diff --git a/htdocs/public.php b/htdocs/public.php index 0d9bd968..74765546 100644 --- a/htdocs/public.php +++ b/htdocs/public.php @@ -8,13 +8,11 @@ * @copyright Catalyst .Net Ltd * @license http://gnu.org/copyleft/gpl.html GNU GPL v2 */ -require_once("../inc/always.php"); +require("../inc/always.php"); dbg_error_log( "caldav", " User agent: %s", ((isset($_SERVER['HTTP_USER_AGENT']) ? $_SERVER['HTTP_USER_AGENT'] : "Unfortunately Mulberry does not send a 'User-agent' header with its requests :-(")) ); dbg_log_array( "headers", '_SERVER', $_SERVER, true ); -$session = (object) array( - 'username' => 'public', - 'user_no' => -1 -); +require("PublicSession.php"); +$session = new PublicSession(); /** A simplified DAV header in this case */ $dav = "1, 2, calendar-access"; @@ -22,6 +20,9 @@ header( "DAV: $dav"); require_once("CalDAVRequest.php"); $request = new CalDAVRequest(); +if ( !$request->IsPublic() ) { + $request->DoResponse( 403, translate('Anonymous users may only access public calendars') ); +} switch ( $request->method ) { case 'OPTIONS': include_once("caldav-OPTIONS.php"); break; diff --git a/inc/PublicSession.php b/inc/PublicSession.php new file mode 100644 index 00000000..357e1e6b --- /dev/null +++ b/inc/PublicSession.php @@ -0,0 +1,76 @@ + +* @copyright Morphoss Ltd +* @license http://gnu.org/copyleft/gpl.html GNU GPL v2 or later +*/ + +/** +* A Class for handling a public (anonymous) session +* +* @package davical +*/ +class PublicSession { + /**#@+ + * @access private + */ + + /** + * User ID number + * @var user_no int + */ + var $user_no; + + /** + * User e-mail + * @var email string + */ + var $email; + + /** + * User full name + * @var fullname string + */ + var $fullname; + + /** + * Group rights + * @var groups array + */ + var $groups; + /**#@-*/ + + /** + * The constructor, which just calls the actual type configured + */ + function PublicSession() { + global $c; + + $this->user_no = -1; + $this->email = null; + $this->username = 'guest'; + $this->fullname = 'Anonymous'; + $this->groups = ( isset($c->public_groups) ? $c->public_groups : array() ); + $this->roles = array( 'Public' => true ); + $this->logged_in = false; + } + + + /** + * Checks whether a user is allowed to do something. + * + * The check is performed to see if the user has that role. + * + * @param string $whatever The role we want to know if the user has. + * @return boolean Whether or not the user has the specified role. + */ + function AllowedTo ( $whatever ) { + return ( $this->logged_in && isset($this->roles[$whatever]) && $this->roles[$whatever] ); + } + +} +