From c75c451a4cb047984bcd9c80b8918fb2015bf661 Mon Sep 17 00:00:00 2001 From: Jacek Kowalski <jkowalsk@student.agh.edu.pl> Date: Sat, 05 Sep 2015 23:40:16 +0000 Subject: [PATCH] Add Travis CI configuration file --- uphpCAS.php | 92 ++++++++++++++++++++++++++++++++++------------ 1 files changed, 68 insertions(+), 24 deletions(-) diff --git a/uphpCAS.php b/uphpCAS.php index e14b20c..955d204 100644 --- a/uphpCAS.php +++ b/uphpCAS.php @@ -14,6 +14,8 @@ protected $serverUrl = ''; protected $serviceUrl; protected $sessionName = 'uphpCAS-user'; + protected $method = 'POST'; + protected $caFile = NULL; function __construct($serverUrl = NULL, $serviceUrl = NULL, $sessionName = NULL) { if($serverUrl != NULL) { @@ -28,6 +30,10 @@ if($sessionName) { $this->sessionName = $sessionName; + } + + if(version_compare(PHP_VERSION, '5.6', '<')) { + $this->caFile = $this->findCaFile(); } } @@ -51,6 +57,8 @@ $url .= ':'.$port; } $url .= $_SERVER['REQUEST_URI']; + + return $url; } public function getServerUrl() { @@ -74,12 +82,35 @@ $this->sessionName = $sessionName; } + public function getMethod() { + return $this->method; + } + public function setMethod($method) { + if($method != 'GET' && $method != 'POST') { + throw new DomainException('Unsupported CAS response' + .' method: '.$method); + } + $this->method = $method; + } + + public function getCaFile() { + return $this->caFile; + } + public function setCaFile($caFile) { + if(!is_file($caFile)) { + throw new DomainException('Invalid CA file: '.$caFile); + } + $this->caFile = $caFile; + } + public function loginUrl() { - return $this->serverUrl.'/login?method=POST&service='.urlencode($this->serviceUrl); + return $this->serverUrl.'/login?method='.$this->method + .'&service='.urlencode($this->serviceUrl); } public function logoutUrl($returnUrl = NULL) { - return $this->serverUrl.'/logout'.($returnUrl ? '?service='.urlencode($returnUrl) : ''); + return $this->serverUrl.'/logout' + .($returnUrl ? '?service='.urlencode($returnUrl) : ''); } public function logout($returnUrl = NULL) { @@ -112,7 +143,25 @@ } } - public function verifyTicket($ticket) { + protected function findCaFile() { + $cafiles = array( + '/etc/ssl/certs/ca-certificates.crt', + '/etc/ssl/certs/ca-bundle.crt', + '/etc/pki/tls/certs/ca-bundle.crt', + ); + + $cafile = NULL; + foreach($cafiles as $file) { + if(is_file($file)) { + $cafile = $file; + break; + } + } + + return $cafile; + } + + protected function createStreamContext($hostname) { $context = array( 'http' => array( 'method' => 'GET', @@ -128,31 +177,26 @@ ), ); - if(version_compare(PHP_VERSION, '5.6', '<')) { - $cafiles = array( - '/etc/ssl/certs/ca-certificates.crt', - '/etc/ssl/certs/ca-bundle.crt', - '/etc/pki/tls/certs/ca-bundle.crt', - ); - $cafile = NULL; - foreach($cafiles as $file) { - if(is_file($file)) { - $cafile = $file; - break; - } - } - - $url = parse_url($this->serverUrl); - $context['ssl']['cafile'] = $cafile; - $context['ssl']['ciphers'] = 'ECDH:DH:AES:CAMELLIA:!SSLv2:!aNULL' - .':!eNULL:!EXPORT:!DES:!3DES:!MD5:!RC4:!ADH:!PSK:!SRP'; - $context['ssl']['CN_match'] = $url['host']; + if($this->caFile) { + $context['ssl']['cafile'] = $this->caFile; } + + if(version_compare(PHP_VERSION, '5.6', '<')) { + $context['ssl']['ciphers'] = 'ECDH:DH:AES:CAMELLIA:!SSLv2:!aNULL' + .':!eNULL:!EXPORT:!DES:!3DES:!MD5:!RC4:!ADH:!PSK:!SRP'; + $context['ssl']['CN_match'] = $hostname; + } + + return stream_context_create($context); + } + + public function verifyTicket($ticket) { + $url = parse_url($this->serverUrl); + $context = $this->createStreamContext($url['host']); $data = file_get_contents($this->serverUrl .'/serviceValidate?service='.urlencode($this->serviceUrl) - .'&ticket='.urlencode($ticket), - FALSE, stream_context_create($context)); + .'&ticket='.urlencode($ticket), FALSE, $context); if($data === FALSE) { throw new JasigException('Authentication error: CAS server is unavailable'); } -- Gitblit v1.9.1