILURE; if ($response->error_message === '') { $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_PASS'); } } else { // Grab some details from LDAP and return them if (isset($userdetails[0][$ldap_uid][0])) { $response->username = $userdetails[0][$ldap_uid][0]; } if (isset($userdetails[0][$ldap_email][0])) { $response->email = $userdetails[0][$ldap_email][0]; } if (isset($userdetails[0][$ldap_fullname][0])) { $response->fullname = $userdetails[0][$ldap_fullname][0]; } else { $response->fullname = $credentials['username']; } // Were good - So say so. $response->status = JAuthentication::STATUS_SUCCESS; $response->error_message = ''; } $ldap->close(); } /** * Shortcut method to build a LDAP search based on a semicolon separated string * * Note that this method requires that semicolons which should be part of the search term to be escaped * to correctly split the search string into separate lookups * * @param string $search search string of search values * @param LdapClient $ldap The LDAP client * * @return array Search results * * @since 3.8.2 */ private static function searchByString($search, LdapClient $ldap) { $results = explode(';', $search); foreach ($results as $key => $result) { $results[$key] = '(' . str_replace('\3b', ';', $result) . ')'; } return $ldap->search($results); } } PK �Q!]�f�] ] gmail/gmail.phpnu &1i� <?php /** * @package Joomla.Plugin * @subpackage Authentication.gmail * * @copyright (C) 2006 Open Source Matters, Inc. <https://www.joomla.org> * @license GNU General Public License version 2 or later; see LICENSE.txt */ defined('_JEXEC') or die; use Joomla\CMS\Authentication\AuthenticationResponse; use Joomla\Registry\Registry; /** * GMail Authentication Plugin * * @since 1.5 */ class PlgAuthenticationGMail extends JPlugin { /** * This method should handle any authentication and report back to the subject * * @param array $credentials Array holding the user credentials * @param array $options Array of extra options * @param AuthenticationResponse &$response Authentication response object * * @return void * * @since 1.5 */ public function onUserAuthenticate($credentials, $options, &$response) { // Load plugin language $this->loadLanguage(); // No backend authentication if (JFactory::getApplication()->isClient('administrator') && !$this->params->get('backendLogin', 0)) { return; } $success = false; $curlParams = array( 'follow_location' => true, 'transport.curl' => array( CURLOPT_SSL_VERIFYPEER => $this->params->get('verifypeer', 1) ), ); $transportParams = new Registry($curlParams); try { $http = JHttpFactory::getHttp($transportParams, 'curl'); } catch (RuntimeException $e) { $response->status = JAuthentication::STATUS_FAILURE; $response->type = 'GMail'; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('JGLOBAL_AUTH_CURL_NOT_INSTALLED')); return; } // Check if we have a username and password if ($credentials['username'] === '' || $credentials['password'] === '') { $response->type = 'GMail'; $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('JGLOBAL_AUTH_USER_BLACKLISTED')); return; } $blacklist = explode(',', $this->params->get('user_blacklist', '')); // Check if the username isn't blacklisted if (in_array($credentials['username'], $blacklist)) { $response->type = 'GMail'; $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('JGLOBAL_AUTH_USER_BLACKLISTED')); return; } $suffix = $this->params->get('suffix', ''); $applysuffix = $this->params->get('applysuffix', 0); $offset = strpos($credentials['username'], '@'); // Check if we want to do suffix stuff, typically for Google Apps for Your Domain if ($suffix && $applysuffix) { if ($applysuffix == 1 && $offset === false) { // Apply suffix if missing $credentials['username'] .= '@' . $suffix; } elseif ($applysuffix == 2) { // Always use suffix if ($offset) { // If we already have an @, get rid of it and replace it $credentials['username'] = substr($credentials['username'], 0, $offset); } $credentials['username'] .= '@' . $suffix; } } $headers = array( 'Authorization' => 'Basic ' . base64_encode($credentials['username'] . ':' . $credentials['password']) ); try { $result = $http->get('https://mail.google.com/mail/feed/atom', $headers); } catch (Exception $e) { $response->status = JAuthentication::STATUS_FAILURE; $response->type = 'GMail'; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('JGLOBAL_AUTH_UNKNOWN_ACCESS_DENIED')); return; } $code = $result->code; switch ($code) { case 200 : $message = JText::_('JGLOBAL_AUTH_ACCESS_GRANTED'); $success = true; break; case 401 : $message = JText::_('JGLOBAL_AUTH_ACCESS_DENIED'); break; default : $message = JText::_('JGLOBAL_AUTH_UNKNOWN_ACCESS_DENIED'); break; } $response->type = 'GMail'; if (!$success) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', $message); return; } if (strpos($credentials['username'], '@') === false) { if ($suffix) { // If there is a suffix then we want to apply it $email = $credentials['username'] . '@' . $suffix; } else { // If there isn't a suffix just use the default gmail one $email = $credentials['username'] . '@gmail.com'; } } else { // The username looks like an email address (probably is) so use that $email = $credentials['username']; } // Extra security checks with existing local accounts $db = JFactory::getDbo(); $localUsernameChecks = array(strstr($email, '@', true), $email); $query = $db->getQuery(true) ->select('id, activation, username, email, block') ->from('#__users') ->where('username IN(' . implode(',', array_map(array($db, 'quote'), $localUsernameChecks)) . ')' . ' OR email = ' . $db->quote($email) ); $db->setQuery($query); if ($localUsers = $db->loadObjectList()) { foreach ($localUsers as $localUser) { // Local user exists with same username but different email address if ($email !== $localUser->email) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('PLG_GMAIL_ERROR_LOCAL_USERNAME_CONFLICT')); return; } else { // Existing user disabled locally if ($localUser->block || !empty($localUser->activation)) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_ACCESS_DENIED'); return; } // We will always keep the local username for existing accounts $credentials['username'] = $localUser->username; break; } } } elseif (JFactory::getApplication()->isClient('administrator')) { // We wont' allow backend access without local account $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JERROR_LOGIN_DENIED'); return; } $response->status = JAuthentication::STATUS_SUCCESS; $response->error_message = ''; $response->email = $email; // Reset the username to what we ended up using $response->username = $credentials['username']; $response->fullname = $credentials['username']; } } PK �Q!]��, , gmail/gmail.xmlnu &1i� <?xml version="1.0" encoding="utf-8"?> <extension version="3.1" type="plugin" group="authentication" method="upgrade"> <name>plg_authentication_gmail</name> <author>Joomla! Project</author> <creationDate>February 2006</creationDate> <copyright>(C) 2006 Open Source Matters, Inc.</copyright> <license>GNU General Public License version 2 or later; see LICENSE.txt</license> <authorEmail>admin@joomla.org</authorEmail> <authorUrl>www.joomla.org</authorUrl> <version>3.0.0</version> <description>PLG_GMAIL_XML_DESCRIPTION</description> <files> <filename plugin="gmail">gmail.php</filename> </files> <languages> <language tag="en-GB">en-GB.plg_authentication_gmail.ini</language> <language tag="en-GB">en-GB.plg_authentication_gmail.sys.ini</language> </languages> <config> <fields name="params"> <fieldset name="basic"> <field name="applysuffix" type="list" label="PLG_GMAIL_FIELD_APPLYSUFFIX_LABEL" description="PLG_GMAIL_FIELD_APPLYSUFFIX_DESC" default="0" filter="integer" > <option value="0">PLG_GMAIL_FIELD_VALUE_NOAPPLYSUFFIX</option> <option value="1">PLG_GMAIL_FIELD_VALUE_APPLYSUFFIXMISSING</option> <option value="2">PLG_GMAIL_FIELD_VALUE_APPLYSUFFIXALWAYS</option> </field> <field name="suffix" type="text" label="PLG_GMAIL_FIELD_SUFFIX_LABEL" description="PLG_GMAIL_FIELD_SUFFIX_DESC" size="20" showon="applysuffix:1,2" /> <field name="verifypeer" type="radio" label="PLG_GMAIL_FIELD_VERIFYPEER_LABEL" description="PLG_GMAIL_FIELD_VERIFYPEER_DESC" default="1" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> <field name="user_blacklist" type="text" label="PLG_GMAIL_FIELD_USER_BLACKLIST_LABEL" description="PLG_GMAIL_FIELD_USER_BLACKLIST_DESC" size="20" /> <field name="backendLogin" type="radio" label="PLG_GMAIL_FIELD_BACKEND_LOGIN_LABEL" description="PLG_GMAIL_FIELD_BACKEND_LOGIN_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JENABLED</option> <option value="0">JDISABLED</option> </field> </fieldset> </fields> </config> </extension> PK �Q!]cH�� � joomla/joomla.phpnu &1i� <?php /** * @package Joomla.Plugin * @subpackage Authentication.joomla * * @copyright (C) 2006 Open Source Matters, Inc. <https://www.joomla.org> * @license GNU General Public License version 2 or later; see LICENSE.txt */ defined('_JEXEC') or die; /** * Joomla Authentication plugin * * @since 1.5 */ class PlgAuthenticationJoomla extends JPlugin { /** * This method should handle any authentication and report back to the subject * * @param array $credentials Array holding the user credentials * @param array $options Array of extra options * @param object &$response Authentication response object * * @return void * * @since 1.5 */ public function onUserAuthenticate($credentials, $options, &$response) { $response->type = 'Joomla'; // Joomla does not like blank passwords if (empty($credentials['password'])) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_EMPTY_PASS_NOT_ALLOWED'); return; } // Get a database object $db = JFactory::getDbo(); $query = $db->getQuery(true) ->select('id, password') ->from('#__users') ->where('username=' . $db->quote($credentials['username'])); $db->setQuery($query); $result = $db->loadObject(); if ($result) { $match = JUserHelper::verifyPassword($credentials['password'], $result->password, $result->id); if ($match === true) { // Bring this in line with the rest of the system $user = JUser::getInstance($result->id); $response->email = $user->email; $response->fullname = $user->name; if (JFactory::getApplication()->isClient('administrator')) { $response->language = $user->getParam('admin_language'); } else { $response->language = $user->getParam('language'); } $response->status = JAuthentication::STATUS_SUCCESS; $response->error_message = ''; } else { // Invalid password $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_PASS'); } } else { // Let's hash the entered password even if we don't have a matching user for some extra response time // By doing so, we mitigate side channel user enumeration attacks JUserHelper::hashPassword($credentials['password']); // Invalid user $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NO_USER'); } // Check the two factor authentication if ($response->status === JAuthentication::STATUS_SUCCESS) { $methods = JAuthenticationHelper::getTwoFactorMethods(); if (count($methods) <= 1) { // No two factor authentication method is enabled return; } JModelLegacy::addIncludePath(JPATH_ADMINISTRATOR . '/components/com_users/models', 'UsersModel'); /** @var UsersModelUser $model */ $model = JModelLegacy::getInstance('User', 'UsersModel', array('ignore_request' => true)); // Load the user's OTP (one time password, a.k.a. two factor auth) configuration if (!array_key_exists('otp_config', $options)) { $otpConfig = $model->getOtpConfig($result->id); $options['otp_config'] = $otpConfig; } else { $otpConfig = $options['otp_config']; } // Check if the user has enabled two factor authentication if (empty($otpConfig->method) || ($otpConfig->method === 'none')) { // Warn the user if they are using a secret code but they have not // enabled two factor auth in their account. if (!empty($credentials['secretkey'])) { try { $app = JFactory::getApplication(); $this->loadLanguage(); $app->enqueueMessage(JText::_('PLG_AUTH_JOOMLA_ERR_SECRET_CODE_WITHOUT_TFA'), 'warning'); } catch (Exception $exc) { // This happens when we are in CLI mode. In this case // no warning is issued return; } } return; } // Try to validate the OTP FOFPlatform::getInstance()->importPlugin('twofactorauth'); $otpAuthReplies = FOFPlatform::getInstance()->runPlugins('onUserTwofactorAuthenticate', array($credentials, $options)); $check = false; /* * This looks like noob code but DO NOT TOUCH IT and do not convert * to in_array(). During testing in_array() inexplicably returned * null when the OTEP begins with a zero! o_O */ if (!empty($otpAuthReplies)) { foreach ($otpAuthReplies as $authReply) { $check = $check || $authReply; } } // Fall back to one time emergency passwords if (!$check) { // Did the user use an OTEP instead? if (empty($otpConfig->otep)) { if (empty($otpConfig->method) || ($otpConfig->method === 'none')) { // Two factor authentication is not enabled on this account. // Any string is assumed to be a valid OTEP. return; } else { /* * Two factor authentication enabled and no OTEPs defined. The * user has used them all up. Therefore anything they enter is * an invalid OTEP. */ $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_SECRETKEY'); return; } } // Clean up the OTEP (remove dashes, spaces and other funny stuff // our beloved users may have unwittingly stuffed in it) $otep = $credentials['secretkey']; $otep = filter_var($otep, FILTER_SANITIZE_NUMBER_INT); $otep = str_replace('-', '', $otep); $check = false; // Did we find a valid OTEP? if (in_array($otep, $otpConfig->otep)) { // Remove the OTEP from the array $otpConfig->otep = array_diff($otpConfig->otep, array($otep)); $model->setOtpConfig($result->id, $otpConfig); // Return true; the OTEP was a valid one $check = true; } } if (!$check) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_SECRETKEY'); } } } } PK �Q!] �$ $ joomla/joomla.xmlnu &1i� <?xml version="1.0" encoding="utf-8"?> <extension version="3.1" type="plugin" group="authentication" method="upgrade"> <name>plg_authentication_joomla</name> <author>Joomla! Project</author> <creationDate>November 2005</creationDate> <copyright>(C) 2005 Open Source Matters, Inc.</copyright> <license>GNU General Public License version 2 or later; see LICENSE.txt</license> <authorEmail>admin@joomla.org</authorEmail> <authorUrl>www.joomla.org</authorUrl> <version>3.0.0</version> <description>PLG_AUTH_JOOMLA_XML_DESCRIPTION</description> <files> <filename plugin="joomla">joomla.php</filename> </files> <languages> <language tag="en-GB">en-GB.plg_authentication_joomla.ini</language> <language tag="en-GB">en-GB.plg_authentication_joomla.sys.ini</language> </languages> </extension> PK �Q!]��3��- �- cookie/cookie.phpnu &1i� <?php /** * @package Joomla.Plugin * @subpackage Authentication.cookie * * @copyright (C) 2013 Open Source Matters, Inc. <https://www.joomla.org> * @license GNU General Public License version 2 or later; see LICENSE.txt */ defined('_JEXEC') or die; /** * Joomla Authentication plugin * * @since 3.2 * @note Code based on http://jaspan.com/improved_persistent_login_cookie_best_practice * and http://fishbowl.pastiche.org/2004/01/19/persistent_login_cookie_best_practice/ */ class PlgAuthenticationCookie extends JPlugin { /** * Application object * * @var JApplicationCms * @since 3.2 */ protected $app; /** * Database object * * @var JDatabaseDriver * @since 3.2 */ protected $db; /** * Reports the privacy related capabilities for this plugin to site administrators. * * @return array * * @since 3.9.0 */ public function onPrivacyCollectAdminCapabilities() { $this->loadLanguage(); return array( JText::_('PLG_AUTHENTICATION_COOKIE') => array( JText::_('PLG_AUTH_COOKIE_PRIVACY_CAPABILITY_COOKIE'), ) ); } /** * This method should handle any authentication and report back to the subject * * @param array $credentials Array holding the user credentials * @param array $options Array of extra options * @param object &$response Authentication response object * * @return boolean * * @since 3.2 */ public function onUserAuthenticate($credentials, $options, &$response) { // No remember me for admin if ($this->app->isClient('administrator')) { return false; } // Get cookie $cookieName = 'joomla_remember_me_' . JUserHelper::getShortHashedUserAgent(); $cookieValue = $this->app->input->cookie->get($cookieName); // Try with old cookieName (pre 3.6.0) if not found if (!$cookieValue) { $cookieName = JUserHelper::getShortHashedUserAgent(); $cookieValue = $this->app->input->cookie->get($cookieName); } if (!$cookieValue) { return false; } $cookieArray = explode('.', $cookieValue); // Check for valid cookie value if (count($cookieArray) !== 2) { // Destroy the cookie in the browser. $this->app->input->cookie->set($cookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); JLog::add('Invalid cookie detected.', JLog::WARNING, 'error'); return false; } $response->type = 'Cookie'; // Filter series since we're going to use it in the query $filter = new JFilterInput; $series = $filter->clean($cookieArray[1], 'ALNUM'); // Remove expired tokens $query = $this->db->getQuery(true) ->delete('#__user_keys') ->where($this->db->quoteName('time') . ' < ' . $this->db->quote(time())); try { $this->db->setQuery($query)->execute(); } catch (RuntimeException $e) { // We aren't concerned with errors from this query, carry on } // Find the matching record if it exists. $query = $this->db->getQuery(true) ->select($this->db->quoteName(array('user_id', 'token', 'series', 'time'))) ->from($this->db->quoteName('#__user_keys')) ->where($this->db->quoteName('series') . ' = ' . $this->db->quote($series)) ->where($this->db->quoteName('uastring') . ' = ' . $this->db->quote($cookieName)) ->order($this->db->quoteName('time') . ' DESC'); try { $results = $this->db->setQuery($query)->loadObjectList(); } catch (RuntimeException $e) { $response->status = JAuthentication::STATUS_FAILURE; return false; } if (count($results) !== 1) { // Destroy the cookie in the browser. $this->app->input->cookie->set($cookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); $response->status = JAuthentication::STATUS_FAILURE; return false; } // We have a user with one cookie with a valid series and a corresponding record in the database. if (!JUserHelper::verifyPassword($cookieArray[0], $results[0]->token)) { /* * This is a real attack! * Either the series was guessed correctly or a cookie was stolen and used twice (once by attacker and once by victim). * Delete all tokens for this user! */ $query = $this->db->getQuery(true) ->delete('#__user_keys') ->where($this->db->quoteName('user_id') . ' = ' . $this->db->quote($results[0]->user_id)); try { $this->db->setQuery($query)->execute(); } catch (RuntimeException $e) { // Log an alert for the site admin JLog::add( sprintf('Failed to delete cookie token for user %s with the following error: %s', $results[0]->user_id, $e->getMessage()), JLog::WARNING, 'security' ); } // Destroy the cookie in the browser. $this->app->input->cookie->set($cookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); // Issue warning by email to user and/or admin? JLog::add(JText::sprintf('PLG_AUTH_COOKIE_ERROR_LOG_LOGIN_FAILED', $results[0]->user_id), JLog::WARNING, 'security'); $response->status = JAuthentication::STATUS_FAILURE; return false; } // Make sure there really is a user with this name and get the data for the session. $query = $this->db->getQuery(true) ->select($this->db->quoteName(array('id', 'username', 'password'))) ->from($this->db->quoteName('#__users')) ->where($this->db->quoteName('username') . ' = ' . $this->db->quote($results[0]->user_id)) ->where($this->db->quoteName('requireReset') . ' = 0'); try { $result = $this->db->setQuery($query)->loadObject(); } catch (RuntimeException $e) { $response->status = JAuthentication::STATUS_FAILURE; return false; } if ($result) { // Bring this in line with the rest of the system $user = JUser::getInstance($result->id); // Set response data. $response->username = $result->username; $response->email = $user->email; $response->fullname = $user->name; $response->password = $result->password; $response->language = $user->getParam('language'); // Set response status. $response->status = JAuthentication::STATUS_SUCCESS; $response->error_message = ''; } else { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NO_USER'); } } /** * We set the authentication cookie only after login is successfully finished. * We set a new cookie either for a user with no cookies or one * where the user used a cookie to authenticate. * * @param array $options Array holding options * * @return boolean True on success * * @since 3.2 */ public function onUserAfterLogin($options) { // No remember me for admin if ($this->app->isClient('administrator')) { return false; } if (isset($options['responseType']) && $options['responseType'] === 'Cookie') { // Logged in using a cookie $cookieName = 'joomla_remember_me_' . JUserHelper::getShortHashedUserAgent(); // We need the old data to get the existing series $cookieValue = $this->app->input->cookie->get($cookieName); // Try with old cookieName (pre 3.6.0) if not found if (!$cookieValue) { $oldCookieName = JUserHelper::getShortHashedUserAgent(); $cookieValue = $this->app->input->cookie->get($oldCookieName); // Destroy the old cookie in the browser $this->app->input->cookie->set($oldCookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); } $cookieArray = explode('.', $cookieValue); // Filter series since we're going to use it in the query $filter = new JFilterInput; $series = $filter->clean($cookieArray[1], 'ALNUM'); } elseif (!empty($options['remember'])) { // Remember checkbox is set $cookieName = 'joomla_remember_me_' . JUserHelper::getShortHashedUserAgent(); // Create a unique series which will be used over the lifespan of the cookie $unique = false; $errorCount = 0; do { $series = JUserHelper::genRandomPassword(20); $query = $this->db->getQuery(true) ->select($this->db->quoteName('series')) ->from($this->db->quoteName('#__user_keys')) ->where($this->db->quoteName('series') . ' = ' . $this->db->quote($series)); try { $results = $this->db->setQuery($query)->loadResult(); if ($results === null) { $unique = true; } } catch (RuntimeException $e) { $errorCount++; // We'll let this query fail up to 5 times before giving up, there's probably a bigger issue at this point if ($errorCount === 5) { return false; } } } while ($unique === false); } else { return false; } // Get the parameter values $lifetime = $this->params->get('cookie_lifetime', 60) * 24 * 60 * 60; $length = $this->params->get('key_length', 16); // Generate new cookie $token = JUserHelper::genRandomPassword($length); $cookieValue = $token . '.' . $series; // Overwrite existing cookie with new value $this->app->input->cookie->set( $cookieName, $cookieValue, time() + $lifetime, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', ''), $this->app->isHttpsForced(), true ); $query = $this->db->getQuery(true); if (!empty($options['remember'])) { // Create new record $query ->insert($this->db->quoteName('#__user_keys')) ->set($this->db->quoteName('user_id') . ' = ' . $this->db->quote($options['user']->username)) ->set($this->db->quoteName('series') . ' = ' . $this->db->quote($series)) ->set($this->db->quoteName('uastring') . ' = ' . $this->db->quote($cookieName)) ->set($this->db->quoteName('time') . ' = ' . (time() + $lifetime)); } else { // Update existing record with new token $query ->update($this->db->quoteName('#__user_keys')) ->where($this->db->quoteName('user_id') . ' = ' . $this->db->quote($options['user']->username)) ->where($this->db->quoteName('series') . ' = ' . $this->db->quote($series)) ->where($this->db->quoteName('uastring') . ' = ' . $this->db->quote($cookieName)); } $hashedToken = JUserHelper::hashPassword($token); $query->set($this->db->quoteName('token') . ' = ' . $this->db->quote($hashedToken)); try { $this->db->setQuery($query)->execute(); } catch (RuntimeException $e) { return false; } return true; } /** * This is where we delete any authentication cookie when a user logs out * * @param array $options Array holding options (length, timeToExpiration) * * @return boolean True on success * * @since 3.2 */ public function onUserAfterLogout($options) { // No remember me for admin if ($this->app->isClient('administrator')) { return false; } $cookieName = 'joomla_remember_me_' . JUserHelper::getShortHashedUserAgent(); $cookieValue = $this->app->input->cookie->get($cookieName); // There are no cookies to delete. if (!$cookieValue) { return true; } $cookieArray = explode('.', $cookieValue); // Filter series since we're going to use it in the query $filter = new JFilterInput; $series = $filter->clean($cookieArray[1], 'ALNUM'); // Remove the record from the database $query = $this->db->getQuery(true) ->delete('#__user_keys') ->where($this->db->quoteName('series') . ' = ' . $this->db->quote($series)); try { $this->db->setQuery($query)->execute(); } catch (RuntimeException $e) { // We aren't concerned with errors from this query, carry on } // Destroy the cookie $this->app->input->cookie->set($cookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); return true; } } PK �Q!]G��� � cookie/cookie.xmlnu &1i� <?xml version="1.0" encoding="utf-8"?> <extension version="3.2" type="plugin" group="authentication" method="upgrade"> <name>plg_authentication_cookie</name> <author>Joomla! Project</author> <creationDate>July 2013</creationDate> <copyright>(C) 2013 Open Source Matters, Inc.</copyright> <license>GNU General Public License version 2 or later; see LICENSE.txt</license> <authorEmail>admin@joomla.org</authorEmail> <authorUrl>www.joomla.org</authorUrl> <version>3.0.0</version> <description>PLG_AUTH_COOKIE_XML_DESCRIPTION</description> <files> <filename plugin="cookie">cookie.php</filename> </files> <languages> <language tag="en-GB">en-GB.plg_authentication_cookie.ini</language> <language tag="en-GB">en-GB.plg_authentication_cookie.sys.ini</language> </languages> <config> <fields name="params"> <fieldset name="basic"> <field name="cookie_lifetime" type="number" label="PLG_AUTH_COOKIE_FIELD_COOKIE_LIFETIME_LABEL" description="PLG_AUTH_COOKIE_FIELD_COOKIE_LIFETIME_DESC" default="60" filter="integer" required="true" /> <field name="key_length" type="list" label="PLG_AUTH_COOKIE_FIELD_KEY_LENGTH_LABEL" description="PLG_AUTH_COOKIE_FIELD_KEY_LENGTH_DESC" default="16" filter="integer" required="true" > <option value="8">8</option> <option value="16">16</option> <option value="32">32</option> <option value="64">64</option> </field> </fieldset> </fields> </config> </extension> PK �Q!]l��;� � ldap/ldap.xmlnu &1i� PK �Q!]2� � � + ldap/ldap.phpnu &1i� PK �Q!]�f�] ] _&