if (!defined('LACONICA')) { exit(1); }
-class OpenidloginAction extends Action {
-
- function handle($args) {
- parent::handle($args);
- if (common_logged_in()) {
- common_user_error(_t('Already logged in.'));
- } else if ($_SERVER['REQUEST_METHOD'] == 'POST') {
- $this->start_openid_login();
- } else {
- $this->show_form();
- }
- }
-
- function show_form($error=NULL) {
- common_show_header(_t('OpenID Login'));
- if ($error) {
- common_element('div', array('class' => 'error'), $error);
- } else {
- common_element('div', 'instructions',
- _t('Login with an OpenID account.'));
- }
- common_element_start('form', array('method' => 'POST',
- 'id' => 'openidlogin',
- 'action' => common_local_url('openidlogin')));
- common_input('openid_url', _t('OpenID URL'));
- common_submit('submit', _t('Login'));
- common_element_end('form');
- common_show_footer();
- }
-
- function check_login() {
- # XXX: form token in $_SESSION to prevent XSS
- # XXX: login throttle
- $openid_url = $this->trimmed('openid_url');
- }
+require_once(INSTALLDIR.'/lib/openid.php');
+
+class OpenidloginAction extends Action
+{
+
+ function handle($args)
+ {
+ parent::handle($args);
+ if (common_logged_in()) {
+ $this->clientError(_('Already logged in.'));
+ } else if ($_SERVER['REQUEST_METHOD'] == 'POST') {
+ $openid_url = $this->trimmed('openid_url');
+
+ # CSRF protection
+ $token = $this->trimmed('token');
+ if (!$token || $token != common_session_token()) {
+ $this->show_form(_('There was a problem with your session token. Try again, please.'), $openid_url);
+ return;
+ }
+
+ $rememberme = $this->boolean('rememberme');
+
+ common_ensure_session();
+
+ $_SESSION['openid_rememberme'] = $rememberme;
+
+ $result = oid_authenticate($openid_url,
+ 'finishopenidlogin');
+
+ if (is_string($result)) { # error message
+ unset($_SESSION['openid_rememberme']);
+ $this->show_form($result, $openid_url);
+ }
+ } else {
+ $openid_url = oid_get_last();
+ $this->show_form(null, $openid_url);
+ }
+ }
+
+ function get_instructions()
+ {
+ return _('Login with an [OpenID](%%doc.openid%%) account.');
+ }
+
+ function show_top($error=null)
+ {
+ if ($error) {
+ $this->element('div', array('class' => 'error'), $error);
+ } else {
+ $instr = $this->get_instructions();
+ $output = common_markup_to_html($instr);
+ $this->elementStart('div', 'instructions');
+ $this->raw($output);
+ $this->elementEnd('div');
+ }
+ }
+
+ function show_form($error=null, $openid_url)
+ {
+ common_show_header(_('OpenID Login'), null, $error, array($this, 'show_top'));
+ $formaction = common_local_url('openidlogin');
+ $this->elementStart('form', array('method' => 'post',
+ 'id' => 'openidlogin',
+ 'action' => $formaction));
+ $this->hidden('token', common_session_token());
+ $this->input('openid_url', _('OpenID URL'),
+ $openid_url,
+ _('Your OpenID URL'));
+ $this->checkbox('rememberme', _('Remember me'), false,
+ _('Automatically login in the future; ' .
+ 'not for shared computers!'));
+ $this->submit('submit', _('Login'));
+ $this->elementEnd('form');
+ common_show_footer();
+ }
}