PageSourceSearch

https://otenet.gr/plugins/ote_auth/ote_auth.js?s=1696744038

js otenet.gr collected 2026-09-24 09:31:36 UTC 5,787 bytes, 208 lines download raw bytes

1// Jquery extension method to get parameters from query string
2// Posted by geekyjohn at http://snipplr.com/view/26662/get-url-parameters-with-jquery--improved/
3$.urlParam = function (name) {
4  var results = new RegExp("[\\?&]" + name + "=([^&#]*)").exec(
5    window.location.href,
6  );
7  if (!results) {
8    return 0;
9  }
10  return results[1] || 0;
11};
12
13// do no action until init is called
14rcmail.addEventListener("init", function (evt) {
15  // if querystring includes ssoLoginFailure notification, then show the "login failed"
16  // message
17  if ($.urlParam("ssoLoginFailure") == "true") {
18    var username = $.urlParam("username");
19
20    rcmail.display_message(rcmail.env.loginFailedText, "warning");
21    var $form = $("#login-form form").eq(0);
22    $form.find("input[name=_user]").attr("value", username);
23  }
24
25  // if querystring includes ssoLogout, then show the logout message
26  if ($.urlParam("ssoLogout") == "true") {
27    rcmail.display_message(rcmail.env.logoutText);
28  }
29
30  // should we show reCAPTCHA?
31  if (rcmail.env.showCAPTCHA == 1) {
32    showRecaptcha();
33  }
34
35  // alter form submission behavior
36  alterFormSubmission();
37});
38
39/**
40 * Alters the submission process to include CAPTCHA and SSO authentication.
41 *
42 * This method only handles the reCAPTCHA portion of the submission, then delegates action
43 * to proceedAfterCaptcha().
44 */
45function alterFormSubmission() {
46  var $form = $("#login-form form").eq(0);
47
48  // unbind anything set by another plugin
49  $form.unbind("submit");
50  $form.submit(function (e) {
51    e.preventDefault();
52
53    // if CAPTCHA is enabled, check it first, then do authentication
54    if (rcmail.env.showCAPTCHA == 1) {
55      var captcha_code = $("#captcha_code").val();
56      var captchaId = $("#recaptcha_iframe")
57        .contents()
58        .find("#captchaId")
59        .val();
60
61      if (captcha_code.length <= 0) {
62        rcmail.display_message(rcmail.env.captchaEmpty, "error");
63        return;
64      }
65
66      $.ajax({
67        type: "POST",
68        url: "./securimage/validatingCaptchaId.php",
69        dataType: "json",
70        data: {
71          captcha_code: captcha_code,
72          captchaId: captchaId,
73        },
74        success: function (data, status, xhr) {
75          if (data == true) {
76            proceedAfterCaptcha();
77          } else {
78            // show CAPTCHA failure message
79            rcmail.display_message(rcmail.env.captchaFailed, "error");
80            recaptcha_iframe_reload();
81
82            return;
83          }
84        },
85      });
86    } else {
87      // proceed to authentication
88      proceedAfterCaptcha();
89    }
90  });
91}
92
93function recaptcha_iframe_reload() {
94  $("#captcha_code").val("");
95  document
96    .getElementById("recaptcha_iframe")
97    .contentDocument.location.reload(true);
98}
99
100/**
101 * Handles the form submission after the CAPTCHA step.
102 */
103function proceedAfterCaptcha() {
104  var $form = $("#login-form form").eq(0);
105
106  if (rcmail.env.authMode === "cloud") {
107    // alter the form, then submit
108
109    alterFormForCloudLogin();
110    $form.unbind("submit");
111    $form.submit();
112  } else if (rcmail.env.authMode === "auto") {
113    // first make an AJAX call to check account type, then submit
114
115    handleAutoAuthSubmission();
116  } else {
117    // legacy authentication, just submit
118    $form.unbind("submit");
119    $form.submit();
120  }
121}
122
123/**
124 * Alters the form so that it submits data to the OpenSSO service.
125 */
126function alterFormForCloudLogin() {
127  var $form = $("#login-form form").eq(0);
128
129  // keep username, as we'll need it for login-failed URL
130  var username = $form.find("input[name=_user]").eq(0).val();
131
132  // change URL of form
133  $form.attr("action", rcmail.env.ssoLoginUrl);
134
135  // remove existing hidden fields as the data are only relevant to Roundcube
136  $form.find("input[type=hidden]").remove();
137
138  // change the names of the username/password fields
139  $form.find("input[name=_user]").attr("name", "IDToken1");
140  $form.find("input[name=_pass]").attr("name", "IDToken2");
141
142  // add new hidden fields
143  $form.append(
144    '<input type="hidden" name="goto" value="' +
145      rcmail.env.ssoReturnUrl +
146      '" />',
147  );
148  $form.append(
149    '<input type="hidden" name="gotoOnFail" value="' +
150      rcmail.env.ssoReturnUrl +
151      "?ssoLoginFailure=true&username=" +
152      username +
153      '" />',
154  );
155  $form.append(
156    '<input type="hidden" name="realm" value="' + rcmail.env.authRealm + '" />',
157  );
158}
159
160/**
161 * First checks with the Mail API for the account type and then either
162 * send the data to the OpenSSO service or perform a simple IMAP login.
163 */
164function handleAutoAuthSubmission() {
165  var $form = $("#login-form form").eq(0);
166
167  var usernameInput = $form.find("input[name=_user]").val();
168
169  $.ajax({
170    type: "POST",
171    url: "plugins/ote_auth/ajaxIsCloud.php",
172    dataType: "json",
173    data: { username: usernameInput },
174    success: function (data, status, xhr) {
175      // change the form for SSO login only if a cloud account
176      if (
177        data.success == true &&
178        data.accountFound == true &&
179        data.isCloudAccount == true
180      ) {
181        alterFormForCloudLogin();
182        // the 'complete' callback will submit the form
183      }
184    },
185    complete: function (xhr, status) {
186      // unbind form, submit for login
187      $form.unbind("submit");
188      $form.submit();
189    },
190  });
191}
192
193/*
194 * Displays the reCAPTCHA input field.
195 */
196function showRecaptcha() {
197  var htmlString =
198    ' \
199<iframe id="recaptcha_iframe" width="350" height="110" frameborder="0" src="./securimage/sircube.php"></iframe><br/> \
200<label style="font-weight: bold;" for="captcha_code">' +
201    rcmail.gettext("captcha_code", "password_recovery") +
202    ': </label> \
203<input id="captcha_code" style="width:70px;" type="text" name="_captcha_code" size="7"> \
204\
205';
206
207  $("#recaptchaArea").append(htmlString);
208}

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.