/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
/* This module is triggered by an * *AuthGroupFilestandard/path/to/file * *andthepresenceofa * *requiregroup<list-of-groups> * *Inanapplicablelimit/directoryblockforthatmethod. * *IftherearenoAuthGroupFiledirectivesvalidfor *therequest;weDECLINED. * *IftheAuthGroupFileisdefined;butsomehownot *accessible:weSERVER_ERROR(wasDECLINED). * *Ifthereareno'require'directivesdefinedfor *thisrequestthenweDECLINED(wasOK). * *Ifthereareno'require'directivesvalidfor *thisrequestmethodthenweDECLINED.(wasOK) * *Ifthereareany'requiregroup'blocksandwe *arenotinanygroup-weHTTP_UNAUTHORIZE *
*/
/* If there is no group file - then we are not *configured.Sodecline.
*/ if (!(conf->groupfile)) {
ap_log_rerror(APLOG_MARK, APLOG_ERR, 0, r, APLOGNO(01664) "No group file was specified in the configuration"); return AUTHZ_DENIED;
}
status = groups_for_user(r->pool, user, conf->groupfile,
&grpstatus);
if (status != APR_SUCCESS) {
ap_log_rerror(APLOG_MARK, APLOG_ERR, status, r, APLOGNO(01665) "Could not open group file: %s",
conf->groupfile); return AUTHZ_DENIED;
}
if (apr_is_empty_table(grpstatus)) { /* no groups available, so exit immediately */
ap_log_rerror(APLOG_MARK, APLOG_INFO, 0, r, APLOGNO(01666) "Authorization of user %s to access %s failed, reason: " "user doesn't appear in group file (%s).",
r->user, r->uri, conf->groupfile); return AUTHZ_DENIED;
}
t = require; while ((w = ap_getword_conf(r->pool, &t)) && w[0]) { if (apr_table_get(grpstatus, w)) { return AUTHZ_GRANTED;
}
}
ap_log_rerror(APLOG_MARK, APLOG_DEBUG, 0, r, APLOGNO(01667) "Authorization of user %s to access %s failed, reason: " "user is not part of the 'require'ed group(s).",
r->user, r->uri);
/* If there is no group file - then we are not *configured.Sodecline.
*/ if (!(conf->groupfile)) {
ap_log_rerror(APLOG_MARK, APLOG_ERR, 0, r, APLOGNO(01668) "No group file was specified in the configuration"); return AUTHZ_DENIED;
}
status = groups_for_user(r->pool, user, conf->groupfile,
&grpstatus); if (status != APR_SUCCESS) {
ap_log_rerror(APLOG_MARK, APLOG_ERR, status, r, APLOGNO(01669) "Could not open group file: %s",
conf->groupfile); return AUTHZ_DENIED;
}
if (apr_is_empty_table(grpstatus)) { /* no groups available, so exit immediately */
ap_log_rerror(APLOG_MARK, APLOG_ERR, 0, r, APLOGNO(01670) "Authorization of user %s to access %s failed, reason: " "user doesn't appear in group file (%s).",
r->user, r->uri, conf->groupfile); return AUTHZ_DENIED;
}
filegroup = authz_owner_get_file_group(r);
if (filegroup) { if (apr_table_get(grpstatus, filegroup)) { return AUTHZ_GRANTED;
}
} else { /* No need to emit a error log entry because the call toauthz_owner_get_file_groupalreadydidit forus.
*/ return AUTHZ_DENIED;
}
ap_log_rerror(APLOG_MARK, APLOG_DEBUG, 0, r, APLOGNO(01671) "Authorization of user %s to access %s failed, reason: " "user is not part of the 'require'ed file group.",
r->user, r->uri);
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.