index.php 2.11 KB
Newer Older
stc's avatar
stc committed
1
2
3
4
5
6
7
8
9
10
11
<?php
session_start();

if (!isset($_SESSION['ticket'])) {
  /*  If session is already open for current PHP file, user is already logged in, do nothing
      If session is not open on current PHP file, check if it is open on CAS server
        If it is open on CAS server retrieve session informations
        If it is not on open on CAS server, ask for login to CAS server
  */

  include $_SERVER['DOCUMENT_ROOT'].'/apisub/lib/cas.php';
12
13
  $cas = new CAS('https://cas.utc.fr/cas/','http');
  $info = $cas->authenticate();
stc's avatar
stc committed
14
15
16
17
18
19
20
  if ($info != -1) 	{
    $_SESSION['ticket'] = $_GET['ticket'];
    $_SESSION['utclogin'] = $info['cas:user'];
    $_SESSION['mail'] = $info['cas:attributes']['cas:mail'];
    $_SESSION['surname'] = strtoupper($info['cas:attributes']['cas:sn']);
    $_SESSION['firstname'] = $info['cas:attributes']['cas:givenName'];
  }
21
  else {
22
    $cas->login();
23
24
  }
  $_SESSION['localcopy'] =  true; //call localcopy once per session
stc's avatar
stc committed
25
26
}

27
include 'lib/db.php';
28
include 'lib/views.php';
29
include 'lib/admin.php';
30

stc's avatar
stc committed
31
$db = new DB();
32
if ($_SESSION['localcopy']) {
33
  $db->copyUser($_SESSION['utclogin'], $_SESSION['surname'], $_SESSION['firstname'], $_SESSION['mail']);
34
35
  $_SESSION['localcopy']=false;
}
36
37
38
39
40
$admin = new Admin($db);
$view = new Views($admin, $_SESSION['utclogin'], $_SESSION['surname'], $_SESSION['firstname']);

$view->printHtmlBegin();
$view->printUser($db->isResp($_SESSION['utclogin']), $db->isAdmin($_SESSION['utclogin']));
41
42
43
44
45
46
47
48
49

if (isset($_GET['mode'])) {
  if ($_GET['mode']=='resp') {
    $view->respValidation($_SESSION['utclogin']);
  }
  if ($_GET['mode']=='admin') {
    $view->adminFunction($_SESSION['utclogin']);
  }
}
stc's avatar
stc committed
50

Stephane Crozat's avatar
Fix #9  
Stephane Crozat committed
51
/** Subscription and unsubscription management **/
52
if (isset($_GET['api']) && $admin->isActive()) {
stc's avatar
stc committed
53
54
  if (isset($_GET['action'])) {
    if ($_GET['action']=='sub') {
55
      $db->subToApi($_SESSION['utclogin'], $_GET['api']);
stc's avatar
stc committed
56
57
    }
    elseif ($_GET['action']=='unsub') {
58
      $db->unsubToApi($_SESSION['utclogin'], $_GET['api']);
stc's avatar
stc committed
59
60
61
62
    }
  }
}

63
$view->printInstructions($db->config());
64
$view->printSubList($db->subList($_SESSION['utclogin']));
65
$view->printApiList($db->apiList('E', 2019), $_SESSION['utclogin']);
stc's avatar
stc committed
66
67

?>