Clarify and simplify how session is destroyed and separate from session restore mechanism
[squirrelmail.git] / src / login.php
CommitLineData
59177427 1<?php
895905c0 2
35586184 3/**
4 * login.php -- simple login screen
5 *
35586184 6 * This a simple login screen. Some housekeeping is done to clean
7 * cookies and find language.
8 *
4b5049de 9 * @copyright &copy; 1999-2007 The SquirrelMail Project Team
4b4abf93 10 * @license http://opensource.org/licenses/gpl-license.php GNU Public License
30967a1e 11 * @version $Id$
8f6f9ba5 12 * @package squirrelmail
35586184 13 */
8e2ed807 14
ebd2391c 15/** This is the login page */
16define('PAGE_NAME', 'login');
17
30967a1e 18/**
202bcbcc 19 * Include the SquirrelMail initialization file.
30967a1e 20 */
202bcbcc 21require('../include/init.php');
22
86725763 23/* SquirrelMail required files. */
ea348fd3 24require_once(SM_PATH . 'functions/imap_general.php');
a34d6890 25require_once(SM_PATH . 'functions/forms.php');
98f2ee76 26
8f6f9ba5 27/**
98f2ee76 28 * $squirrelmail_language is set by a cookie when the user selects
29 * language and logs out
30 */
5e2b6751 31set_up_language($squirrelmail_language, TRUE, TRUE);
d4e84069 32
c6f28eb1 33/**
98f2ee76 34 * In case the last session was not terminated properly, make sure
c6f28eb1 35 * we get a new one, but make sure we preserve session_expired_*
98f2ee76 36 */
5cf27342 37$sep = '';
38$sel = '';
39sqGetGlobalVar('session_expired_post', $sep, SQ_SESSION);
40sqGetGlobalVar('session_expired_location', $sel, SQ_SESSION);
c6f28eb1 41
5cf27342 42/* blow away session */
43sqsession_destroy();
44
45/**
46 * in some rare instances, the session seems to stick
47 * around even after destroying it (!!), so if it does,
48 * we'll manually flatten the $_SESSION data
49 */
50if (!empty($_SESSION)) {
51 $_SESSION = array();
52}
53
54/* start session and put session_expired_* variables back in session */
55@sqsession_is_active();
56if (!empty($sep) && !empty($sel)) {
c6f28eb1 57 sqsession_register($sep, 'session_expired_post');
58 sqsession_register($sel, 'session_expired_location');
c6f28eb1 59}
98f2ee76 60
8f6f9ba5 61/**
91e0dccc 62 * This detects if the IMAP server has logins disabled, and if so,
8f6f9ba5 63 * squelches the display of the login form and puts up a message
64 * explaining the situation.
65 */
6d611a76 66if($imap_auth_mech == 'login') {
c0c5cf6a 67 /**
f8a1ed5a 68 * detect disabled login, only when imapServerAddress contains
c0c5cf6a 69 * server address and not mapping. See sqimap_get_user_server()
70 */
71 if (substr($imapServerAddress, 0, 4) != "map:") {
72 $imap = sqimap_create_stream($imapServerAddress, $imapPort, $use_imap_tls);
73 $logindisabled = sqimap_capability($imap,'LOGINDISABLED');
74 sqimap_logout($imap);
75 if ($logindisabled) {
76 $string = _("The IMAP server is reporting that plain text logins are disabled.").'<br />'.
77 _("Using CRAM-MD5 or DIGEST-MD5 authentication instead may work.").'<br />';
78 if (!$use_imap_tls) {
79 $string .= _("Also, the use of TLS may allow SquirrelMail to login.").'<br />';
80 }
81 $string .= _("Please contact your system administrator and report this error.");
1b858d86 82 error_box($string);
83 // display footer (closes html tags) and stop script execution
84 $oTemplate->display('footer.tpl');
c0c5cf6a 85 exit;
6d611a76 86 }
ea348fd3 87 }
ea348fd3 88}
89
6e515418 90do_hook('login_cookie', $null);
98f2ee76 91
bca2d025 92$loginname_value = (sqGetGlobalVar('loginname', $loginname) ? htmlspecialchars($loginname) : '');
93
6e515418 94//FIXME: should be part of the template, not the core!
98f2ee76 95/* Output the javascript onload function. */
2c92ea9d 96$header = "<script type=\"text/javascript\">\n" .
98f2ee76 97 "<!--\n".
98 " function squirrelmail_loginpage_onload() {\n".
03ccb49b 99 " var textElements = 0;\n".
100 " for (i = 0; i < document.forms[0].elements.length; i++) {\n".
101 " if (document.forms[0].elements[i].type == \"text\" || document.forms[0].elements[i].type == \"password\") {\n".
102 " textElements++;\n".
103 " if (textElements == " . (isset($loginname) ? 2 : 1) . ") {\n".
104 " document.forms[0].elements[i].focus();\n".
105 " break;\n".
106 " }\n".
107 " }\n".
108 " }\n".
98f2ee76 109 " }\n".
110 "// -->\n".
111 "</script>\n";
dfb94cac 112
113if (@file_exists($theme[$theme_default]['PATH']))
114 @include ($theme[$theme_default]['PATH']);
115
832dc1e2 116if (! isset($color) || ! is_array($color)) {
117 // Add default color theme, if theme loading fails
118 $color = array();
119 $color[0] = '#dcdcdc'; /* light gray TitleBar */
120 $color[1] = '#800000'; /* red */
121 $color[2] = '#cc0000'; /* light red Warning/Error Messages */
122 $color[4] = '#ffffff'; /* white Normal Background */
123 $color[7] = '#0000cc'; /* blue Links */
124 $color[8] = '#000000'; /* black Normal text */
125}
126
c5330196 127displayHtmlHeader( "$org_name - " . _("Login"), $header, FALSE );
98f2ee76 128
98f2ee76 129
6e515418 130
78b2428e 131/* If they don't have a logo, don't bother.. */
c5330196 132$logo_str = '';
78b2428e 133if (isset($org_logo) && $org_logo) {
b86f98e4 134
78b2428e 135 if (isset($org_logo_width) && is_numeric($org_logo_width) &&
136 $org_logo_width>0) {
0173ad29 137 $width = $org_logo_width;
efb5bde8 138 } else {
0173ad29 139 $width = '';
78b2428e 140 }
141 if (isset($org_logo_height) && is_numeric($org_logo_height) &&
142 $org_logo_height>0) {
0173ad29 143 $height = $org_logo_height;
efb5bde8 144 } else {
0173ad29 145 $height = '';
78b2428e 146 }
0173ad29 147
b86f98e4 148 $logo_str = create_image($org_logo, sprintf(_("%s Logo"), $org_name),
0173ad29 149 $width, $height, '', 'sqm_loginImage');
150
c5330196 151}
152
153$sm_attribute_str = '';
beebd508 154if (isset($hide_sm_attributions) && !$hide_sm_attributions) {
3e6b917e 155 $sm_attribute_str = _("SquirrelMail Webmail")."\n" .
2e9a4e86 156 _("By the SquirrelMail Project Team");
98f2ee76 157}
3fde693b 158
7e2ff844 159if(sqgetGlobalVar('mailtodata', $mailtodata)) {
160 $mailtofield = addHidden('mailtodata', $mailtodata);
c67e4479 161} else {
7e2ff844 162 $mailtofield = '';
c67e4479 163}
c5330196 164
84d10885 165$password_field = addPwField('secretkey');
2f04c558 166$login_extra = addHidden('js_autodetect_results', SMPREF_JS_OFF).
7e2ff844 167 $mailtofield .
31633bef 168 addHidden('just_logged_in', '1');
c5330196 169
202bcbcc 170session_write_close();
171
5cf27342 172$oTemplate->assign('logo_str', $logo_str, FALSE);
84d10885 173$oTemplate->assign('logo_path', $org_logo);
c5330196 174$oTemplate->assign('sm_attribute_str', $sm_attribute_str);
6f4080b1 175// i18n: The %s represents the service provider's name
c5330196 176$oTemplate->assign('org_name_str', sprintf (_("%s Login"), $org_name));
6f4080b1 177// i18n: The %s represents the service provider's name
178$oTemplate->assign('org_logo_str', sprintf (_("The %s logo"), $org_name));
2f04c558 179$oTemplate->assign('login_field_value', $loginname_value);
5cf27342 180$oTemplate->assign('login_extra', $login_extra, FALSE);
2f04c558 181
0173ad29 182//FIXME: need to remove *ALL* HTML from this file!
3b4dece1 183echo '<body onload="squirrelmail_loginpage_onload()">'."\n";
184echo '<form action="redirect.php" method="post" onsubmit="document.forms[0].js_autodetect_results.value='. SMPREF_JS_ON .'">'."\n";
6e515418 185do_hook('login_top', $null);
c5330196 186
187$oTemplate->display('login.tpl');
f5dcd7f3 188
0173ad29 189//FIXME: need to remove *ALL* HTML from this file!
2f04c558 190echo "</form>\n";
6e515418 191do_hook('login_bottom', $null);
2f04c558 192
f5dcd7f3 193// Turn off delayed error handling to make sure all errors are dumped.
84d10885 194$oErrorHandler->setDelayedErrors(false);
f5dcd7f3 195
f5dcd7f3 196$oTemplate->display('footer.tpl');