← Index
NYTProf Performance Profile   « block view • line view • sub view »
For /usr/share/koha/opac/cgi-bin/opac/opac-search.pl
  Run on Tue Oct 15 11:58:52 2013
Reported on Tue Oct 15 12:02:06 2013

Filename/usr/share/koha/lib/C4/Auth_with_cas.pm
StatementsExecuted 41 statements in 2.56ms
Subroutines
Calls P F Exclusive
Time
Inclusive
Time
Subroutine
1113.36ms8.59msC4::Auth_with_cas::::BEGIN@26C4::Auth_with_cas::BEGIN@26
1111.12ms1.75msC4::Auth_with_cas::::BEGIN@28C4::Auth_with_cas::BEGIN@28
111602µs1.04msC4::Auth_with_cas::::BEGIN@25C4::Auth_with_cas::BEGIN@25
11131µs88µsC4::Auth_with_cas::::BEGIN@27C4::Auth_with_cas::BEGIN@27
11125µs33µsC4::Auth_with_cas::::BEGIN@20C4::Auth_with_cas::BEGIN@20
11123µs23µsC4::Auth_with_cas::::BEGIN@33C4::Auth_with_cas::BEGIN@33
11117µs119µsC4::Auth_with_cas::::BEGIN@31C4::Auth_with_cas::BEGIN@31
11116µs16µsC4::Auth_with_cas::::CORE:ftisC4::Auth_with_cas::CORE:ftis (opcode)
11115µs39µsC4::Auth_with_cas::::BEGIN@21C4::Auth_with_cas::BEGIN@21
11114µs18µsC4::Auth_with_cas::::BEGIN@24C4::Auth_with_cas::BEGIN@24
11114µs173µsC4::Auth_with_cas::::BEGIN@23C4::Auth_with_cas::BEGIN@23
11113µs29µsC4::Auth_with_cas::::multipleAuthC4::Auth_with_cas::multipleAuth
0000s0sC4::Auth_with_cas::::check_api_auth_casC4::Auth_with_cas::check_api_auth_cas
0000s0sC4::Auth_with_cas::::checkpw_casC4::Auth_with_cas::checkpw_cas
0000s0sC4::Auth_with_cas::::getMultipleAuthC4::Auth_with_cas::getMultipleAuth
0000s0sC4::Auth_with_cas::::login_casC4::Auth_with_cas::login_cas
0000s0sC4::Auth_with_cas::::login_cas_urlC4::Auth_with_cas::login_cas_url
0000s0sC4::Auth_with_cas::::logout_casC4::Auth_with_cas::logout_cas
Call graph for these subroutines as a Graphviz dot language file.
Line State
ments
Time
on line
Calls Time
in subs
Code
1package C4::Auth_with_cas;
2
3# Copyright 2009 BibLibre SARL
4#
5# This file is part of Koha.
6#
7# Koha is free software; you can redistribute it and/or modify it under the
8# terms of the GNU General Public License as published by the Free Software
9# Foundation; either version 2 of the License, or (at your option) any later
10# version.
11#
12# Koha is distributed in the hope that it will be useful, but WITHOUT ANY
13# WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
14# A PARTICULAR PURPOSE. See the GNU General Public License for more details.
15#
16# You should have received a copy of the GNU General Public License along
17# with Koha; if not, write to the Free Software Foundation, Inc.,
18# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
19
20336µs240µs
# spent 33µs (25+8) within C4::Auth_with_cas::BEGIN@20 which was called: # once (25µs+8µs) by C4::Auth::BEGIN@39 at line 20
use strict;
# spent 33µs making 1 call to C4::Auth_with_cas::BEGIN@20 # spent 8µs making 1 call to strict::import
21336µs263µs
# spent 39µs (15+24) within C4::Auth_with_cas::BEGIN@21 which was called: # once (15µs+24µs) by C4::Auth::BEGIN@39 at line 21
use warnings;
# spent 39µs making 1 call to C4::Auth_with_cas::BEGIN@21 # spent 24µs making 1 call to warnings::import
22
23341µs2333µs
# spent 173µs (14+160) within C4::Auth_with_cas::BEGIN@23 which was called: # once (14µs+160µs) by C4::Auth::BEGIN@39 at line 23
use C4::Debug;
# spent 173µs making 1 call to C4::Auth_with_cas::BEGIN@23 # spent 160µs making 1 call to Exporter::import
24334µs222µs
# spent 18µs (14+4) within C4::Auth_with_cas::BEGIN@24 which was called: # once (14µs+4µs) by C4::Auth::BEGIN@39 at line 24
use C4::Context;
# spent 18µs making 1 call to C4::Auth_with_cas::BEGIN@24 # spent 4µs making 1 call to C4::Context::import
253182µs21.21ms
# spent 1.04ms (602µs+442µs) within C4::Auth_with_cas::BEGIN@25 which was called: # once (602µs+442µs) by C4::Auth::BEGIN@39 at line 25
use C4::Utils qw( :all );
# spent 1.04ms making 1 call to C4::Auth_with_cas::BEGIN@25 # spent 169µs making 1 call to Exporter::import
263166µs18.59ms
# spent 8.59ms (3.36+5.23) within C4::Auth_with_cas::BEGIN@26 which was called: # once (3.36ms+5.23ms) by C4::Auth::BEGIN@39 at line 26
use Authen::CAS::Client;
# spent 8.59ms making 1 call to C4::Auth_with_cas::BEGIN@26
27355µs2145µs
# spent 88µs (31+57) within C4::Auth_with_cas::BEGIN@27 which was called: # once (31µs+57µs) by C4::Auth::BEGIN@39 at line 27
use CGI;
# spent 88µs making 1 call to C4::Auth_with_cas::BEGIN@27 # spent 57µs making 1 call to CGI::import
283216µs21.78ms
# spent 1.75ms (1.12+637µs) within C4::Auth_with_cas::BEGIN@28 which was called: # once (1.12ms+637µs) by C4::Auth::BEGIN@39 at line 28
use FindBin;
# spent 1.75ms making 1 call to C4::Auth_with_cas::BEGIN@28 # spent 25µs making 1 call to Exporter::import
29
30
31374µs2220µs
# spent 119µs (17+101) within C4::Auth_with_cas::BEGIN@31 which was called: # once (17µs+101µs) by C4::Auth::BEGIN@39 at line 31
use vars qw($VERSION @ISA @EXPORT @EXPORT_OK %EXPORT_TAGS $debug);
# spent 119µs making 1 call to C4::Auth_with_cas::BEGIN@31 # spent 102µs making 1 call to vars::import
32
33
# spent 23µs within C4::Auth_with_cas::BEGIN@33 which was called: # once (23µs+0s) by C4::Auth::BEGIN@39 at line 39
BEGIN {
341500ns require Exporter;
3511µs $VERSION = 3.07.00.049; # set the version for version checking
3611µs $debug = $ENV{DEBUG};
37111µs @ISA = qw(Exporter);
38112µs @EXPORT = qw(check_api_auth_cas checkpw_cas login_cas logout_cas login_cas_url);
3911.63ms123µs}
# spent 23µs making 1 call to C4::Auth_with_cas::BEGIN@33
40113µs143.3msmy $context = C4::Context->new() or die 'C4::Context->new failed';
# spent 43.3ms making 1 call to C4::Context::new
411500nsmy $defaultcasserver;
421300nsmy $casservers;
4311µsmy $yamlauthfile = "../C4/Auth_cas_servers.yaml";
44
45
46# If there's a configuration for multiple cas servers, then we get it
4715µs129µsif (multipleAuth()) {
# spent 29µs making 1 call to C4::Auth_with_cas::multipleAuth
48 ($defaultcasserver, $casservers) = YAML::LoadFile(qq($FindBin::Bin/$yamlauthfile));
49 $defaultcasserver = $defaultcasserver->{'default'};
50} else {
51# Else, we fall back to casServerUrl syspref
521900ns $defaultcasserver = 'default';
5319µs12.05ms $casservers = { 'default' => C4::Context->preference('casServerUrl') };
# spent 2.05ms making 1 call to C4::Context::preference
54}
55
56# Is there a configuration file for multiple cas servers?
57
# spent 29µs (13+16) within C4::Auth_with_cas::multipleAuth which was called: # once (13µs+16µs) by C4::Auth::BEGIN@39 at line 47
sub multipleAuth {
58130µs116µs return (-e qq($FindBin::Bin/$yamlauthfile));
# spent 16µs making 1 call to C4::Auth_with_cas::CORE:ftis
59}
60
61# Returns configured CAS servers' list if multiple authentication is enabled
62sub getMultipleAuth {
63 return $casservers;
64}
65
66# Logout from CAS
67sub logout_cas {
68 my ($query) = @_;
69 my $uri = C4::Context->preference('OPACBaseURL') . $query->script_name();
70 my $casparam = $query->param('cas');
71 # FIXME: This should be more generic and handle whatever parameters there might be
72 $uri .= "?cas=" . $casparam if (defined $casparam);
73 $casparam = $defaultcasserver if (not defined $casparam);
74 my $cas = Authen::CAS::Client->new($casservers->{$casparam});
75 print $query->redirect( $cas->logout_url($uri));
76}
77
78# Login to CAS
79sub login_cas {
80 my ($query) = @_;
81 my $uri = C4::Context->preference('OPACBaseURL') . $query->script_name();
82 my $casparam = $query->param('cas');
83 # FIXME: This should be more generic and handle whatever parameters there might be
84 $uri .= "?cas=" . $casparam if (defined $casparam);
85 $casparam = $defaultcasserver if (not defined $casparam);
86 my $cas = Authen::CAS::Client->new($casservers->{$casparam});
87 print $query->redirect( $cas->login_url($uri));
88}
89
90# Returns CAS login URL with callback to the requesting URL
91sub login_cas_url {
92
93 my ($query, $key) = @_;
94 my $uri = C4::Context->preference('OPACBaseURL') . $query->url( -absolute => 1, -query => 1 );
95 my $casparam = $query->param('cas');
96 $casparam = $defaultcasserver if (not defined $casparam);
97 $casparam = $key if (defined $key);
98 my $cas = Authen::CAS::Client->new($casservers->{$casparam});
99 return $cas->login_url($uri);
100}
101
102# Checks for password correctness
103# In our case : is there a ticket, is it valid and does it match one of our users ?
104sub checkpw_cas {
105 $debug and warn "checkpw_cas";
106 my ($dbh, $ticket, $query) = @_;
107 my $retnumber;
108 my $uri = C4::Context->preference('OPACBaseURL') . $query->script_name();
109 my $casparam = $query->param('cas');
110 # FIXME: This should be more generic and handle whatever parameters there might be
111 $uri .= "?cas=" . $casparam if (defined $casparam);
112 $casparam = $defaultcasserver if (not defined $casparam);
113 my $cas = Authen::CAS::Client->new($casservers->{$casparam});
114
115 # If we got a ticket
116 if ($ticket) {
117 $debug and warn "Got ticket : $ticket";
118
119 # We try to validate it
120 my $val = $cas->service_validate($uri, $ticket );
121
122 # If it's valid
123 if ( $val->is_success() ) {
124
125 my $userid = $val->user();
126 $debug and warn "User CAS authenticated as: $userid";
127
128 # Does it match one of our users ?
129 my $sth = $dbh->prepare("select cardnumber from borrowers where userid=?");
130 $sth->execute($userid);
131 if ( $sth->rows ) {
132 $retnumber = $sth->fetchrow;
133 return ( 1, $retnumber, $userid );
134 }
135 $sth = $dbh->prepare("select userid from borrowers where cardnumber=?");
136 $sth->execute($userid);
137 if ( $sth->rows ) {
138 $retnumber = $sth->fetchrow;
139 return ( 1, $retnumber, $userid );
140 }
141
142 # If we reach this point, then the user is a valid CAS user, but not a Koha user
143 $debug and warn "User $userid is not a valid Koha user";
144
145 } else {
146 $debug and warn "Problem when validating ticket : $ticket";
147 $debug and warn "Authen::CAS::Client::Response::Error: " . $val->error() if $val->is_error();
148 $debug and warn "Authen::CAS::Client::Response::Failure: " . $val->message() if $val->is_failure();
149 $debug and warn Data::Dumper::Dumper($@) if $val->is_error() or $val->is_failure();
150 return 0;
151 }
152 }
153 return 0;
154}
155
156# Proxy CAS auth
157sub check_api_auth_cas {
158 $debug and warn "check_api_auth_cas";
159 my ($dbh, $PT, $query) = @_;
160 my $retnumber;
161 my $url = C4::Context->preference('OPACBaseURL') . $query->script_name();
162
163 my $casparam = $query->param('cas');
164 $casparam = $defaultcasserver if (not defined $casparam);
165 my $cas = Authen::CAS::Client->new($casservers->{$casparam});
166
167 # If we have a Proxy Ticket
168 if ($PT) {
169 my $r = $cas->proxy_validate( $url, $PT );
170
171 # If the PT is valid
172 if ( $r->is_success ) {
173
174 # We've got a username !
175 $debug and warn "User authenticated as: ", $r->user, "\n";
176 $debug and warn "Proxied through:\n";
177 $debug and warn " $_\n" for $r->proxies;
178
179 my $userid = $r->user;
180
181 # Does it match one of our users ?
182 my $sth = $dbh->prepare("select cardnumber from borrowers where userid=?");
183 $sth->execute($userid);
184 if ( $sth->rows ) {
185 $retnumber = $sth->fetchrow;
186 return ( 1, $retnumber, $userid );
187 }
188 $sth = $dbh->prepare("select userid from borrowers where cardnumber=?");
189 return $r->user;
190 $sth->execute($userid);
191 if ( $sth->rows ) {
192 $retnumber = $sth->fetchrow;
193 return ( 1, $retnumber, $userid );
194 }
195
196 # If we reach this point, then the user is a valid CAS user, but not a Koha user
197 $debug and warn "User $userid is not a valid Koha user";
198
199 } else {
200 $debug and warn "Proxy Ticket authentication failed";
201 return 0;
202 }
203 }
204 return 0;
205}
206
207
20818µs1;
209__END__
 
# spent 16µs within C4::Auth_with_cas::CORE:ftis which was called: # once (16µs+0s) by C4::Auth_with_cas::multipleAuth at line 58
sub C4::Auth_with_cas::CORE:ftis; # opcode