# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
use strict;
+#use warnings; FIXME - Bug 2505
use Digest::MD5 qw(md5_base64);
use Storable qw(thaw freeze);
use URI::Escape;
=head1 DESCRIPTION
- The main function of this module is to provide
- authentification. However the get_template_and_user function has
- been provided so that a users login information is passed along
- automatically. This gets loaded into the template.
+The main function of this module is to provide
+authentification. However the get_template_and_user function has
+been provided so that a users login information is passed along
+automatically. This gets loaded into the template.
=head1 FUNCTIONS
-=over 2
-
-=item get_template_and_user
-
- my ($template, $borrowernumber, $cookie)
- = get_template_and_user(
- {
- template_name => "opac-main.tmpl",
- query => $query,
- type => "opac",
- authnotrequired => 1,
- flagsrequired => {borrow => 1, catalogue => '*', tools => 'import_patrons' },
- }
- );
-
- This call passes the C<query>, C<flagsrequired> and C<authnotrequired>
- to C<&checkauth> (in this module) to perform authentification.
- See C<&checkauth> for an explanation of these parameters.
-
- The C<template_name> is then used to find the correct template for
- the page. The authenticated users details are loaded onto the
- template in the HTML::Template LOOP variable C<USER_INFO>. Also the
- C<sessionID> is passed to the template. This can be used in templates
- if cookies are disabled. It needs to be put as and input to every
- authenticated page.
-
- More information on the C<gettemplate> sub can be found in the
- Output.pm module.
+=head2 get_template_and_user
+
+ my ($template, $borrowernumber, $cookie)
+ = get_template_and_user(
+ {
+ template_name => "opac-main.tmpl",
+ query => $query,
+ type => "opac",
+ authnotrequired => 1,
+ flagsrequired => {borrow => 1, catalogue => '*', tools => 'import_patrons' },
+ }
+ );
+
+This call passes the C<query>, C<flagsrequired> and C<authnotrequired>
+to C<&checkauth> (in this module) to perform authentification.
+See C<&checkauth> for an explanation of these parameters.
+
+The C<template_name> is then used to find the correct template for
+the page. The authenticated users details are loaded onto the
+template in the HTML::Template LOOP variable C<USER_INFO>. Also the
+C<sessionID> is passed to the template. This can be used in templates
+if cookies are disabled. It needs to be put as and input to every
+authenticated page.
+
+More information on the C<gettemplate> sub can be found in the
+Output.pm module.
=cut
+my $SEARCH_HISTORY_INSERT_SQL =<<EOQ;
+INSERT INTO search_history(userid, sessionid, query_desc, query_cgi, total, time )
+VALUES ( ?, ?, ?, ?, ?, FROM_UNIXTIME(?))
+EOQ
sub get_template_and_user {
my $in = shift;
my $template =
}
}
- if (C4::Context->preference('GranularPermissions')) {
- if ( $flags ) {
- foreach my $module (keys %$all_perms) {
- if ( $flags->{$module} == 1) {
- foreach my $subperm (keys %{ $all_perms->{$module} }) {
- $template->param( "CAN_user_${module}_${subperm}" => 1 );
- }
- } elsif ( ref($flags->{$module}) ) {
- foreach my $subperm (keys %{ $flags->{$module} } ) {
- $template->param( "CAN_user_${module}_${subperm}" => 1 );
- }
- }
- }
- }
- } else {
+ if ( $flags ) {
foreach my $module (keys %$all_perms) {
- foreach my $subperm (keys %{ $all_perms->{$module} }) {
- $template->param( "CAN_user_${module}_${subperm}" => 1 );
+ if ( $flags->{$module} == 1) {
+ foreach my $subperm (keys %{ $all_perms->{$module} }) {
+ $template->param( "CAN_user_${module}_${subperm}" => 1 );
+ }
+ } elsif ( ref($flags->{$module}) ) {
+ foreach my $subperm (keys %{ $flags->{$module} } ) {
+ $template->param( "CAN_user_${module}_${subperm}" => 1 );
+ }
}
}
}
# And if there's a cookie with searches performed when the user was not logged in,
# we add them to the logged-in search history
- my @recentSearches;
my $searchcookie = $in->{'query'}->cookie('KohaOpacRecentSearches');
if ($searchcookie){
$searchcookie = uri_unescape($searchcookie);
- if (thaw($searchcookie)) {
- @recentSearches = @{thaw($searchcookie)};
- }
-
- if (@recentSearches > 0) {
- my $query = "INSERT INTO search_history(userid, sessionid, query_desc, query_cgi, total, time) VALUES";
- my $icount = 1;
- foreach my $asearch (@recentSearches) {
- $query .= "(";
- $query .= $borrowernumber . ", ";
- $query .= '"' . $in->{'query'}->cookie("CGISESSID") . "\", ";
- $query .= '"' . $asearch->{'query_desc'} . "\", ";
- $query .= '"' . $asearch->{'query_cgi'} . "\", ";
- $query .= $asearch->{'total'} . ", ";
- $query .= 'FROM_UNIXTIME(' . $asearch->{'time'} . "))";
- if ($icount < @recentSearches) { $query .= ", ";}
- $icount++;
- }
-
- my $sth = $dbh->prepare($query);
- $sth->execute;
+ my @recentSearches = @{thaw($searchcookie) || []};
+ if (@recentSearches) {
+ my $sth = $dbh->prepare($SEARCH_HISTORY_INSERT_SQL);
+ $sth->execute( $borrowernumber,
+ $in->{'query'}->cookie("CGISESSID"),
+ $_->{'query_desc'},
+ $_->{'query_cgi'},
+ $_->{'total'},
+ $_->{'time'},
+ ) foreach @recentSearches;
# And then, delete the cookie's content
my $newsearchcookie = $in->{'query'}->cookie(
}
# Anonymous opac search history
# If opac search history is enabled and at least one search has already been performed
- if (C4::Context->preference('EnableOpacSearchHistory') && $in->{'query'}->cookie('KohaOpacRecentSearches')) {
+ if (C4::Context->preference('EnableOpacSearchHistory')) {
+ my $searchcookie = $in->{'query'}->cookie('KohaOpacRecentSearches');
+ if ($searchcookie){
+ $searchcookie = uri_unescape($searchcookie);
+ my @recentSearches = @{thaw($searchcookie) || []};
# We show the link in opac
- if (thaw(uri_unescape($in->{'query'}->cookie('KohaOpacRecentSearches')))) {
- my @recentSearches = @{thaw(uri_unescape($in->{'query'}->cookie('KohaOpacRecentSearches')))};
- if (@recentSearches > 0) {
+ if (@recentSearches) {
$template->param(ShowOpacRecentSearchLink => 1);
}
}
if ( $in->{'type'} eq "intranet" ) {
$template->param(
AmazonContent => C4::Context->preference("AmazonContent"),
+ AmazonCoverImages => C4::Context->preference("AmazonCoverImages"),
+ AmazonEnabled => C4::Context->preference("AmazonEnabled"),
AmazonSimilarItems => C4::Context->preference("AmazonSimilarItems"),
AutoLocation => C4::Context->preference("AutoLocation"),
"BiblioDefaultView".C4::Context->preference("IntranetBiblioDefaultView") => 1,
OPACSerialIssueDisplayCount => C4::Context->preference("OPACSerialIssueDisplayCount"),
OpacAddMastheadLibraryPulldown => C4::Context->preference("OpacAddMastheadLibraryPulldown"),
OPACXSLTDetailsDisplay => C4::Context->preference("OPACXSLTDetailsDisplay"),
- OPACXSLTResultsDisplay => C4::Context->preference("OPACXSLTResultsDisplay")
+ OPACXSLTResultsDisplay => C4::Context->preference("OPACXSLTResultsDisplay"),
+ SyndeticsClientCode => C4::Context->preference("SyndeticsClientCode"),
+ SyndeticsEnabled => C4::Context->preference("SyndeticsEnabled"),
+ SyndeticsCoverImages => C4::Context->preference("SyndeticsCoverImages"),
+ SyndeticsTOC => C4::Context->preference("SyndeticsTOC"),
+ SyndeticsSummary => C4::Context->preference("SyndeticsSummary"),
+ SyndeticsEditions => C4::Context->preference("SyndeticsEditions"),
+ SyndeticsExcerpt => C4::Context->preference("SyndeticsExcerpt"),
+ SyndeticsReviews => C4::Context->preference("SyndeticsReviews"),
+ SyndeticsAuthorNotes => C4::Context->preference("SyndeticsAuthorNotes"),
+ SyndeticsAwards => C4::Context->preference("SyndeticsAwards"),
+ SyndeticsSeries => C4::Context->preference("SyndeticsSeries"),
+ SyndeticsCoverImageSize => C4::Context->preference("SyndeticsCoverImageSize"),
);
}
$template->param(listloop=>[{shelfname=>"Freelist", shelfnumber=>110}]);
return ( $template, $borrowernumber, $cookie, $flags);
}
-=item checkauth
+=head2 checkauth
($userid, $cookie, $sessionID) = &checkauth($query, $noauth, $flagsrequired, $type);
proceed. To make sure that access control is correct, the
C<$flagsrequired> parameter must be specified correctly.
-If the GranularPermissions system preference is ON, the
-value of each key in the C<flagsrequired> hash takes on an additional
-meaning, e.g.,
+Koha also has a concept of sub-permissions, also known as
+granular permissions. This makes the value of each key
+in the C<flagsrequired> hash take on an additional
+meaning, i.e.,
-=item 1
+ 1
The user must have access to all subfunctions of the module
specified by the hash key.
-=item *
+ *
The user must have access to at least one subfunction of the module
specified by the hash key.
-=item specific permission, e.g., 'export_catalog'
+ specific permission, e.g., 'export_catalog'
The user must have access to the specific subfunction list, which
must correspond to a row in the permissions table.
exit;
}
-=item check_api_auth
+=head2 check_api_auth
($status, $cookie, $sessionId) = check_api_auth($query, $userflags);
Possible return values in C<$status> are:
-=over 4
+=over
=item "ok" -- user authenticated; C<$cookie> and C<$sessionid> have valid values.
}
}
-=item check_cookie_auth
+=head2 check_cookie_auth
($status, $sessionId) = check_api_auth($cookie, $userflags);
Possible return values in C<$status> are:
-=over 4
+=over
=item "ok" -- user authenticated; C<$sessionID> have valid values.
}
}
-=item get_session
+=head2 get_session
use CGI::Session;
my $session = get_session($sessionID);
return 0;
}
-=item getuserflags
+=head2 getuserflags
my $authflags = getuserflags($flags, $userid, [$dbh]);
return $userflags;
}
-=item get_user_subpermissions
+=head2 get_user_subpermissions
-=over 4
-
-my $user_perm_hashref = get_user_subpermissions($userid);
-
-=back
+ $user_perm_hashref = get_user_subpermissions($userid);
Given the userid (note, not the borrowernumber) of a staff user,
return a hashref of hashrefs of the specific subpermissions
accorded to the user. An example return is
-{
+ {
tools => {
export_catalog => 1,
import_patrons => 1,
}
-}
+ }
The top-level hash-key is a module or function code from
userflags.flag, while the second-level key is a code
return $user_perms;
}
-=item get_all_subpermissions
+=head2 get_all_subpermissions
-=over 4
-
-my $perm_hashref = get_all_subpermissions();
-
-=back
+ my $perm_hashref = get_all_subpermissions();
Returns a hashref of hashrefs defining all specific
permissions currently defined. The return value
return $all_perms;
}
-=item haspermission
+=head2 haspermission
$flags = ($userid, $flagsrequired);
}
return $flags if $flags->{superlibrarian};
foreach my $module ( keys %$flagsrequired ) {
- if (C4::Context->preference('GranularPermissions')) {
- my $subperm = $flagsrequired->{$module};
- if ($subperm eq '*') {
- return 0 unless ( $flags->{$module} == 1 or ref($flags->{$module}) );
- } else {
- return 0 unless ( $flags->{$module} == 1 or
- ( ref($flags->{$module}) and
- exists $flags->{$module}->{$subperm} and
- $flags->{$module}->{$subperm} == 1
- )
- );
- }
+ my $subperm = $flagsrequired->{$module};
+ if ($subperm eq '*') {
+ return 0 unless ( $flags->{$module} == 1 or ref($flags->{$module}) );
} else {
- return 0 unless ( $flags->{$module} );
+ return 0 unless ( $flags->{$module} == 1 or
+ ( ref($flags->{$module}) and
+ exists $flags->{$module}->{$subperm} and
+ $flags->{$module}->{$subperm} == 1
+ )
+ );
}
}
return $flags;
1;
__END__
-=back
-
=head1 SEE ALSO
CGI(3)