require_once(INSTALLDIR.'/lib/openid.php');
-class OpenidloginAction extends Action {
+class OpenidloginAction extends Action
+{
- function handle($args) {
- parent::handle($args);
- if (common_logged_in()) {
- common_user_error(_t('Already logged in.'));
- } else if ($_SERVER['REQUEST_METHOD'] == 'POST') {
- $openid_url = $this->trimmed('openid_url');
- $result = oid_authenticate($openid_url,
- 'finishopenidlogin');
- if (is_string($result)) { # error message
- $this->show_form($result, $openid_url);
- }
- } else {
- $openid_url = oid_get_last();
- $this->show_form(NULL, $openid_url);
- }
- }
+ function handle($args)
+ {
+ parent::handle($args);
+ if (common_logged_in()) {
+ $this->clientError(_('Already logged in.'));
+ } else if ($_SERVER['REQUEST_METHOD'] == 'POST') {
+ $openid_url = $this->trimmed('openid_url');
- function get_instructions() {
- return _t('Login with an [OpenID](%%doc.openid%%) account.');
- }
+ # CSRF protection
+ $token = $this->trimmed('token');
+ if (!$token || $token != common_session_token()) {
+ $this->show_form(_('There was a problem with your session token. Try again, please.'), $openid_url);
+ return;
+ }
- function show_top($error=NULL) {
- if ($error) {
- common_element('div', array('class' => 'error'), $error);
- } else {
- $instr = $this->get_instructions();
- $output = common_markup_to_html($instr);
- common_element_start('div', 'instructions');
- common_raw($output);
- common_element_end('div');
- }
- }
+ $rememberme = $this->boolean('rememberme');
+
+ common_ensure_session();
+
+ $_SESSION['openid_rememberme'] = $rememberme;
+
+ $result = oid_authenticate($openid_url,
+ 'finishopenidlogin');
+
+ if (is_string($result)) { # error message
+ unset($_SESSION['openid_rememberme']);
+ $this->show_form($result, $openid_url);
+ }
+ } else {
+ $openid_url = oid_get_last();
+ $this->show_form(null, $openid_url);
+ }
+ }
- function show_form($error=NULL, $openid_url) {
- common_show_header(_t('OpenID Login'), NULL, $error, array($this, 'show_top'));
- $formaction = common_local_url('openidlogin');
- common_element_start('form', array('method' => 'POST',
- 'id' => 'openidlogin',
- 'action' => $formaction));
- common_input('openid_url', _t('OpenID URL'),
- $openid_url,
- _t('Your OpenID URL'));
- common_submit('submit', _t('Login'));
- common_element_end('form');
- common_show_footer();
- }
+ function get_instructions()
+ {
+ return _('Login with an [OpenID](%%doc.openid%%) account.');
+ }
+
+ function show_top($error=null)
+ {
+ if ($error) {
+ $this->element('div', array('class' => 'error'), $error);
+ } else {
+ $instr = $this->get_instructions();
+ $output = common_markup_to_html($instr);
+ $this->elementStart('div', 'instructions');
+ $this->raw($output);
+ $this->elementEnd('div');
+ }
+ }
+
+ function show_form($error=null, $openid_url)
+ {
+ common_show_header(_('OpenID Login'), null, $error, array($this, 'show_top'));
+ $formaction = common_local_url('openidlogin');
+ $this->elementStart('form', array('method' => 'post',
+ 'id' => 'openidlogin',
+ 'action' => $formaction));
+ $this->hidden('token', common_session_token());
+ $this->input('openid_url', _('OpenID URL'),
+ $openid_url,
+ _('Your OpenID URL'));
+ $this->checkbox('rememberme', _('Remember me'), false,
+ _('Automatically login in the future; ' .
+ 'not for shared computers!'));
+ $this->submit('submit', _('Login'));
+ $this->elementEnd('form');
+ common_show_footer();
+ }
}