Freeradius users script added
[ga4php.git] / authserver / usercmd.php
1 <?php
2 /*
3  * 
4  * 
5  * This file is designed as a "script" extension to freeradius (or some such tool) for radius authentication.
6  * Also provided is a simple web interface for managing users in freeradius.
7  * 
8  * The simple web interface should also provide a mechanism for configuring freeradius itself
9  * 
10  */
11
12 require_once("lib/authClient.php");
13
14 $myAC = new GAAuthClient();
15
16 /*
17 define("MSG_AUTH_USER_TOKEN", 1);
18 define("MSG_ADD_USER_TOKEN", 2);
19 define("MSG_DELETE_USER", 3);
20 define("MSG_AUTH_USER_PASSWORD", 4);
21 define("MSG_SET_USER_PASSWORD", 5);
22 define("MSG_SET_USER_REALNAME", 6);
23 define("MSG_SET_USER_TOKEN", 7);
24 define("MSG_SET_USER_TOKEN_TYPE", 8);
25
26  */
27 if(!isset($argv[1])) {
28         echo "Usage: ".$argv[0]." command username [args]\n";
29         echo "\tadd: add <username> - returns token code url\n";
30         echo "\tauth: auth <username> <passcode> - returns 0/1 for pass/fail\n";
31         echo "\tdelete: delete <username> - deletes user\n";
32         echo "\tauthpass: authpass <username> <password> - returns 0/1 for pass/fail\n";
33         echo "\tsetpass: setpass <username> <password> - sets a password for a user (x to remove pass)\n";
34         echo "\tsetname: setname <username> <realname> - sets the real name for a user\n";
35         echo "\tsettoken: settoken <username> <tokenkey> - sets the key (hex) for a token\n";
36         echo "\tsettype: settype <username> <tokentype> - sets a token type for a user\n";
37         echo "\tgetusers: getusers - gets a list of users\n";
38         echo "\tgetotk: getotk <username> - gets the OTKID for a key\n";
39         echo "\tradauth: radauth <username> <pin> - for radius, only returns a code\n";
40         return 0;       
41 }
42
43 switch($argv[1]) {
44         case "radauth":
45                 if($myAC->authUserToken($argv[2], $argv[3])==1) {
46                         syslog(LOG_WARNING, "Got good request for user, ".$argv[2]);
47                         exit(0);
48                 } else {
49                         syslog(LOG_WARNING, "Got bad request for user, ".$argv[2]);
50                         exit(255);
51                 }
52                 break;
53         case "getotk":
54                 $val = $myAC->getOtkID($argv[2]);
55                 if($val === false) {
56                         echo "Failure\n";
57                 } else {
58                         echo "$val\n";
59                 }
60                 break;
61         case "auth":
62                 if($myAC->authUserToken($argv[2], $argv[3])==1) {
63                         echo "Pass!\n";
64                 } else {
65                         echo "Fail!\n";
66                 }
67                 break;
68         case "add":
69                 $return = $myAC->addUser($argv[2]);
70                 echo "Created user, ".$argv[2]." returned $return\n";
71                 break;
72         case "delete":
73                 $res = $myAC->deleteUser($argv[2]);
74                 if($res) {
75                         echo "Deleted\n";
76                 } else {
77                         echo "Failure?\n";
78                 }
79                 break;
80         case "authpass":
81                 $ret = $myAC->authUserPass($argv[2], $argv[3]);
82                 if($ret) echo "Authenticated\n";
83                 else echo "Failed\n";
84                 break;
85         case "setpass":
86                 $res = $myAC->setUserPass($argv[2], $argv[3]);
87                 if($res) echo "Password Set\n";
88                 else echo "Failure?\n";
89                 break;
90         case "setname":
91                 $ret = $myAC->setUserRealName($argv[2], $argv[3]);
92                 if($ret) echo "Real Name Set\n";
93                 else echo "Failure?\n";
94                 break;
95         case "settoken":
96                 $ret = $myAC->setUserToken($argv[2], $argv[3]);
97                 if($ret) echo "Token Set\n";
98                 else echo "Failure?\n";
99                 break;
100         case "settype":
101                 $ret = $myAC->setUserTokenType($argv[2], $argv[3]);
102                 if($ret) echo "Token Type Set\n";
103                 else echo "Failure?\n";
104                 break;
105         case "getusers":
106                 $users = $myAC->getUsers();
107                 foreach($users as $user) {
108                         if($user["realname"] != "") $realname = $user["realname"];
109                         else $realname = "- Not Set -";
110                         
111                         if($user["haspass"]) $haspass = "Yes";
112                         else $haspass = "No";
113                         
114                         if($user["hastoken"]) $hastoken = "Yes";
115                         else $hastoken = "No";
116                         
117                         echo "Username: ".$user["username"]."\n";
118                         echo "\tReal Name: ".$realname."\n";
119                         echo "\tHas Password?: ".$haspass."\n";
120                         echo "\tHas Token?: ".$hastoken."\n\n";
121                 }
122                 break;
123 }
124 ?>