|
@@ -325,7 +325,7 @@ discard block |
|
|
block discarded – undo |
|
325
|
325
|
$invitationObject = new SilverbulletInvitation($token); |
|
326
|
326
|
$profile = new ProfileSilverbullet($invitationObject->profile); |
|
327
|
327
|
$inst = new IdP($profile->institution); |
|
328
|
|
- $loggerInstance->debug(5, "tokenStatus: done, got " . $invitationObject->invitationTokenStatus . ", " . $invitationObject->profile . ", " . $invitationObject->userId . ", " . $invitationObject->expiry . ", " . $invitationObject->invitationTokenString . "\n"); |
|
|
328
|
+ $loggerInstance->debug(5, "tokenStatus: done, got ".$invitationObject->invitationTokenStatus.", ".$invitationObject->profile.", ".$invitationObject->userId.", ".$invitationObject->expiry.", ".$invitationObject->invitationTokenString."\n"); |
|
329
|
329
|
if ($invitationObject->invitationTokenStatus != SilverbulletInvitation::SB_TOKENSTATUS_VALID && $invitationObject->invitationTokenStatus != SilverbulletInvitation::SB_TOKENSTATUS_PARTIALLY_REDEEMED) { |
|
330
|
330
|
throw new Exception("Attempt to generate a SilverBullet installer with an invalid/redeemed/expired token. The user should never have gotten that far!"); |
|
331
|
331
|
} |
|
@@ -338,12 +338,12 @@ discard block |
|
|
block discarded – undo |
|
338
|
338
|
throw new Exception("Despite a valid token, the corresponding user was not found in database or database query error!"); |
|
339
|
339
|
} |
|
340
|
340
|
$expiryObject = mysqli_fetch_object(/** @scrutinizer ignore-type */ $userrow); |
|
341
|
|
- $loggerInstance->debug(5, "EXP: " . $expiryObject->expiry . "\n"); |
|
|
341
|
+ $loggerInstance->debug(5, "EXP: ".$expiryObject->expiry."\n"); |
|
342
|
342
|
$expiryDateObject = date_create_from_format("Y-m-d H:i:s", $expiryObject->expiry); |
|
343
|
343
|
if ($expiryDateObject === FALSE) { |
|
344
|
344
|
throw new Exception("The expiry date we got from the DB is bogus!"); |
|
345
|
345
|
} |
|
346
|
|
- $loggerInstance->debug(5, $expiryDateObject->format("Y-m-d H:i:s") . "\n"); |
|
|
346
|
+ $loggerInstance->debug(5, $expiryDateObject->format("Y-m-d H:i:s")."\n"); |
|
347
|
347
|
// date_create with no parameters can't fail, i.e. is never FALSE |
|
348
|
348
|
$validity = date_diff(/** @scrutinizer ignore-type */ date_create(), $expiryDateObject); |
|
349
|
349
|
$expiryDays = $validity->days + 1; |
|
@@ -382,7 +382,7 @@ discard block |
|
|
block discarded – undo |
|
382
|
382
|
$certString = ""; |
|
383
|
383
|
openssl_x509_export($cert, $certString); |
|
384
|
384
|
$parsedCert = $x509->processCertificate($certString); |
|
385
|
|
- $loggerInstance->debug(5, "CERTINFO: " . /** @scrutinizer ignore-type */ print_r($parsedCert['full_details'], true)); |
|
|
385
|
+ $loggerInstance->debug(5, "CERTINFO: "./** @scrutinizer ignore-type */ print_r($parsedCert['full_details'], true)); |
|
386
|
386
|
$realExpiryDate = date_create_from_format("U", $parsedCert['full_details']['validTo_time_t'])->format("Y-m-d H:i:s"); |
|
387
|
387
|
|
|
388
|
388
|
// store new cert info in DB |
|
@@ -394,7 +394,7 @@ discard block |
|
|
block discarded – undo |
|
394
|
394
|
// let the RADIUS users know the actual username for CUI generation |
|
395
|
395
|
$radiusDbs = core\DBConnection::handle("RADIUS"); // is an array of server conns |
|
396
|
396
|
foreach ($radiusDbs as $oneRadiusDb) { |
|
397
|
|
- $oneRadiusDb->exec("INSERT IGNORE INTO radcheck (username, attribute, op, value) VALUES (?, 'CUI-Source-Username', ':=', ?)", "ss", ($profile->getUserById($invitationObject->userId))[$invitationObject->userId] , $csr["USERNAME"]); |
|
|
397
|
+ $oneRadiusDb->exec("INSERT IGNORE INTO radcheck (username, attribute, op, value) VALUES (?, 'CUI-Source-Username', ':=', ?)", "ss", ($profile->getUserById($invitationObject->userId))[$invitationObject->userId], $csr["USERNAME"]); |
|
398
|
398
|
} |
|
399
|
399
|
|
|
400
|
400
|
// return PKCS#12 data stream |
|
@@ -448,7 +448,7 @@ discard block |
|
|
block discarded – undo |
|
448
|
448
|
$username = ""; |
|
449
|
449
|
while ($usernameIsUnique === FALSE) { |
|
450
|
450
|
$usernameLocalPart = common\Entity::randomString(64 - 1 - strlen($realm), "0123456789abcdefghijklmnopqrstuvwxyz"); |
|
451
|
|
- $username = $usernameLocalPart . "@" . $realm; |
|
|
451
|
+ $username = $usernameLocalPart."@".$realm; |
|
452
|
452
|
$uniquenessQuery = $databaseHandle->exec("SELECT cn from silverbullet_certificate WHERE cn = ? AND ca_type = ?", "ss", $username, $certtype); |
|
453
|
453
|
// SELECT -> resource, not boolean |
|
454
|
454
|
if (mysqli_num_rows(/** @scrutinizer ignore-type */ $uniquenessQuery) == 0) { |