Merge branch 'master' of https://github.com/dimst23/Mattermost-LDAP into dimst23-master
This commit is contained in:
commit
0c5e9ae2e5
|
@ -5,3 +5,18 @@ deny from all
|
|||
<Files *.php>
|
||||
allow from all
|
||||
</Files>
|
||||
|
||||
# Only allow access to CSS files
|
||||
<Files *.css>
|
||||
allow from all
|
||||
</Files>
|
||||
|
||||
# Only allow access to image
|
||||
<Files *.png>
|
||||
allow from all
|
||||
</Files>
|
||||
|
||||
# Only allow access to html files
|
||||
<Files *.html>
|
||||
allow from all
|
||||
</Files>
|
||||
|
|
|
@ -23,7 +23,7 @@ if (!$server->validateAuthorizeRequest($request, $response)) {
|
|||
if (!isset($_SESSION['uid']))
|
||||
{
|
||||
//store the authorize request
|
||||
$explode_url=explode("/", strip_tags(trim($_SERVER['REQUEST_URI'])));
|
||||
$explode_url=explode("/", strip_tags(trim($_SERVER['REQUEST_URI'])));
|
||||
$_SESSION['auth_page']=end($explode_url);
|
||||
header('Location: index.php');
|
||||
exit();
|
||||
|
@ -35,85 +35,52 @@ if (empty($_POST)) {
|
|||
exit('
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<meta charset="UTF-8" />
|
||||
<link rel="stylesheet" type="text/css" href="./style.css">
|
||||
<title>Authorisation Mattermost</title>
|
||||
</head>
|
||||
<head>
|
||||
<link rel="stylesheet" type="text/css" href="./style.css">
|
||||
<title>Mattermost - LDAP Authorization</title>
|
||||
|
||||
<body>
|
||||
<link rel="stylesheet" href="https://use.fontawesome.com/releases/v5.3.1/css/all.css"
|
||||
integrity="sha384-mzrmE5qonljUremFsqc01SB46JvROS7bZs3IO2EmfFsd15uHvIt+Y8vEf7N7fWAU" crossorigin="anonymous">
|
||||
<link href="https://fonts.googleapis.com/css?family=Roboto:300,400" rel="stylesheet">
|
||||
|
||||
</head>
|
||||
|
||||
<center>
|
||||
<table background="images/login.png" border="0" width="729" height="343" cellspacing="1" cellpadding="4">
|
||||
<tr>
|
||||
<td width="40%"> </td>
|
||||
|
||||
<td width="60%">
|
||||
<table border="0" width="100%">
|
||||
|
||||
<tr>
|
||||
<td align="center">
|
||||
<div class="LoginTitle">Mattermost desires access to your LDAP data:</div>
|
||||
|
||||
|
||||
<form method="post">
|
||||
|
||||
<table border="0" width="90%" cellpadding="1">
|
||||
<body>
|
||||
<div id="form-wrapper" style="text-align: center;">
|
||||
<div id="form_credentials">
|
||||
<h1>LDAP Authentication</h1>
|
||||
<div id="form_icon">
|
||||
<img src="./images/auth_icon.png" alt="authentication icon" >
|
||||
</div>
|
||||
<br>
|
||||
<h2>Authorize Mattermost to get the following data:</h2>
|
||||
<table>
|
||||
<tr>
|
||||
<td colspan="2" align="left">
|
||||
|
||||
<div class="messageLogin" align="center">
|
||||
|
||||
</div>
|
||||
|
||||
</td>
|
||||
<td>
|
||||
<strong>Full Name</strong><br/>
|
||||
<strong>E-mail</strong><br/>
|
||||
For the user <strong>' . $_SESSION['uid'] . '</strong><br/>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td align="center" width="100%" class="LoginUsername">
|
||||
Login as : <b>' . $_SESSION['uid'] . ' </b>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td align="left" width="100%" class="LoginUsername">
|
||||
|
||||
<br/>
|
||||
Requested Data : <br/>
|
||||
-> Username,<br/>
|
||||
-> Full Name,<br/>
|
||||
-> Email
|
||||
|
||||
</td>
|
||||
</tr>
|
||||
<tr><td colspan="2"> </td></tr>
|
||||
<tr>
|
||||
<td colspan="2" align="center"> <input type="submit" class="GreenButton" name="authorized" value="Authorize" >
|
||||
<input type="submit" class="GreenButton" name="authorized" value="Deny" > </td>
|
||||
|
||||
</tr>
|
||||
|
||||
|
||||
</table>
|
||||
</form>
|
||||
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</center>
|
||||
</body>
|
||||
<br>
|
||||
|
||||
<form method="POST">
|
||||
<input type="submit" value="Authorize" name="authorized" id="input_accept" class="input_field">
|
||||
<input type="submit" value="Deny" name="authorized" id="input_deny" class="input_field">
|
||||
</form>
|
||||
</div>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
');
|
||||
');
|
||||
}
|
||||
|
||||
// print the authorization code if the user has authorized your client
|
||||
$is_authorized = ($_POST['authorized'] === 'Authorize');
|
||||
$server->handleAuthorizeRequest($request, $response, $is_authorized,strtolower($_SESSION['uid']));
|
||||
|
||||
if ($is_authorized)
|
||||
if ($is_authorized)
|
||||
{
|
||||
// This is only here so that you get to see your code in the cURL request. Otherwise, we'd redirect back to the client
|
||||
$code = substr($response->getHttpHeader('Location'), strpos($response->getHttpHeader('Location'), 'code=')+5, 40);
|
||||
|
@ -122,4 +89,4 @@ if ($is_authorized)
|
|||
}
|
||||
|
||||
// Send message in case of error
|
||||
$response->send();
|
||||
$response->send();
|
||||
|
|
|
@ -0,0 +1,41 @@
|
|||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<link rel="stylesheet" type="text/css" href="./style.css">
|
||||
<title>LDAP Connection Interface</title>
|
||||
|
||||
<link rel="stylesheet" href="https://use.fontawesome.com/releases/v5.3.1/css/all.css"
|
||||
integrity="sha384-mzrmE5qonljUremFsqc01SB46JvROS7bZs3IO2EmfFsd15uHvIt+Y8vEf7N7fWAU" crossorigin="anonymous">
|
||||
<link href="https://fonts.googleapis.com/css?family=Roboto:300,400" rel="stylesheet">
|
||||
|
||||
</head>
|
||||
|
||||
<body>
|
||||
<div id="form-wrapper" style="text-align: center;">
|
||||
<div id="form_credentials">
|
||||
<h1>LDAP Authentication</h1>
|
||||
<div id="form_icon_prompt">
|
||||
<img src="./images/prompt_icon.png" alt="authentication icon" >
|
||||
</div>
|
||||
<br>
|
||||
|
||||
<form method="POST">
|
||||
<div class="input_container">
|
||||
<i class="fas fa-user"></i>
|
||||
<input placeholder="Username" type="text" name="user" id="field_username" class="input_field">
|
||||
</div><br>
|
||||
|
||||
<div class="input_container">
|
||||
<i class="fas fa-lock"></i>
|
||||
<input placeholder="Password" type="password" name="password" id="field_password" class="input_field">
|
||||
</div><br>
|
||||
|
||||
<div class="err_msg">
|
||||
</div>
|
||||
|
||||
<input type="submit" value="Login" name="login" id="input_login" class="input_field">
|
||||
</form>
|
||||
</div>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
Binary file not shown.
Before Width: | Height: | Size: 977 B |
Binary file not shown.
After Width: | Height: | Size: 45 KiB |
Binary file not shown.
Before Width: | Height: | Size: 39 KiB |
Binary file not shown.
After Width: | Height: | Size: 44 KiB |
149
oauth/index.php
149
oauth/index.php
|
@ -1,72 +1,89 @@
|
|||
<?php
|
||||
session_start();
|
||||
?>
|
||||
/**
|
||||
* @author Denis CLAVIER <clavierd at gmail dot com>
|
||||
* A modified verion by dimst23
|
||||
*/
|
||||
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<link rel="stylesheet" type="text/css" href="./style.css">
|
||||
<title>LDAP Connection Interface</title>
|
||||
</head>
|
||||
|
||||
<body>
|
||||
<center>
|
||||
<table background="images/login.png" border="0" width="733" height="348" cellspacing="1" cellpadding="4">
|
||||
<tr>
|
||||
<td width="40%"> </td>
|
||||
|
||||
<td width="60%">
|
||||
<table border="0" width="100%">
|
||||
// include our LDAP object
|
||||
require_once __DIR__.'/LDAP/LDAP.php';
|
||||
require_once __DIR__.'/LDAP/config_ldap.php';
|
||||
|
||||
<tr>
|
||||
<td align="center">
|
||||
<div class="LoginTitle">LDAP Authentification</div>
|
||||
|
||||
$prompt_template = new DOMDocument();
|
||||
$prompt_template->loadHTMLFile('form_prompt.html');
|
||||
|
||||
<form method="post" action="connexion.php">
|
||||
|
||||
<table border="0" width="90%" cellpadding="1">
|
||||
<tr>
|
||||
<td colspan="2" align="left">
|
||||
|
||||
<div class="messageLogin" align="center">
|
||||
|
||||
</div>
|
||||
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td align="left" width="40%" class="LoginUsername">
|
||||
Username:
|
||||
</td>
|
||||
<td width="60%">
|
||||
<input type="text" name="user" size="25" value="" >
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td align="left" width="40%" class="LoginUsername">
|
||||
Password:
|
||||
</td>
|
||||
<td width="60%">
|
||||
<input type="password" name="password" size="25" value="" >
|
||||
</td>
|
||||
</tr>
|
||||
<tr><td colspan="2"> </td></tr>
|
||||
<tr>
|
||||
<td colspan="2" align="center"> <input type="submit" class="GreenButton" name="login" value=" Connect " > </td>
|
||||
</tr>
|
||||
|
||||
|
||||
</table>
|
||||
</form>
|
||||
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</center>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
function messageShow($html_template, $message = 'No Msg') {
|
||||
$modification_node = $html_template->getElementsByTagName('div')->item(5);
|
||||
$page_fragment = $html_template->createDocumentFragment();
|
||||
$page_fragment->appendXML($message);
|
||||
|
||||
$modification_node->appendChild($page_fragment);
|
||||
|
||||
echo $html_template->saveHTML();
|
||||
}
|
||||
|
||||
|
||||
// Verify all fields have been filled
|
||||
if (empty($_POST['user']) || empty($_POST['password']))
|
||||
{
|
||||
if (empty($_POST['user'])) {
|
||||
messageShow($prompt_template, 'Username field can\'t be empty.');
|
||||
} else {
|
||||
messageShow($prompt_template, 'Password field can\'t be empty.');
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
// Check received data length (to prevent code injection)
|
||||
if (strlen($_POST['user']) > 64)
|
||||
{
|
||||
messageShow($prompt_template, 'Username has incorrect format ... Please try again');
|
||||
}
|
||||
elseif (strlen($_POST['password']) > 64 || strlen($_POST['password']) <= 7)
|
||||
{
|
||||
messageShow($prompt_template, 'Password has incorrect format ... Please try again');
|
||||
}
|
||||
else
|
||||
{
|
||||
// Remove every html tag and useless space on username (to prevent XSS)
|
||||
$user=strtolower(strip_tags(htmlspecialchars(trim($_POST['user']))));
|
||||
$password=$_POST['password'];
|
||||
|
||||
// Open a LDAP connection
|
||||
$ldap = new LDAP($ldap_host,$ldap_port,$ldap_version);
|
||||
|
||||
// Check user credential on LDAP
|
||||
try{
|
||||
$authenticated = $ldap->checkLogin($user,$password,$ldap_search_attribute,$ldap_filter,$ldap_base_dn,$ldap_bind_dn,$ldap_bind_pass);
|
||||
}
|
||||
catch (Exception $e)
|
||||
{
|
||||
$authenticated = false;
|
||||
}
|
||||
|
||||
// If user is authenticated
|
||||
if ($authenticated)
|
||||
{
|
||||
$_SESSION['uid']=$user;
|
||||
|
||||
// If user came here with an autorize request, redirect him to the authorize page. Else prompt a simple message.
|
||||
if (isset($_SESSION['auth_page']))
|
||||
{
|
||||
$auth_page=$_SESSION['auth_page'];
|
||||
header('Location: ' . $auth_page);
|
||||
exit();
|
||||
}
|
||||
else
|
||||
{
|
||||
messageShow($prompt_template, 'Congratulation you are authenticated ! <br /><br /> However there is nothing to do here ...');
|
||||
}
|
||||
}
|
||||
// check login on LDAP has failed. Login and password were invalid or LDAP is unreachable
|
||||
else
|
||||
{
|
||||
messageShow($prompt_template, 'Authentication failed ... Check your username and password.<br />If the error persists contact your administrator.<br /><br />');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
244
oauth/style.css
244
oauth/style.css
|
@ -1,57 +1,187 @@
|
|||
html
|
||||
{
|
||||
height: 100%;
|
||||
margin: 0;
|
||||
}
|
||||
|
||||
body {
|
||||
font-family:"Tahoma","Arial", serif;
|
||||
font-size:8px;
|
||||
font-weight: normal;
|
||||
color: black;
|
||||
text-decoration:none;
|
||||
background-color: white;
|
||||
height: 100%;
|
||||
margin: 0;
|
||||
}
|
||||
|
||||
|
||||
.LoginTitle {
|
||||
color: #000000;
|
||||
font-family : "Tahoma","Arial", serif;
|
||||
font-size : 18pt;
|
||||
font-weight: normal;
|
||||
}
|
||||
|
||||
.LoginUsername {
|
||||
color: #000000;
|
||||
font-family : "Tahoma","Arial", serif;
|
||||
font-size : 14pt;
|
||||
font-weight: normal;
|
||||
}
|
||||
|
||||
.LoginComment {
|
||||
color: #000000;
|
||||
font-family : "Tahoma","Arial", serif;
|
||||
font-size : 8pt;
|
||||
font-weight: normal;
|
||||
}
|
||||
|
||||
.GreenButton
|
||||
{
|
||||
color: white;
|
||||
font-family : "Tahoma", "Arial", serif;
|
||||
font-size : 10pt;
|
||||
font-weight: normal;
|
||||
height: 28px;
|
||||
background: transparent url(images/ButtonGreen.png) repeat-x left top;
|
||||
border: solid 1px #50B4AE;
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.messageLogin {
|
||||
color: Yellow;
|
||||
font-family : "Tahoma", "Arial", serif;
|
||||
font-size : 8pt;
|
||||
font-weight: bold;
|
||||
}
|
||||
:root {
|
||||
--input_bg: #E5E5E5;
|
||||
--input_hover:#eaeaea;
|
||||
--accept_bg: #1FCC44;
|
||||
--accept_hover: #40e263;
|
||||
--deny_bg: #cc1f1f;
|
||||
--deny_hover: #e24040;
|
||||
--icon_color:#6b6b6b;
|
||||
}
|
||||
|
||||
html {
|
||||
height: 100%;
|
||||
margin: 0;
|
||||
}
|
||||
|
||||
/* Overide browser defaults */
|
||||
* {
|
||||
padding: 0;
|
||||
margin: 0;
|
||||
box-sizing: border-box;
|
||||
}
|
||||
|
||||
/* Style the form wrapper */
|
||||
body {
|
||||
/* Set custom font */
|
||||
font-family: 'Roboto', sans-serif;
|
||||
margin: auto;
|
||||
text-align: center;
|
||||
}
|
||||
|
||||
table {
|
||||
margin-left: auto;
|
||||
margin-right: auto;
|
||||
font-size: larger;
|
||||
border-style: solid;
|
||||
border-width: 2px;
|
||||
margin-top: 5%;
|
||||
}
|
||||
|
||||
/* Format the different images*/
|
||||
#form_icon,
|
||||
#form_icon_prompt {
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
align-items: center;
|
||||
margin-top: 5%;
|
||||
}
|
||||
|
||||
#form_icon img {
|
||||
width: 100%;
|
||||
max-width: 450px;
|
||||
}
|
||||
|
||||
#form_icon_prompt img {
|
||||
width: 50%;
|
||||
max-width: 350px;
|
||||
}
|
||||
|
||||
|
||||
/* Style the form_credentials */
|
||||
#form_credentials {
|
||||
/* Center the content */
|
||||
display: inline-block;
|
||||
justify-content: center;
|
||||
align-items: center;
|
||||
position: absolute;
|
||||
transform: translate(-50%, 25%);
|
||||
}
|
||||
|
||||
/* Style input fields */
|
||||
.input_container {
|
||||
background-color: var(--input_bg);
|
||||
|
||||
/* Vertically align icon and text inside the div*/
|
||||
display: flex;
|
||||
align-items: center;
|
||||
padding-left: 20px;
|
||||
}
|
||||
|
||||
.input_container:hover {
|
||||
background-color: var(--input_hover);
|
||||
}
|
||||
|
||||
.input_container,
|
||||
#input_accept,
|
||||
#input_deny,
|
||||
#input_login {
|
||||
height: 60px;
|
||||
|
||||
/* Make the borders more round */
|
||||
border-radius: 12px;
|
||||
width: 100%;
|
||||
}
|
||||
|
||||
.input_field {
|
||||
/* Customize the input tag with lighter font and some padding*/
|
||||
color: var(--icon_color);
|
||||
background-color: inherit;
|
||||
width: 95%;
|
||||
border: none;
|
||||
font-size: 1.3rem;
|
||||
font-weight: 400;
|
||||
padding-left: 6.5%;
|
||||
}
|
||||
|
||||
.input_field:hover,
|
||||
.input_field:focus {
|
||||
/* Remove the outline */
|
||||
outline: none;
|
||||
}
|
||||
|
||||
#input_accept,
|
||||
#input_deny,
|
||||
#input_login {
|
||||
/* Submit button has a different color and different padding */
|
||||
background-color: var(--accept_bg);
|
||||
padding-left: 0;
|
||||
font-weight: bold;
|
||||
color: white;
|
||||
text-transform: capitalize;
|
||||
text-align: center;
|
||||
display: inline-block;
|
||||
margin-top: 25%;
|
||||
margin-right: 2%;
|
||||
width: 50%;
|
||||
}
|
||||
|
||||
#input_accept:hover,
|
||||
#input_deny:hover,
|
||||
#input_login:hover {
|
||||
/* Simple color transition on hover */
|
||||
transition: background-color, 500ms;
|
||||
cursor: pointer;
|
||||
}
|
||||
|
||||
#input_accept,
|
||||
#input_deny {
|
||||
width: 45%;
|
||||
margin-top: 6%;
|
||||
}
|
||||
|
||||
#input_deny {
|
||||
background-color: var(--deny_bg);
|
||||
}
|
||||
|
||||
#input_deny:hover {
|
||||
background-color: var(--deny_hover);
|
||||
}
|
||||
|
||||
/* Format the error messages */
|
||||
.err_msg {
|
||||
color: red;
|
||||
font-weight: bold;
|
||||
font-size: 110%;
|
||||
}
|
||||
|
||||
|
||||
/* General page styling */
|
||||
h1,
|
||||
span {
|
||||
text-align: center;
|
||||
padding-bottom: 2%;
|
||||
padding-top: 0%;
|
||||
font-weight: bolder;
|
||||
font-size: 300%;
|
||||
}
|
||||
|
||||
|
||||
i {
|
||||
color: var(--icon_color);
|
||||
}
|
||||
|
||||
/* Make it responsive */
|
||||
@media screen and (max-width:768px) {
|
||||
|
||||
/* Make the layout a single column and add some margin to the wrapper */
|
||||
#form_wrapper {
|
||||
grid-template-columns: 1fr;
|
||||
margin-left: 10px;
|
||||
margin-right: 10px;
|
||||
}
|
||||
|
||||
/* On small screens we don't display the image */
|
||||
#form_icon {
|
||||
display: flex;
|
||||
}
|
||||
}
|
||||
|
|
Loading…
Reference in New Issue