File:  [LON-CAPA] / loncom / auth / lonroles.pm
Revision 1.71: download - view: text, annotated - select for diffs
Wed Sep 17 18:16:39 2003 UTC (20 years, 8 months ago) by albertel
Branches: MAIN
CVS tags: HEAD
- stupid typo
- removing the blind acceptance of the answers target as a form parameter

# The LearningOnline Network with CAPA
# User Roles Screen
#
# $Id: lonroles.pm,v 1.71 2003/09/17 18:16:39 albertel Exp $
#
# Copyright Michigan State University Board of Trustees
#
# This file is part of the LearningOnline Network with CAPA (LON-CAPA).
#
# LON-CAPA is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# LON-CAPA is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with LON-CAPA; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
#
# /home/httpd/html/adm/gpl.txt
#
# http://www.lon-capa.org/
#
# (Directory Indexer
# (Login Screen
# YEAR=1999
# 5/21/99,5/22,5/25,5/26,5/31,6/2,6/10,7/12,7/14 Gerd Kortemeyer)
# 11/23 Gerd Kortemeyer)
# YEAR=2000
# 1/14,03/06,06/01,07/22,07/24,07/25,
# 09/04,09/06,09/28,09/29,09/30,10/2,10/5,10/26,10/28,
# 12/08,12/28,
# YEAR=2001
# 01/15/01 Gerd Kortemeyer
# 03/02,05/03,05/25,05/30,06/01,07/06,08/06 Gerd Kortemeyer
# 12/29 Gerd Kortemeyer
#
###

package Apache::lonroles;

use strict;
use Apache::lonnet();
use Apache::lonuserstate();
use Apache::Constants qw(:common);
use Apache::File();
use Apache::lonmenu;
use Apache::loncommon;
use Apache::lonannounce;

sub redirect_user {
    my ($r,$title,$url,$msg) = @_;
    $msg = $title if (! defined($msg));
    $r->content_type('text/html');
    &Apache::loncommon::no_cache($r);
    $r->send_http_header;
    my $swinfo=&Apache::lonmenu::rawconfig();
    my $bodytag=&Apache::loncommon::bodytag('Switching Role');
    $r->print (<<ENDREDIR);
<head><title>$title</title>
<meta HTTP-EQUIV="Refresh" CONTENT="1; url=$url">
</head>
<html>
$bodytag
<script>
$swinfo
</script>
<h1>$msg</h1>
</body>
</html>
ENDREDIR
    return;
}

sub handler {

    my $r = shift;

    my $now=time;
    my $then=$ENV{'user.login.time'};
    my $envkey;


# ================================================================== Roles Init

    if ($ENV{'form.selectrole'}) {
	if ($ENV{'request.course.id'}) {
	    my %temp=('logout_'.$ENV{'request.course.id'} => time);
	    &Apache::lonnet::put('email_status',\%temp);
        }
	&Apache::lonnet::appenv("request.course.id"   => '',
				"request.course.fn"   => '',
				"request.course.uri"  => '',
				"request.course.sec"  => '',
				"request.role"        => 'cm',
                                "request.role.adv"    => $ENV{'user.adv'},
				"request.role.domain" => $ENV{'user.domain'});
        foreach $envkey (keys %ENV) {
            next if ($envkey!~/^user\.role\./);
	    my (undef,undef,$role,@pwhere)=split(/\./,$envkey);
            my $where=join('.',@pwhere);
            my $trolecode=$role.'.'.$where;
            if ($ENV{'form.'.$trolecode}) {
		my ($tstart,$tend)=split(/\./,$ENV{$envkey});
		my $tstatus='is';
		if ($tstart) {
		    if ($tstart>$then) { 
			$tstatus='future';
		    }
		}
		if ($tend) {
		    if ($tend<$then) { $tstatus='expired'; }
		    if ($tend<$now) { $tstatus='will_not'; }
		}
		if ($tstatus eq 'is') {
		    $where=~s/^\///;
		    my ($cdom,$cnum,$csec)=split(/\//,$where);
# check for keyed access
		    if (($role eq 'st') && 
                       ($ENV{'course.'.$cdom.'_'.$cnum.'.keyaccess'} eq 'yes')) {
		         unless (&Apache::lonnet::validate_access_key(
				     $ENV{'environment.key.'.$cdom.'_'.$cnum},
					     $cdom,$cnum)) {
# there is no valid key
			     if ($ENV{'form.newkey'}) {
# student attempts to register a new key
			     } else {
# print form to enter a new key
				 $r->content_type('text/html');
				 &Apache::loncommon::no_cache($r);
				 $r->send_http_header;
				 my $swinfo=&Apache::lonmenu::rawconfig();
				 my $bodytag=&Apache::loncommon::bodytag
				    ('Enter Access Key to Unlock this Course');
				 $r->print(<<ENDENTERKEY);
<head><title>Entering Course Access Key</title>
</head>
<html>
$bodytag
<script>
$swinfo
</script>
<form method="post">
<input type="hidden" name="selectrole" value="$ENV{'form.selectrole'}" />
<input type="text" size="20" name="newkey" value="$ENV{'form.newkey'}" />
<input type="submit" value="Enter key" />
</form>
</body></html>
ENDENTERKEY
				 return OK;
			     }
			 }
		     }
                    my $tadv=0;
                    if (($trolecode!~/^st/) && 
                        ($trolecode!~/^ta/) && 
                        ($trolecode!~/^cm/)) { $tadv=1; }
		    &Apache::lonnet::appenv(
                                           'request.role'        => $trolecode,
					   'request.role.adv'    => $tadv,
					   'request.role.domain' => $cdom,
					   'request.course.sec'  => $csec);
		    my $msg='Entering course ...';

		    if (($cnum) && ($role ne 'ca')) {
			my ($furl,$ferr)=
			    &Apache::lonuserstate::readmap($cdom.'/'.$cnum);
			if (($ENV{'form.orgurl'}) && 
			    ($ENV{'form.orgurl'}!~/^\/adm\/flip/)) {
			    my $dest=$ENV{'form.orgurl'};
			    if ( &Apache::lonnet::mod_perl_version() == 2 ) {
				&Apache::lonnet::cleanenv();
			    }
			    $r->internal_redirect($dest);
			    return OK;
			} else {
			    unless ($ENV{'request.course.id'}) {
				&Apache::lonnet::appenv(
				      "request.course.id"  => $cdom.'_'.$cnum);
				$furl='/adm/roles?tryagain=1';
				$msg=
	 '<h1><font color=red>Could not initialize course at this time.</font></h1><h3>Please try again.</h3>'.$ferr;
			    }

			    # Check to see if the user is a CC entering a course 
			    # for the first time
			    my (undef, undef, $role, $courseid) = split(/\./, $envkey);
			    if (substr($courseid, 0, 1) eq '/') {
				$courseid = substr($courseid, 1);
			    }
			    $courseid =~ s/\//_/;
			    if ($role eq 'cc' && $ENV{'course.' . $courseid . 
							  '.course.helper.not.run'}) {
				$furl = "/adm/helper/course.initialization.helper";
			    }
                            #
                            # Send the user to the course they selected
                            &redirect_user($r,'Entering Course',
                                           $furl,$msg);
                            return OK;
			}
		    }
                    #
                    # Send the user to the construction space they selected
                    if ($role =~ /^(au|ca)$/) {
                        my $redirect_url = '/priv/';
                        if ($role eq 'au') {
                            $redirect_url.=$ENV{'user.name'};
                        } else {
                            $where =~ /\/(.*)$/;
                            $redirect_url .= $1;
                        }
                        $redirect_url .= '/';
                        &redirect_user($r,'Entering Construction Space',
                                       $redirect_url);
                        return OK;
                    }
		}
            }
        }
    }


# =============================================================== No Roles Init

    $r->content_type('text/html');
    &Apache::loncommon::no_cache($r);
    $r->send_http_header;
    return OK if $r->header_only;

    my $swinfo=&Apache::lonmenu::rawconfig();
    my $bodytag=&Apache::loncommon::bodytag('User Roles');
    my $helptag=&Apache::loncommon::help_open_topic
     ("General_Intro","Click here for help");
    $r->print(<<ENDHEADER);
<html>
<head>
<title>LON-CAPA User Roles</title>
</head>
$bodytag
$helptag<br />
<script>
$swinfo
window.focus();
</script>
ENDHEADER

# ------------------------------------------ Get Error Message from Environment

    my ($fn,$priv,$nochoose,$error,$msg)=split(/:/,$ENV{'user.error.msg'});
    if ($ENV{'user.error.msg'}) {
	$r->log_reason(
   "$msg for $ENV{'user.name'} domain $ENV{'user.domain'} access $priv",$fn);
    }

# ------------------------------------------------- Can this user re-init, etc?

    my $advanced=$ENV{'user.adv'};
    &Apache::loncommon::get_unprocessed_cgi($ENV{'QUERY_STRING'},['tryagain']);
    my $tryagain=$ENV{'form.tryagain'};

# -------------------------------------------------------- Generate Page Output
# --------------------------------------------------------------- Error Header?
    if ($error) {
	$r->print("<h1>LON-CAPA Access Control</h1>");
        $r->print("<hr><pre>Access  : ".
                  Apache::lonnet::plaintext($priv)."\n");
        $r->print("Resource: $fn\n");
        $r->print("Action  : $msg\n</pre><hr>");
    } else {
        if ($ENV{'user.error.msg'}) {
	    $r->print(
 '<h3><font color=red>You need to choose another user role or '.
 'enter a specific course for this function</font></h3>');
	}
    }
# -------------------------------------------------------- Choice or no choice?
    if ($nochoose) {
        if ($advanced) {
	    $r->print("<h2>Assigned User Roles</h2>\n");
        } else {
	    $r->print("<h2>Sorry ...</h2>\nThis resource might be part of");
	    if ($ENV{'request.course.id'}) {
		$r->print(' another');
	    } else {
		$r->print(' a certain');
	    } 
	    $r->print(' course.</body></html>');
	    return OK;
        } 
    } else {
        if ($advanced) {
	    $r->print("Your home server is ".
		      $Apache::lonnet::hostname{&Apache::lonnet::homeserver
                      ($ENV{'user.name'},$ENV{'user.domain'})}.
		      "<br />\n");
	    $r->print("Author and Co-Author roles may not be available on ".
		      "servers other than your home server.");
        } else {
	    $r->print("<h2>Select a Course to Enter</h2>\n");
        }
        if (($ENV{'REDIRECT_QUERY_STRING'}) && ($fn)) {
    	    $fn.='?'.$ENV{'REDIRECT_QUERY_STRING'};
        }
        $r->print('<form method=post action="'.(($fn)?$fn:$r->uri).'">');
        $r->print('<input type=hidden name=orgurl value="'.$fn.'">');
        $r->print('<input type=hidden name=selectrole value=1>');
    }
    if ($ENV{'user.adv'}) {
	$r->print(
	      '<br />Show all roles: <input type="checkbox" name="showall"');
	if ($ENV{'form.showall'}) { $r->print(' checked'); }
	$r->print('><input type=submit value="Display">');
    }
# ----------------------------------------------------------------------- Table
    $r->print('<br /><table><tr>');
    unless ($nochoose) { $r->print('<th>&nbsp;</th>'); }
    $r->print('<th>User Role</th><th colspan=2>Extent</th>'.
	      '<th>Start</th><th>End</th><th>Remark</th></tr>'."\n");

    foreach $envkey (sort keys %ENV) {
        my $button = 1;
        my $switchserver='';
        if ($envkey=~/^user\.role\./) {
	    my (undef,undef,$role,@pwhere)=split(/\./,$envkey);
            next if (!defined($role) || $role eq '');
            my $where=join('.',@pwhere);
            my $trolecode=$role.'.'.$where;
            my ($tstart,$tend)=split(/\./,$ENV{$envkey});
            my $tremark='';
            my $tstatus='is';
            my $tpstart='&nbsp;';
            my $tpend='&nbsp;';
            my $tfont='#000000';
            if ($tstart) {
		if ($tstart>$then) { 
                    $tstatus='future';
                    if ($tstart<$now) { $tstatus='will'; }
                }
                $tpstart=localtime($tstart);
            }
            if ($tend) {
                if ($tend<$then) { 
                    $tstatus='expired'; 
                } elsif ($tend<$now) { 
                    $tstatus='will_not'; 
                }
                $tpend=localtime($tend);
            }
            if ($ENV{'request.role'} eq $trolecode) {
		$tstatus='selected';
            }
            my $tbg;
            if (($tstatus eq 'is') || ($tstatus eq 'selected') ||
                ($ENV{'form.showall'})) {
                if ($tstatus eq 'is') {
                    $tbg='#77FF77';
                    $tfont='#003300';
                } elsif ($tstatus eq 'future') {
                    $tbg='#FFFF77';
                    $button=0;
                } elsif ($tstatus eq 'will') {
                    $tbg='#FFAA77';
                    $tremark.='Active at next login. ';
                } elsif ($tstatus eq 'expired') {
                    $tbg='#FF7777';
                    $tfont='#330000';
                    $button=0;
                } elsif ($tstatus eq 'will_not') {
                    $tbg='#AAFF77';
                    $tremark.='Expired after logout. ';
                } elsif ($tstatus eq 'selected') {
                    $tbg='#11CC55';
                    $tfont='#002200';
                    $tremark.='Currently selected. ';
                }
                my $trole;
                if ($role =~ /^cr\//) {
                    my ($rdummy,$rdomain,$rauthor,$rrole)=split(/\//,$role);
                    $tremark.='<br>Defined by '.$rauthor.' at '.$rdomain.'.';
                    $trole=$rrole;
                } else {
                    $trole=Apache::lonnet::plaintext($role);
                }
                my $ttype;
                my $twhere;
                my ($tdom,$trest,$tsection)=
                    split(/\//,Apache::lonnet::declutter($where));
                # First, Co-Authorship roles
                if ($role eq 'ca') {
                    my $home = &Apache::lonnet::homeserver($trest,$tdom);
                    if ($home ne $r->dir_config('lonHostID')) {
			$button=0;
                        $switchserver=&Apache::lonnet::escape('http://'.
                         $Apache::lonnet::hostname{$home}.
                         '/adm/login?domain='.$ENV{'user.domain'}.
			  '&username='.$ENV{'user.name'}.
                          '&firsturl=/priv/'.$trest);
                    }
                    #next if ($home eq 'no_host');
                    $home = $Apache::lonnet::hostname{$home};
                    $ttype='Construction Space';
                    $twhere='User: '.$trest.'<br />Domain: '.$tdom.'<br />'.
                        ' Server:&nbsp;'.$home;
                    $ENV{'course.'.$tdom.'_'.$trest.'.description'}='ca';
                } elsif ($role eq 'au') {
                    # Authors
                    my $home = &Apache::lonnet::homeserver
                        ($ENV{'user.name'},$ENV{'user.domain'});
                    if ($home ne $r->dir_config('lonHostID')) {
			$button=0;
                        $switchserver=&Apache::lonnet::escape('http://'.
                         $Apache::lonnet::hostname{$home}.
                          '/adm/login?domain='.$ENV{'user.domain'}.
			   '&username='.$ENV{'user.name'}.
                           '&firsturl=/priv/'.$ENV{'user.name'});
                    }
                    #next if ($home eq 'no_host');
                    $home = $Apache::lonnet::hostname{$home};
                    $ttype='Construction Space';
                    $twhere='Domain: '.$tdom.'<br />Server:&nbsp;'.$home;
                    $ENV{'course.'.$tdom.'_'.$trest.'.description'}='ca';
                } elsif ($trest) {
                    $ttype='Course';
                    if ($tsection) {
                        $ttype.='<br>Section/Group: '.$tsection;
		    }
                    my $tcourseid=$tdom.'_'.$trest;
                    if ($ENV{'course.'.$tcourseid.'.description'}) {
                        $twhere=$ENV{'course.'.$tcourseid.'.description'};
                        unless ($twhere eq 'Currently not available') {
			    $twhere.=' <font size="-2">'.
        &Apache::loncommon::syllabuswrapper('Syllabus',$trest,$tdom,$tfont).
                                    '</font>';
			}
                    } else {
                        my %newhash=Apache::lonnet::coursedescription
                            ($tcourseid);
                        if (%newhash) {
                            $twhere=$newhash{'description'}.
                              ' <font size="-2">'.
        &Apache::loncommon::syllabuswrapper('Syllabus',$trest,$tdom,$tfont).
                              '</font>';
                        } else {
                            $twhere='Currently not available';
                            $ENV{'course.'.$tcourseid.'.description'}=$twhere;
                        }
                    }
		    if ($role ne 'st') { $twhere.="<br />Domain:".$tdom; }
                } elsif ($tdom) {
                    $ttype='Domain';
                    $twhere=$tdom;
                } else {
                    $ttype='System';
                    $twhere='system wide';
                }
 
                $r->print('<tr bgcolor='.$tbg.'>');
                unless ($nochoose) {
                    if (!$button) {
			if ($switchserver) {
			    $r->print('<td><a href="/adm/logout?handover='.
                              $switchserver.'">Switch Server</a></td>');
                        } else {
                            $r->print('<td>&nbsp;</td>');
                        }
                    } elsif ($tstatus eq 'is') {
                        $r->print('<td><input type=submit value=Select name="'.
                                  $trolecode.'"></td>');
                    } elsif ($tryagain) {
                        $r->print
                        ('<td><input type=submit value="Try Selecting Again"'.
                             ' name="'.$trolecode.'"></td>');
                    } elsif ($advanced) {
                        $r->print
                            ('<td><input type=submit value="Re-Initialize"'.
                             ' name="'.$trolecode.'"></td>');
                    } else {
                        $r->print('<td>&nbsp;</td>');
                    }
                }
                $tremark.=&Apache::lonannounce::showday(time,1,
                         &Apache::lonannounce::readcalendar($tdom.'_'.$trest));
                
		$r->print('<td><font color="'.$tfont.'">'.$trole.
                      '</font></td><td><font color="'.$tfont.'">'.$ttype.
                      '</font></td><td><font color="'.$tfont.'">'.$twhere.
                      '</font></td><td><font color="'.$tfont.'">'.$tpstart.
                      '</font></td><td><font color="'.$tfont.'">'.$tpend.
                      '</font></td><td><font color="'.$tfont.'">'.$tremark.
                      '&nbsp;</font></td></tr>'."\n");
	    }
        }
    }
    my $tremark='';
    my $tfont='#003300';
    if ($ENV{'request.role'} eq 'cm') {
	$r->print('<tr bgcolor="#11CC55">');
        $tremark='Currently selected.';
        $tfont='#002200';
    } else {
        $r->print('<tr bgcolor="#77FF77">');
    }
    unless ($nochoose) {
	if ($ENV{'request.role'} ne 'cm') {
	    $r->print('<td><input type=submit value=Select name="cm"></td>');
	} else {
	    $r->print('<td>&nbsp;</td>');
	}
    }
    $r->print('<td colspan=5><font color="'.$tfont.'">No role specified'.
      '</font></td><td><font color="'.$tfont.'">'.$tremark.
      '&nbsp;</font></td></tr>'."\n");

    $r->print('</table>');
    unless ($nochoose) {
	$r->print("</form>\n");
    }
# ------------------------------------------------------------ Privileges Info
    if (($advanced) && (($ENV{'user.error.msg'}) || ($error))) {
	$r->print('<hr><h2>Current Privileges</h2>');

	foreach $envkey (sort keys %ENV) {
	    if ($envkey=~/^user\.priv\.$ENV{'request.role'}\./) {
		my $where=$envkey;
		$where=~s/^user\.priv\.$ENV{'request.role'}\.//;
		my $ttype;
		my $twhere;
		my ($tdom,$trest,$tsec)=
		    split(/\//,Apache::lonnet::declutter($where));
		if ($trest) {
		    if ($ENV{'course.'.$tdom.'_'.$trest.'.description'} eq 'ca') {
			$ttype='Construction Space';
			$twhere='User: '.$trest.', Domain: '.$tdom;
		    } else {
			$ttype='Course';
			$twhere=$ENV{'course.'.$tdom.'_'.$trest.'.description'};
			if ($tsec) {
			    $twhere.=' (Section/Group: '.$tsec.')';
			}
		    }
		} elsif ($tdom) {
		    $ttype='Domain';
		    $twhere=$tdom;
		} else {
		    $ttype='System';
		    $twhere='/';
		}
		$r->print("\n<h3>".$ttype.': '.$twhere.'</h3><ul>');
		foreach (sort split(/:/,$ENV{$envkey})) {
		    if ($_) {
			my ($prv,$restr)=split(/\&/,$_);
			my $trestr='';
			if ($restr ne 'F') {
			    my $i;
			    $trestr.=' (';
			    for ($i=0;$i<length($restr);$i++) {
				$trestr.=
			       Apache::lonnet::plaintext(substr($restr,$i,1));
				if ($i<length($restr)-1) { $trestr.=', '; }
			    }
			    $trestr.=')';
			}
			$r->print('<li>'.
				  Apache::lonnet::plaintext($prv).$trestr.
				  '</li>');
		    }
		}
		$r->print('</ul>');
	    }
	}
    }
    $r->print(&Apache::lonnet::getannounce());
    if ($advanced) {
	$r->print('<p><small><i>This is LON-CAPA '.
		  $r->dir_config('lonVersion').'</i></small></p>');
    }
    $r->print("</body></html>\n");
    return OK;
} 

1;
__END__

=head1 NAME

Apache::lonroles - User Roles Screen

=head1 SYNOPSIS

Invoked by /etc/httpd/conf/srm.conf:

 <Location /adm/roles>
 PerlAccessHandler       Apache::lonacc
 SetHandler perl-script
 PerlHandler Apache::lonroles
 ErrorDocument     403 /adm/login
 ErrorDocument	  500 /adm/errorhandler
 </Location>

=head1 OVERVIEW

=head2 Choosing Roles

C<lonroles> is a handler that allows a user to switch roles in
mid-session. LON-CAPA attempts to work with "No Role Specified", the
default role that a user has before selecting a role, as widely as
possible, but certain handlers for example need specification which
course they should act on, etc. Both in this scenario, and when the
handler determines via C<lonnet>'s C<&allowed> function that a certain
action is not allowed, C<lonroles> is used as error handler. This
allows the user to select another role which may have permission to do
what they were trying to do. C<lonroles> can also be accessed via the
B<CRS> button in the Remote Control. 

=begin latex

\begin{figure}
\begin{center}
\includegraphics[width=0.45\paperwidth,keepaspectratio]{Sample_Roles_Screen}
  \caption{\label{Sample_Roles_Screen}Sample Roles Screen} 
\end{center}
\end{figure}

=end latex

=head2 Role Initialization

The privileges for a user are established at login time and stored in the session environment. As a consequence, a new role does not become active till the next login. Handlers are able to query for privileges using C<lonnet>'s C<&allowed> function. When a user first logs in, their role is the "common" role, which means that they have the sum of all of their privileges. During a session it might become necessary to choose a particular role, which as a consequence also limits the user to only the privileges in that particular role.

=head1 INTRODUCTION

This module enables a user to select what role he wishes to
operate under (instructor, student, teaching assistant, course
coordinator, etc).  These roles are pre-established by the actions
of upper-level users.

This is part of the LearningOnline Network with CAPA project
described at http://www.lon-capa.org.

=head1 HANDLER SUBROUTINE

This routine is called by Apache and mod_perl.

=over 4

=item *

Roles Initialization (yes/no)

=item *

Get Error Message from Environment

=item *

Who is this?

=item *

Generate Page Output

=item *

Choice or no choice

=item *

Table

=item *

Privileges

=back

=cut

FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>
500 Internal Server Error

Internal Server Error

The server encountered an internal error or misconfiguration and was unable to complete your request.

Please contact the server administrator at root@localhost to inform them of the time this error occurred, and the actions you performed just before this error.

More information about this error may be available in the server error log.